Salt logo

AI Security & Governance Architect | GenAI / LLM / RAG / Agentic AI

Salt
Posted 3 hours ago
BelgiumHybrid€900–€1.2K/dayEngineering & Development
Is this job info correct?

AI Security & Governance Architect | GenAI / LLM / RAG / Agentic AI

Location: Belgium – candidates must already be based in Belgium or be happy to relocate themselves to belgium within 1-2 months.

Rate: €900 - €1200 per day (12 month contract +extension)

Working Model: Hybrid – 8 days per month onsite, remainder remote

Engagement: Contract


Role Overview

We are seeking an experienced AI Security & Governance Architect to join a CISO organisation and help define, design and embed the security capabilities required to support the organisation's rapidly evolving adoption of AI.


This is a senior role sitting at the intersection of AI, Cyber Security, Security Architecture and Governance. The successful candidate will work across IT Risk, Security Architecture, security engineering and operational security, while partnering closely with AI architects, engineers, data scientists, product owners and technology teams.


The role requires someone who understands modern AI architectures at a technical level – including Generative AI, LLMs, RAG and Agentic AI – and can translate emerging AI risks into practical security controls, reusable architecture patterns, governance frameworks and a sustainable AI Security roadmap.


This is not purely an AI Governance position. The successful candidate must be technically credible and capable of understanding AI architectures, threat modelling them and designing appropriate security controls.


Key Accountabilities

1. AI Security Governance

Define and validate the AI Security target state, principles, scope and multi-year capability roadmap, aligned with CISO and Technology priorities.

Design and embed the AI Security governance model, including:

  • Decision rights and accountabilities
  • RACI
  • Security approval gates
  • Escalation paths
  • Risk acceptance and exceptions
  • Evidence and assurance requirements

Develop and maintain policies, standards, minimum security requirements, control objectives and implementation guidance for AI systems and AI-enabled technology.


Create an AI Security control baseline, ensuring governance and control design reflects recognised frameworks and guidance including:

  • OWASP guidance for LLM and Agentic AI applications
  • MITRE ATLAS
  • SAFE AI framework
  • NIST AI Risk Management Framework
  • ISO/IEC 42001
  • ISO/IEC 23894
  • Applicable AI, cyber-security and regulatory requirements


2. Secure AI Architecture & Reusable Security Controls

Build and maintain AI threat scenarios, attack-surface maps and risk scenario catalogues, using OWASP and MITRE ATLAS as key threat references.

Assess current and target AI architectures including:

  • LLMs and other models
  • Datasets and data pipelines
  • RAG architectures
  • Embeddings and vector stores
  • Model APIs
  • Orchestration layers
  • Tools and plugins
  • Memory
  • Agent workflows
  • Inference and deployment environments

Design and publish reusable AI Security requirements, reference architectures and security patterns.

Define appropriate:

  • Trust boundaries
  • Identity and access models
  • Secrets management
  • Data-security rules
  • Network protections
  • API and tool security
  • Runtime safeguards
  • Logging and monitoring
  • Security testing
  • Human oversight

Translate business and technical requirements into secure AI solution architectures that are scalable, supportable and proportionate to risk.


3. AI Security Readiness & Capability Roadmap

Assess the organisation's current AI Security maturity across people, processes and technology.

Identify quick wins, structural gaps and capability dependencies and translate these findings into prioritised remediation plans and clear definitions of done.

Design target capabilities covering areas including:

  • AI data security
  • Identity and secrets
  • Secure AI supply chain
  • AI system security testing
  • Vulnerability management
  • Logging and monitoring
  • Threat detection
  • Incident response

Establish clear roadmaps, milestones, deliverables, ownership and progress reporting for the implementation of these capabilities.


4. Stakeholder Engagement & AI Security Expertise

Act as a senior CISO subject-matter expert for AI Security, providing authoritative guidance to Technology, AI delivery teams and control functions.


Partner with AI architects, engineers, data scientists, product owners and platform teams to ensure security is incorporated during solution design rather than becoming a late-stage compliance exercise.


Facilitate:

  • AI threat-modelling sessions
  • Architecture reviews
  • Security workshops
  • AI Security readiness assessments
  • Control-design discussions

Communicate AI Security risks, decisions and options effectively to technical teams, senior management, auditors, risk functions and regulators.

Monitor developments across AI security standards, threat intelligence, research and regulation and translate relevant changes into actionable internal requirements.


Candidate Profile

The successful candidate should have substantial experience within Cyber Security Architecture, Security Engineering, Technology Risk or Security Governance in a complex enterprise environment.


You should be able to demonstrate experience designing security controls and capabilities for AI systems across multiple security domains, rather than solely having theoretical knowledge of AI risk.


Strong knowledge of modern AI architecture is particularly important, including:

LLMs • Generative AI • Agentic AI • RAG • Embeddings • Vector Databases • Model APIs • Orchestration • AI Agents • Tools/Plugins • Data Pipelines • Inference & Deployment

You should also bring:

  • Strong AI Security governance and control-framework knowledge
  • AI/LLM threat-modelling experience
  • Security architecture and engineering experience
  • Experience defining reusable security controls and reference architectures
  • Understanding of model governance, assurance and auditability
  • Experience integrating security requirements into architecture, product delivery and SDLC processes
  • Working knowledge of OWASP LLM/GenAI, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001 and ISO/IEC 23894
  • Ability to translate emerging AI threats into practical technical and governance controls
  • Strong stakeholder-management skills across technical, security, risk and senior-management audiences

Experience within regulated financial services, critical infrastructure or another highly governed enterprise environment is strongly preferred.

A Master's degree, or equivalent professional experience, in Computer Science, Artificial Intelligence, Cyber Security, Engineering or a related discipline is preferred.

Working Arrangements


Candidates must already be based in Belgium.

The position operates on a hybrid model requiring 8 days per month onsite in Belgium, with the remainder of the assignment performed remotely.


This requirement would particularly suit someone who combines the technical credibility of an AI/GenAI Security Architect with the governance and strategic capabilities required to help a major organisation establish a mature, enterprise-wide AI Security capability.

Similar jobs