NextPath Jobs

Corporate Security Engineer, AI

Capital · Warsaw, Mazowieckie, Poland

Posted 2026-07-27 · Verified live 2026-09-23

See how your real experience scores against this role — our AI drafts an honest, verifiable resume tailor. Nothing invented, ever. You approve everything.

Get matched — join the waitlist Apply on company site ↗

About this role

<p>We are looking for a <strong>Corporate Security Engineer, AI</strong> to own the security of how artificial intelligence is adopted and operated across Capital.com.</p>

<p>AI tools are already embedded in how the company works — and the security risks they introduce are unlike those any other team currently owns. This role sits in Corporate Security and is responsible for AI system integration security, AI-specific threat detection, data protection in AI contexts, shadow AI governance, and the regulatory compliance obligations that AI adoption brings with it.</p>

<p>The ideal candidate understands how LLMs, RAG systems, and AI automation tools actually work — and can apply that understanding to evaluate what risks they introduce, design controls that hold, and build the governance framework that makes AI adoption secure and auditable in a regulated financial services environment.</p>

Key Responsibilities:

<h3>AI/ML Security — Integrations &amp; Environment:</h3>

<ul>

<li>

<p>Review and assess the security of AI system integrations across the corporate environment: LLM deployments, RAG pipelines, AI APIs, and AI-enabled automation tools</p>

</li>

<li>

<p>Evaluate configuration, access controls, and data flows of AI systems — the security of how AI is deployed and connected to corporate data and infrastructure</p>

</li>

<li>

<p>Conduct threat modelling for AI integrations and define secure deployment patterns for AI-powered tools</p>

</li>

<li>

<p>Support security reviews for new AI initiatives, tools, and vendor integrations before they reach production</p>

</li>

<h3>AI Threat Detection &amp; Mitigation:</h3>

<ul>

<li>

<p>Identify and mitigate AI-specific threats: prompt injection &amp; jailbreaks, model poisoning &amp; data contamination, adversarial attacks, training-data leakage, insecure model serialisation, excessive permissions in AI agents</p>

</li>

<li>

<p>Develop guardrails, content filters, and output-validation mechanisms</p>

</li>

<li>

<p>Implement monitoring for anomalous AI behaviour across integrated systems</p>

</li>

<h3>AI Data Egress &amp; Data Protection:</h3>

<ul>

<li>

<p>Own data protection controls in AI contexts: govern what data reaches LLM integrations, AI APIs, and AI-enabled tools</p>

</li>

<li>

<p>Design and maintain DLP policies specifically for AI channels — share links, API-connected AI tools, AI browser extensions, and automation agents</p>

</li>

<li>

<p>Ensure AI system compliance with GDPR, data-privacy regulations, and financial-industry data handling requirements</p>

</li>

<li>

<p>Perform AI-specific data risk assessments aligned with the internal risk methodology</p>

</li>

<h3>AI Tool Risk &amp; Shadow AI:</h3>

<ul>

<li>

<p>Operate the controls that govern AI tool use across the organisation — detection policies, sanctioned-tool enforcement, share-link and egress controls</p>

</li>

<li>

<p>Lead third-party AI tool due diligence and ongoing assurance of AI vendor integrations</p>

</li>

<li>

<p>Monitor AI tool usage patterns and investigate anomalous behaviour</p>

</li>

<li>

<p>Contribute to AI security standards, internal policies, and the company's AI risk classification framework</p>

</li>

<h3>Compliance &amp; Governance:</h3>

<ul>

<li>

<p>Own the AI security governance framework: policy authoring, risk classification, control design, and regulatory mapping</p>

</li>

<li>

<p>Maintain the AI risk register and report on AI-related risk posture to management</p>

</li>

<li>

<p>Map AI security controls against applicable regulatory frameworks: EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR, and financial-sector requirements across FCA, CySEC, ASIC, SCB, and SCA jurisdictions</p>

