As artificial intelligence transforms the financial services sector, the need for robust and forward-looking security architecture has never been more critical. Northern Trust is seeking a Principal AI Security Architect to lead the secure design, integration, and governance of AI systems across the enterprise.
Requirements
- Expertise in Microsoft security ecosystem
- Strong scripting and query experience with PowerShell, KQL
- Experience securing AI pipelines and plugin-based architectures
- Proven leadership in AI-specific threat modeling and risk treatment
- Familiarity with model lifecycle governance
- Regulatory alignment: CRI v2.1, NIST AI RMF, OWASP LLM Top 10, FFIEC, GDPR, Basel III
- Experience with a Global Systemically Important Bank (G-SIB)
Responsibilities
- Define and enforce enterprise-wide AI security architecture patterns across: First-party AI/LLM deployments, Microsoft Copilot and GitHub Copilot, Azure OpenAI and plugin architectures, Third-party managed AI platforms (e.g., Workday, ServiceNow, Solytics, and other integrated AI services)
- Ensure AI systems and plugins are securely integrated with Microsoft 365, Entra ID, Defender suite, Purview, and Azure services.
- Architect Model Context Protocol (MCP) patterns for safe containerized deployments: Secure pod-to-pod communication via microsegmentation, API gateway authentication and rate limiting, Container image integrity validation, Grounding data access policy enforcement, Centralized monitoring and logging for auditability
- Develop and maintain enterprise-wide AI security policy frameworks
- Design and implement policy-as-code and workflow-based governance controls
- Build and maintain AI-specific threat models
- Design AI-aware detection and response strategies
Other
- Act as a recognized authority on AI security
- Advise Security Leadership, Technology Leadership, and governance boards
- Present AI security strategy and posture to stakeholders
- Mentor security architects, engineers, and data scientists
- Partner with Data Protection, Legal, Procurement, and Business Units