Job offer
Principal Security Engineer – AI & Copilot Data Protection
The Northern Trust is looking for a Principal Security Engineer in Chicago to serve as the technical authority on the protection of AI and Copilot data and to define security-related architectures for LLMs and MLOps.
Tasks and responsibilities
- This role serves as a leading technical authority on AI privacy, promotes critical thinking, generates actionable insights, provides guidance on the use of the Microsoft AI Copilot platform, and shares expertise with peer teams.
- Area of Responsibility (Principal Practitioner):
- Tier 2 technical consulting and monitoring strategy for AI and Copilot data protection, not just for enterprise functions.
- Definition of robust, repeatable patterns to validate AI model workflows that can be adopted by others.
- Close collaboration with product managers, compliance, and AI innovation teams (product, information security, data protection, audit, and GRC teams).
- Advising C-suite executives and senior leadership teams to ensure that risks associated with Microsoft AI are appropriately mitigated.
- Serve as a management consultant for templates and controls in AI security assessments to ensure corporate compliance.
- AI and Copilot Security Architecture:
- Serves as a trusted technical leader and design authority for AI model and enterprise AI security controls (Large Language Models (LLM), MLOps, and RAG).
- Definition of secure-by-design architectural models for deploying AI models to ensure the protection of AI-related models and vector databases.
- Research and evaluation of commercial third-party models, including:
- Risk Assessment of Vendor Benchmarks
- Supply Chain Integrity Analysis
- AI-Related Security and Privacy Metrics
- Transparency, verifiable findings, and human oversight
- Providing security blueprints for the development of AI models, behavior, data pipelines, and full-stack deployment.
- Control Engineering and Operations:
- Design, implementation, and operation of automated controls, consisting of:
- Strategy for Information Disclosure and Alerting
- Self-configuration of AI-based content protection and AI acceptance for use
- Shadow Data Management and Data Protection Compliance
- Data Journey Management and Pipeline Observability
- Uniform, structured observability.
- Development of monitoring, alerting, and dashboards to support the adoption of high-risk AI usage patterns.
- Develop proactive measures that enable the detection of automated violations and improve governance.
- Documentation of standards and tools, regular reviews, and ongoing consultations.
- Design, implementation, and operation of automated controls, consisting of:
- Governance and Institutionalization:
- Providing AI insights from internal abuse analyses and benchmarking security controls.
- Collaborating with governance teams to provide support:
- Adoption of AI Innovations
- Documentation of Quality and Usage
- Desktop Usage and Error Handling
- Safe House and Adoption Reports
- Candidate and AI Model Deployment
- Maintenance of Sector Patterns in Copilot Monitoring, Demo-Trust
Job details