# Corporate Security Engineer, AI

[Capital](https://gurify.com/jobs?q=Capital) · Warsaw, Poland · Posted 3 weeks ago

Hybrid

[AI & ML](https://gurify.com/jobs/ai-ml)

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.lever.co/capital/692d8bfd-30c2-4965-a3d2-4f2526d15da7)

## Job description

Corporate Security Engineer, AI
Company: capital.com
Location: Limassol, Cyprus / Sofia City, Bulgaria / Warsaw, Mazowieckie, Poland
Type: Hybrid

We are looking for a Corporate Security Engineer, AI to own the security of how artificial intelligence is adopted and operated across Capital.com.

AI tools are already embedded in how the company works — and the security risks they introduce are unlike those any other team currently owns. This role sits in Corporate Security and is responsible for AI system integration security, AI-specific threat detection, data protection in AI contexts, shadow AI governance, and the regulatory compliance obligations that AI adoption brings with it.

The ideal candidate understands how LLMs, RAG systems, and AI automation tools actually work — and can apply that understanding to evaluate what risks they introduce, design controls that hold, and build the governance framework that makes AI adoption secure and auditable in a regulated financial services environment.

\n

Key Responsibilities:
AI/ML Security — Integrations & Environment:

-
Review and assess the security of AI system integrations across the corporate environment: LLM deployments, RAG pipelines, AI APIs, and AI-enabled automation tools

-
Evaluate configuration, access controls, and data flows of AI systems — the security of how AI is deployed and connected to corporate data and infrastructure

-
Conduct threat modelling for AI integrations and define secure deployment patterns for AI-powered tools

-
Support security reviews for new AI initiatives, tools, and vendor integrations before they reach production

### AI Threat Detection & Mitigation:

-
Identify and mitigate AI-specific threats: prompt injection & jailbreaks, model poisoning & data contamination, adversarial attacks, training-data leakage, insecure model serialisation, excessive permissions in AI agents

-
Develop guardrails, content filters, and output-validation mechanisms

-
Implement monitoring for anomalous AI behaviour across integrated systems

### AI Data Egress & Data Protection:

-
Own data protection controls in AI contexts: govern what data reaches LLM integrations, AI APIs, and AI-enabled tools

-
Design and maintain DLP policies specifically for AI channels — share links, API-connected AI tools, AI browser extensions, and automation agents

-
Ensure AI system compliance with GDPR, data-privacy regulations, and financial-industry data handling requirements

-
Perform AI-specific data risk assessments aligned with the internal risk methodology

### AI Tool Risk & Shadow AI:

-
Operate the controls that govern AI tool use across the organisation — detection policies, sanctioned-tool enforcement, share-link and egress controls

-
Lead third-party AI tool due diligence and ongoing assurance of AI vendor integrations

-
Monitor AI tool usage patterns and investigate anomalous behaviour

-
Contribute to AI security standards, internal policies, and the company's AI risk classification framework

### Compliance & Governance:

-
Own the AI security governance framework: policy authoring, risk classification, control design, and regulatory mapping

-
Maintain the AI risk register and report on AI-related risk posture to management

-
Map AI security controls against applicable regulatory frameworks: EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR, and financial-sector requirements across FCA, CySEC, ASIC, SCB, and SCA jurisdictions

-
Participate in audit cycles; provide technical evidence and explain AI control design to auditors and regulators

### Required Qualifications:

-
3–5+ years in cybersecurity with hands-on experience in AI/ML system security or a strong AI security focus;

-
Deep knowledge of AI-specific security risks and mitigations: prompt injection, model poisoning, data leakage, adversarial attacks, excessive permissions in AI agents;

-
Hands-on experience securing LLM integrations, RAG pipelines, and AI APIs — reviewing configurations, access controls, and data flows;

-
Experience authoring AI security policies, standards, and risk classification frameworks;

-
Familiarity with AI governance frameworks: EU AI Act, NIST AI RMF, ISO/IEC 42001, and their application in a regulated financial services context;

-
Experience running AI risk assessments and maintaining an AI risk register;

-
Ability to manage third-party AI tool due diligence and control shadow AI across a distributed workforce;

-
Python proficiency for automation and scripting.

