As artificial intelligence transforms the financial services sector, Northern Trust needs to ensure robust and forward-looking security architecture for AI systems, including internal LLM deployments, Microsoft Copilot, and third-party AI platforms, to balance innovation with regulatory, operational, and reputational risk.
Requirements
- 10+ years in enterprise security architecture or engineering
- Expertise in Microsoft security ecosystem
- Strong scripting and query experience with PowerShell, KQL
- Experience securing AI pipelines and plugin-based architectures
- Proven leadership in AI-specific threat modeling and risk treatment
- Familiarity with model lifecycle governance
- Regulatory alignment: CRI v2.1, NIST AI RMF, OWASP LLM Top 10, FFIEC, GDPR, Basel III
Responsibilities
- Define and enforce enterprise-wide AI security architecture patterns across: First-party AI/LLM deployments, Microsoft Copilot and GitHub Copilot, Azure OpenAI and plugin architectures, Third-party managed AI platforms (e.g., Workday, ServiceNow, Solytics, and other integrated AI services)
- Ensure AI systems and plugins are securely integrated with Microsoft 365, Entra ID, Defender suite, Purview, and Azure services.
- Architect Model Context Protocol (MCP) patterns for safe containerized deployments: Secure pod-to-pod communication via microsegmentation, API gateway authentication and rate limiting, Container image integrity validation, Grounding data access policy enforcement, Centralized monitoring and logging for auditability
- Develop and maintain enterprise-wide AI security policy frameworks
- Design and implement policy-as-code and workflow-based governance controls
- Build and maintain AI-specific threat models
- Design AI-aware detection and response strategies
Other
- Serve as a trusted advisor to Security & Technology Leadership, internal governance boards, and senior business stakeholders
- Partner with Data Protection, Legal, Procurement, and Business Units
- Support red teaming, abuse case development, and adversarial testing
- Act as a recognized authority on AI security
- Advise Security Leadership, Technology Leadership, and governance boards