Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Capital.com operates in the regulated financial services sector and is advancing the adoption of digital assets.
задачи
Review and assess the security of AI system integrations, including LLM deployments, RAG pipelines, AI APIs, and AI-enabled automation tools;
Evaluate AI system configurations, access controls, and data flows;
Conduct threat modelling for AI integrations and define secure deployment patterns;
Support security reviews for new AI initiatives, tools, and vendor integrations before production;
Identify and mitigate AI-specific threats, including prompt injection, jailbreaks, model poisoning, data contamination, adversarial attacks, training-data leakage, insecure model serialisation, and excessive permissions in AI agents;
Develop guardrails, content filters, and output-validation mechanisms;
Implement monitoring for anomalous AI behaviour across integrated systems;
Own data protection controls in AI contexts and govern data shared with LLM integrations, AI APIs, and AI-enabled tools;
Design and maintain DLP policies for AI channels, including share links, API-connected AI tools, AI browser extensions, and automation agents;
Ensure AI systems comply with GDPR, data-privacy regulations, and financial-industry data-handling requirements;
Perform AI-specific data risk assessments aligned with the internal risk methodology;
Operate controls governing organisation-wide AI tool use, including detection policies, sanctioned-tool enforcement, and share-link and egress controls;
Lead third-party AI tool due diligence and ongoing assurance of AI vendor integrations;
Monitor AI tool usage patterns and investigate anomalous behaviour;
Contribute to AI security standards, internal policies, and the company’s AI risk classification framework;
Own the AI security governance framework, including policy authoring, risk classification, control design, and regulatory mapping;
Maintain the AI risk register and report AI-related risk posture to management;
Map AI security controls against applicable frameworks, including the EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR, and financial-sector requirements across FCA, CySEC, ASIC, SCB, and SCA jurisdictions;
Participate in audit cycles, provide technical evidence, and explain AI control design to auditors and regulators.
требования
3–5+ Years of cybersecurity experience, with hands-on AI/ML system security experience or a strong AI security focus;
Deep knowledge of AI-specific security risks and mitigations, including prompt injection, model poisoning, data leakage, adversarial attacks, and excessive permissions in AI agents;
Hands-on experience securing LLM integrations, RAG pipelines, and AI APIs, including reviewing configurations, access controls, and data flows;
Experience authoring AI security policies, standards, and risk classification frameworks;
Familiarity with AI governance frameworks, including the EU AI Act, NIST AI RMF, and ISO/IEC 42001, and their application in regulated financial services;
Experience conducting AI risk assessments and maintaining an AI risk register;
Ability to manage third-party AI tool due diligence and control shadow AI across a distributed workforce;
Python proficiency for automation and scripting;
Strong analytical and problem-solving skills;
Ability to translate technical AI risk into business and regulatory impact;
Ability to explain AI security risks and mitigations to non-security teams;
Cross-functional collaboration skills with risk, compliance, product, and engineering teams;
Clear documentation and communication skills;
Nice to have: CISM, CISSP, or equivalent certifications; fintech or regulated financial services experience; multi-jurisdiction compliance exposure (FCA, CySEC, ASIC, SCB, or SCA); experience building AI-powered security automation, including autonomous agents, LLM-driven triage, and automated response workflows; experience presenting AI security risk posture to leadership or board-level audiences.
условия
Competitive salary; amount not specified;
Work-life harmony;
Generous annual leave;
Employee referral program;
Medical insurance and pension plans, plus location-specific benefits and perks;
30 Extra days to work remotely from anywhere in the world, subject to some restrictions;
Two additional paid volunteer days each year;
The company may use AI tools to support parts of the hiring process, including reviewing applications, analysing resumes, and assessing responses; these tools assist the recruitment team but do not replace human judgment, and final hiring decisions are made by humans.