### Preferred Qualifications:

-
Recognised certifications: CISM, CISSP, or equivalent;

-
Experience in fintech or a regulated financial services environment;

-
Multi-jurisdiction compliance exposure (FCA, CySEC, ASIC, SCB, or SCA);

-
Experience building AI-powered security automation — autonomous agents, LLM-driven triage, automated response workflows;

-
Experience presenting AI security risk posture to leadership or board-level audiences.

### Soft Skills:

-
Strong analytical and problem-solving skills;

-
Ability to translate technical AI risk into business and regulatory impact;

-
Able to explain AI security risks and mitigations to non-security teams;

-
Cross-functional collaboration with risk, compliance, product, and engineering teams;

-
Clear documentation and communication skills.

What you will get in return:
• Competitive Salary: We believe great work deserves great pay! Your skills and talents will be rewarded with a salary that makes you feel valued and motivated.

• Work-Life Harmony: Join a company that genuinely cares about you - because your life outside of work matters just as much as your time on the clock. #LI-Hybrid

• Generous Time Off: Need a breather? Our annual leave policy lets you recharge and enjoy life outside of work without a worry.

• Employee Referral Program: Love working here? Share the love! Bring your talented friends on board and get rewarded for growing our awesome team.

• Comprehensive Health & Pension Benefits: From medical insurance to pension plans, we’ve got your back. Plus, location-specific benefits and perks!

• Workation Wonderland: Live your digital nomad dreams with 30 extra days to work remotely from anywhere in the world (some restrictions apply). Adventure awaits!

• Volunteer Days: Make a difference! Take two additional paid days each year to support causes you care about and give back to the community.

\n

Be a key player at the forefront of the digital assets movement, propelling your career to new heights! Join a dynamic and rapidly expanding company that values and rewards talent, initiative, and creativity. Work alongside one of the most brilliant teams in the industry.