</li>

<li>

<p>Participate in audit cycles; provide technical evidence and explain AI control design to auditors and regulators</p>

</li>

</ul></ul></ul></ul></ul>

Required Qualifications:

<ul>

<li>

<p>3–5+ years in cybersecurity with hands-on experience in AI/ML system security or a strong AI security focus;</p>

</li>

<li>

<p>Deep knowledge of AI-specific security risks and mitigations: prompt injection, model poisoning, data leakage, adversarial attacks, excessive permissions in AI agents;</p>

</li>

<li>

<p>Hands-on experience securing LLM integrations, RAG pipelines, and AI APIs — reviewing configurations, access controls, and data flows;</p>

</li>

<li>

<p>Experience authoring AI security policies, standards, and risk classification frameworks;</p>

</li>

<li>

<p>Familiarity with AI governance frameworks: EU AI Act, NIST AI RMF, ISO/IEC 42001, and their application in a regulated financial services context;</p>

</li>

<li>

<p>Experience running AI risk assessments and maintaining an AI risk register;</p>

</li>

<li>

<p>Ability to manage third-party AI tool due diligence and control shadow AI across a distributed workforce;</p>

</li>

<li>

<p>Python proficiency for automation and scripting.</p>

</li>

</ul>

Preferred Qualifications:

<ul>

<li>

<p>Recognised certifications: CISM, CISSP, or equivalent;</p>

</li>

<li>

<p>Experience in fintech or a regulated financial services environment;</p>

</li>

<li>

<p>Multi-jurisdiction compliance exposure (FCA, CySEC, ASIC, SCB, or SCA);</p>

</li>

<li>

<p>Experience building AI-powered security automation — autonomous agents, LLM-driven triage, automated response workflows;</p>

</li>

<li>

<p>Experience presenting AI security risk posture to leadership or board-level audiences.</p>

</li>

</ul>

Soft Skills:

<ul>

<li>

<p>Strong analytical and problem-solving skills;</p>

</li>

<li>

<p>Ability to translate technical AI risk into business and regulatory impact;</p>

</li>

<li>

<p>Able to explain AI security risks and mitigations to non-security teams;</p>

</li>

<li>

<p>Cross-functional collaboration with risk, compliance, product, and engineering teams;</p>

</li>

<li>

<p>Clear documentation and communication skills.</p>

</li>

</ul>

What you will get in return:

•&nbsp;<strong>Competitive Salary:</strong>&nbsp;We believe great work deserves great pay! Your skills and talents will be rewarded with a salary that makes you feel valued and motivated.

•&nbsp;<strong>Work-Life Harmony:&nbsp;</strong>Join a company that genuinely cares about you - because your life outside of work matters just as much as your time on the clock. #LI-Hybrid

•&nbsp;<strong>Generous Time Off:&nbsp;</strong>Need a breather? Our annual leave policy lets you recharge and enjoy life outside of work without a worry.

•&nbsp;<strong>Employee Referral Program:&nbsp;</strong>Love working here? Share the love! Bring your talented friends on board and get rewarded for growing our awesome team.

•&nbsp;<strong>Comprehensive Health &amp; Pension Benefits:&nbsp;</strong>From medical insurance to pension plans, we’ve got your back. Plus, location-specific benefits and perks!

•&nbsp;<strong>Workation Wonderland:&nbsp;</strong>Live your digital nomad dreams with 30 extra days to work remotely from anywhere in the world (some restrictions apply). Adventure awaits!

•&nbsp;<strong>Volunteer Days:&nbsp;</strong>Make a difference! Take two additional paid days each year to support causes you care about and give back to the community.

Be a key player at the forefront of the digital assets movement, propelling your career to new heights!&nbsp;Join a dynamic and rapidly expanding company that values and rewards talent, initiative, and creativity.&nbsp;Work alongside one of the most brilliant teams in the industry.

One of thousands of fresh listings refreshed nightly, built for cleared & defense careers.

Browse all jobs