Skip to content

Open nowPosted 63 days ago

Corporate Security Engineer, AI

capital45 open roles

Where
Warsaw, Mazowieckie, Poland
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCorporate Security Engineer, AIcapital · Warsaw, Mazowieckie, Poland
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on capital's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.4% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.5%1 day
  2. 3.5%3 days
  3. 7.4%7 days
  4. 13.2%14 days
  5. 34.6%30 days
This job: posted 63 days ago

The posting

We are looking for a Corporate Security Engineer, AI to own the security of how artificial intelligence is adopted and operated across Capital.com.

AI tools are already embedded in how the company works — and the security risks they introduce are unlike those any other team currently owns. This role sits in Corporate Security and is responsible for AI system integration security, AI-specific threat detection, data protection in AI contexts, shadow AI governance, and the regulatory compliance obligations that AI adoption brings with it.

The ideal candidate understands how LLMs, RAG systems, and AI automation tools actually work — and can apply that understanding to evaluate what risks they introduce, design controls that hold, and build the governance framework that makes AI adoption secure and auditable in a regulated financial services environment.

Key Responsibilities:

  • Review and assess the security of AI system integrations across the corporate environment: LLM deployments, RAG pipelines, AI APIs, and AI-enabled automation tools
  • Evaluate configuration, access controls, and data flows of AI systems — the security of how AI is deployed and connected to corporate data and infrastructure
  • Conduct threat modelling for AI integrations and define secure deployment patterns for AI-powered tools
  • Support security reviews for new AI initiatives, tools, and vendor integrations before they reach production
  • Identify and mitigate AI-specific threats: prompt injection & jailbreaks, model poisoning & data contamination, adversarial attacks, training-data leakage, insecure model serialisation, excessive permissions in AI agents
  • Develop guardrails, content filters, and output-validation mechanisms
  • Implement monitoring for anomalous AI behaviour across integrated systems
  • Own data protection controls in AI contexts: govern what data reaches LLM integrations, AI APIs, and AI-enabled tools
  • Design and maintain DLP policies specifically for AI channels — share links, API-connected AI tools, AI browser extensions, and automation agents
  • Ensure AI system compliance with GDPR, data-privacy regulations, and financial-industry data handling requirements
  • Perform AI-specific data risk assessments aligned with the internal risk methodology
  • Operate the controls that govern AI tool use across the organisation — detection policies, sanctioned-tool enforcement, share-link and egress controls
  • Lead third-party AI tool due diligence and ongoing assurance of AI vendor integrations
  • Monitor AI tool usage patterns and investigate anomalous behaviour
  • Contribute to AI security standards, internal policies, and the company's AI risk classification framework
  • Own the AI security governance framework: policy authoring, risk classification, control design, and regulatory mapping
  • Maintain the AI risk register and report on AI-related risk posture to management
  • Map AI security controls against applicable regulatory frameworks: EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR, and financial-sector requirements across FCA, CySEC, ASIC, SCB, and SCA jurisdictions
  • Participate in audit cycles; provide technical evidence and explain AI control design to auditors and regulators

Required Qualifications:

  • 3–5+ years in cybersecurity with hands-on experience in AI/ML system security or a strong AI security focus;
  • Deep knowledge of AI-specific security risks and mitigations: prompt injection, model poisoning, data leakage, adversarial attacks, excessive permissions in AI agents;
  • Hands-on experience securing LLM integrations, RAG pipelines, and AI APIs — reviewing configurations, access controls, and data flows;
  • Experience authoring AI security policies, standards, and risk classification frameworks;
  • Familiarity with AI governance frameworks: EU AI Act, NIST AI RMF, ISO/IEC 42001, and their application in a regulated financial services context;
  • Experience running AI risk assessments and maintaining an AI risk register;
  • Ability to manage third-party AI tool due diligence and control shadow AI across a distributed workforce;
  • Python proficiency for automation and scripting.

Preferred Qualifications:

  • Recognised certifications: CISM, CISSP, or equivalent;
  • Experience in fintech or a regulated financial services environment;
  • Multi-jurisdiction compliance exposure (FCA, CySEC, ASIC, SCB, or SCA);
  • Experience building AI-powered security automation — autonomous agents, LLM-driven triage, automated response workflows;
  • Experience presenting AI security risk posture to leadership or board-level audiences.

Soft Skills:

  • Strong analytical and problem-solving skills;
  • Ability to translate technical AI risk into business and regulatory impact;
  • Able to explain AI security risks and mitigations to non-security teams;
  • Cross-functional collaboration with risk, compliance, product, and engineering teams;
  • Clear documentation and communication skills.

What you will get in return:

Be a key player at the forefront of the digital assets movement, propelling your career to new heights! Join a dynamic and rapidly expanding company that values and rewards talent, initiative, and creativity. Work alongside one of the most brilliant teams in the industry.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against capital's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on capital's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    capital's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.