**Live in Capital’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- CN [Customer Success Engineer – AI Security](https://gurify.com/job/customer-success-engineer-ai-security-at-cato-networks-0893592a2178) Cato Networks · Warsaw, Poland · 7 weeks ago
- TA [Data & Analytics](https://gurify.com/job/data-analytics-at-tango-737a7e168013) Tango · Warszawa, Poland · last week
- BJ [Backend Engineer, AI (Agent Systems)](https://gurify.com/job/backend-engineer-ai-agent-systems-at-bjak-6d07470e5f9a) Bjak · Poland · 4 weeks ago
- BJ [Product Manager - AI Neobank App](https://gurify.com/job/product-manager-ai-neobank-app-at-bjak-164409d7b0ba) Bjak · Poland · 3 weeks ago
- AD [Staff AI Security Engineer](https://gurify.com/job/staff-ai-security-engineer-at-addepar1-b9f9ad310cbf) Addepar1 · Remote, United States · 6 days ago
- NI [Cloud & AI Security Operations Engineer](https://gurify.com/job/cloud-ai-security-operations-engineer-at-nice-47f323349d60) Nice · 2 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Corporate Security Engineer, AI","description":"\u003Cp\u003ECorporate Security Engineer, AI\u003Cbr /\u003ECompany: capital.com\u003Cbr /\u003ELocation: Limassol, Cyprus / Sofia City, Bulgaria / Warsaw, Mazowieckie, Poland\u003Cbr /\u003EType: Hybrid\u003C/p\u003E\u003Cp\u003EWe are looking for a Corporate Security Engineer, AI to own the security of how artificial intelligence is adopted and operated across Capital.com.\u003C/p\u003E\u003Cp\u003EAI tools are already embedded in how the company works \u2014 and the security risks they introduce are unlike those any other team currently owns. This role sits in Corporate Security and is responsible for AI system integration security, AI-specific threat detection, data protection in AI contexts, shadow AI governance, and the regulatory compliance obligations that AI adoption brings with it.\u003C/p\u003E\u003Cp\u003EThe ideal candidate understands how LLMs, RAG systems, and AI automation tools actually work \u2014 and can apply that understanding to evaluate what risks they introduce, design controls that hold, and build the governance framework that makes AI adoption secure and auditable in a regulated financial services environment.\u003C/p\u003E\u003Cp\u003E\\n\u003C/p\u003E\u003Cp\u003EKey Responsibilities:\u003Cbr /\u003EAI/ML Security \u2014 Integrations \u0026amp; Environment:\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EReview and assess the security of AI system integrations across the corporate environment: LLM deployments, RAG pipelines, AI APIs, and AI-enabled automation tools\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EEvaluate configuration, access controls, and data flows of AI systems \u2014 the security of how AI is deployed and connected to corporate data and infrastructure\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EConduct threat modelling for AI integrations and define secure deployment patterns for AI-powered tools\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003ESupport security reviews for new AI initiatives, tools, and vendor integrations before they reach production\u003C/p\u003E\u003Ch3\u003EAI Threat Detection \u0026amp; Mitigation:\u003C/h3\u003E\u003Cp\u003E-\u003Cbr /\u003EIdentify and mitigate AI-specific threats: prompt injection \u0026amp; jailbreaks, model poisoning \u0026amp; data contamination, adversarial attacks, training-data leakage, insecure model serialisation, excessive permissions in AI agents\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EDevelop guardrails, content filters, and output-validation mechanisms\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EImplement monitoring for anomalous AI behaviour across integrated systems\u003C/p\u003E\u003Ch3\u003EAI Data Egress \u0026amp; Data Protection:\u003C/h3\u003E\u003Cp\u003E-\u003Cbr /\u003EOwn data protection controls in AI contexts: govern what data reaches LLM integrations, AI APIs, and AI-enabled tools\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EDesign and maintain DLP policies specifically for AI channels \u2014 share links, API-connected AI tools, AI browser extensions, and automation agents\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EEnsure AI system compliance with GDPR, data-privacy regulations, and financial-industry data handling requirements\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EPerform AI-specific data risk assessments aligned with the internal risk methodology\u003C/p\u003E\u003Ch3\u003EAI Tool Risk \u0026amp; Shadow AI:\u003C/h3\u003E\u003Cp\u003E-\u003Cbr /\u003EOperate the controls that govern AI tool use across the organisation \u2014 detection policies, sanctioned-tool enforcement, share-link and egress controls\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003ELead third-party AI tool due diligence and ongoing assurance of AI vendor integrations\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EMonitor AI tool usage patterns and investigate anomalous behaviour\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EContribute to AI security standards, internal policies, and the company\u0026#39;s AI risk classification framework\u003C/p\u003E\u003Ch3\u003ECompliance \u0026amp; Governance:\u003C/h3\u003E\u003Cp\u003E-\u003Cbr /\u003EOwn the AI security governance framework: policy authoring, risk classification, control design, and regulatory mapping\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EMaintain the AI risk register and report on AI-related risk posture to management\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EMap AI