AI Security

Il y a 5 heures

Brussels, Belgique Salt Temps plein

AI Security & Governance Architect | GenAI / LLM / RAG / Agentic AI

Location: Belgium – candidates must already be based in Belgium or be happy to relocate themselves to belgium within 1-2 months.

Rate: €900 - €1200 per day (12 month contract +extension)

Working Model: Hybrid – 8 days per month onsite, remainder remote

Engagement: Contract



Considering applying for this job Do not delay, scroll down and make your application as soon as possible to avoid missing out.

Role Overview

We are seeking an experienced AI Security & Governance Architect to join a CISO organisation and help define, design and embed the security capabilities required to support the organisation's rapidly evolving adoption of AI.


This is a senior role sitting at the intersection of AI, Cyber Security, Security Architecture and Governance. The successful candidate will work across IT Risk, Security Architecture, security engineering and operational security, while partnering closely with AI architects, engineers, data scientists, product owners and technology teams.


The role requires someone who understands modern AI architectures at a technical level – including Generative AI, LLMs, RAG and Agentic AI – and can translate emerging AI risks into practical security controls, reusable architecture patterns, governance frameworks and a sustainable AI Security roadmap.


This is not purely an AI Governance position. The successful candidate must be technically credible and capable of understanding AI architectures, threat modelling them and designing appropriate security controls.


Key Accountabilities

1. AI Security Governance

Define and validate the AI Security target state, principles, scope and multi-year capability roadmap, aligned with CISO and Technology priorities.

Design and embed the AI Security governance model, including:

  • Decision rights and accountabilities
  • RACI
  • Security approval gates
  • Escalation paths
  • Risk acceptance and exceptions
  • Evidence and assurance requirements

Develop and maintain policies, standards, minimum security requirements, control objectives and implementation guidance for AI systems and AI-enabled technology.


Create an AI Security control baseline, ensuring governance and control design reflects recognised frameworks and guidance including:

  • OWASP guidance for LLM and Agentic AI applications
  • MITRE ATLAS
  • SAFE AI framework
  • NIST AI Risk Management Framework
  • ISO/IEC 42001
  • ISO/IEC 23894
  • Applicable AI, cyber-security and regulatory requirements


2. Secure AI Architecture & Reusable Security Controls

Build and maintain AI threat scenarios, attack-surface maps and risk scenario catalogues, using OWASP and MITRE ATLAS as key threat references.

Assess current and target AI architectures including:

  • LLMs and other models
  • Datasets and data pipelines
  • RAG architectures
  • Embeddings and vector stores
  • Model APIs
  • Orchestration layers
  • Tools and plugins
  • Memory
  • Agent workflows
  • Inference and deployment environments

Design and publish reusable AI Security requirements, reference architectures and security patterns.

Define appropriate:

  • Trust boundaries
  • Identity and access models
  • Secrets management
  • Data-security rules
  • Network protections
  • API and tool security
  • Runtime safeguards
  • Logging and monitoring
  • Security testing
  • Human oversight

Translate business and technical requirements into secure AI solution architectures that are scalable, supportable and proportionate to risk.


3. AI Security Readiness & Capability Roadmap

Assess the organisation's current AI Security maturity across people, processes and technology.

Identify quick wins, structural gaps and capability dependencies and translate these findings into prioritised remediation plans and clear definitions of done.

Design target capabilities covering areas including:

  • AI data security
  • Identity and secrets
  • Secure AI supply chain
  • AI system security testing
  • Vulnerability management
  • Logging and monitoring
  • Threat detection
  • Incident response

Establish clear roadmaps, milestones, deliverables, ownership and progress reporting for the implementation of these capabilities.