security controls against applicable regulatory frameworks: EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR, and financial-sector requirements across FCA, CySEC, ASIC, SCB, and SCA jurisdictions\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EParticipate in audit cycles; provide technical evidence and explain AI control design to auditors and regulators\u003C/p\u003E\u003Ch3\u003ERequired Qualifications:\u003C/h3\u003E\u003Cp\u003E-\u003Cbr /\u003E3\u20135\u002B years in cybersecurity with hands-on experience in AI/ML system security or a strong AI security focus;\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EDeep knowledge of AI-specific security risks and mitigations: prompt injection, model poisoning, data leakage, adversarial attacks, excessive permissions in AI agents;\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EHands-on experience securing LLM integrations, RAG pipelines, and AI APIs \u2014 reviewing configurations, access controls, and data flows;\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EExperience authoring AI security policies, standards, and risk classification frameworks;\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EFamiliarity with AI governance frameworks: EU AI Act, NIST AI RMF, ISO/IEC 42001, and their application in a regulated financial services context;\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EExperience running AI risk assessments and maintaining an AI risk register;\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EAbility to manage third-party AI tool due diligence and control shadow AI across a distributed workforce;\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EPython proficiency for automation and scripting.\u003C/p\u003E\u003Ch3\u003EPreferred Qualifications:\u003C/h3\u003E\u003Cp\u003E-\u003Cbr /\u003ERecognised certifications: CISM, CISSP, or equivalent;\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EExperience in fintech or a regulated financial services environment;\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EMulti-jurisdiction compliance exposure (FCA, CySEC, ASIC, SCB, or SCA);\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EExperience building AI-powered security automation \u2014 autonomous agents, LLM-driven triage, automated response workflows;\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EExperience presenting AI security risk posture to leadership or board-level audiences.\u003C/p\u003E\u003Ch3\u003ESoft Skills:\u003C/h3\u003E\u003Cp\u003E-\u003Cbr /\u003EStrong analytical and problem-solving skills;\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EAbility to translate technical AI risk into business and regulatory impact;\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EAble to explain AI security risks and mitigations to non-security teams;\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003ECross-functional collaboration with risk, compliance, product, and engineering teams;\u003C/p\u003E\u003Cp\u003E-\u003Cbr /\u003EClear documentation and communication skills.\u003C/p\u003E\u003Cp\u003EWhat you will get in return:\u003Cbr /\u003E\u2022\u0026#160;Competitive Salary:\u0026#160;We believe great work deserves great pay! Your skills and talents will be rewarded with a salary that makes you feel valued and motivated.\u003C/p\u003E\u003Cp\u003E\u2022\u0026#160;Work-Life Harmony:\u0026#160;Join a company that genuinely cares about you - because your life outside of work matters just as much as your time on the clock. #LI-Hybrid\u003C/p\u003E\u003Cp\u003E\u2022\u0026#160;Generous Time Off:\u0026#160;Need a breather? Our annual leave policy lets you recharge and enjoy life outside of work without a worry.\u003C/p\u003E\u003Cp\u003E\u2022\u0026#160;Employee Referral Program:\u0026#160;Love working here? Share the love! Bring your talented friends on board and get rewarded for growing our awesome team.\u003C/p\u003E\u003Cp\u003E\u2022\u0026#160;Comprehensive Health \u0026amp; Pension Benefits:\u0026#160;From medical insurance to pension plans, we\u2019ve got your back. Plus, location-specific benefits and perks!\u003C/p\u003E\u003Cp\u003E\u2022\u0026#160;Workation Wonderland:\u0026#160;Live your digital nomad dreams with 30 extra days to work remotely from anywhere in the world (some restrictions apply). Adventure awaits!\u003C/p\u003E\u003Cp\u003E\u2022\u0026#160;Volunteer Days:\u0026#160;Make a difference! Take two additional paid days each year to support causes you care about and give back to the community.\u003C/p\u003E\u003Cp\u003E\\n\u003C/p\u003E\u003Cp\u003EBe a key player at the forefront of the digital assets movement, propelling your career to new heights!\u0026#160;Join a dynamic and rapidly expanding company that values and rewards talent, initiative, and creativity.\u0026#160;Work alongside one of the most brilliant teams in the industry.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"corporate-security-engineer-ai-at-capital-1a9cc64a63a7"},"url":"https://gurify.com/job/corporate-security-engineer-ai-at-capital-1a9cc64a63a7","datePosted":"2026-07-27","validThrough":"2026-10-02T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Capital","sameAs":"https://jobs.lever.co/capital"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"PL","addressLocality":"Warsaw"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Poland","item":"https://gurify.com/jobs/poland"},{"@type":"ListItem","position":3,"name":"Corporate Security Engineer, AI","item":"https://gurify.com/job/corporate-security-engineer-ai-at-capital-1a9cc64a63a7"}]}
```
