Senior AI Security Architect
Charlotte, NC, US, 28202
SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 employees worldwide in nearly 40 countries. Sumitomo Mitsui Financial Group, Inc. (SMFG) is the holding company of SMBC Group, which is one of the three largest banking groups in Japan. SMFG’s shares trade on the Tokyo, Nagoya, and New York (NYSE: SMFG) stock exchanges.
In the Americas, SMBC Group has a presence in the US, Canada, Mexico, Brazil, Chile, Colombia, and Peru. Backed by the capital strength of SMBC Group and the value of its relationships in Asia, the Group offers a range of commercial and investment banking services to its corporate, institutional, and municipal clients. It connects a diverse client base to local markets and the organization’s extensive global network. The Group’s operating companies in the Americas include Sumitomo Mitsui Banking Corp. (SMBC), SMBC Nikko Securities America, Inc., SMBC Capital Markets, Inc., SMBC MANUBANK, JRI America, Inc., SMBC Leasing and Finance, Inc., Banco Sumitomo Mitsui Brasileiro S.A., and Sumitomo Mitsui Finance and Leasing Co., Ltd.
JOB SUMMARY
As the Senior AI Security Architect, you will lead the design, governance, and advancement of the enterprise AI security architecture program. You will define security strategy, architecture standards, governance models, and technical controls that enable the organization to adopt Artificial Intelligence (AI), Generative AI, Machine Learning, and Agentic AI securely and responsibly. This role combines strategic leadership with deep technical architecture expertise and serves as the senior security authority for AI-related initiatives across the enterprise. You will partner closely with engineering, cloud, data, model risk, privacy, legal, compliance, cyber defense, and business teams to ensure security is embedded throughout the AI lifecycle while supporting innovation, regulatory compliance, and business objectives.
PRINCIPAL DUTIES AND RESPONSIBILITIES
- Define and maintain the enterprise AI security architecture strategy, standards, reference architectures, and guardrails for AI, Generative AI, Machine Learning, and Agentic AI solutions.
- Lead the design of secure-by-design architecture patterns across data ingestion, model development, model training, deployment, inference, Retrieval-Augmented Generation (RAG), agent orchestration, and ongoing operations.
- Conduct and oversee AI security architecture reviews, threat models, and risk assessments for enterprise AI platforms, business applications, cloud AI services, third-party AI providers, and open-source AI technologies.
- Identify and mitigate AI-specific threats, including prompt injection, jailbreaking, model poisoning, adversarial attacks, model inversion, unauthorized model access, excessive agent autonomy, sensitive data exposure, and AI supply chain risks.
- Establish and strengthen security controls for AI platforms, cloud environments, identity and access management, privileged access management, secrets management, data protection, monitoring, logging, model lifecycle security, and runtime enforcement capabilities.
- Develop enterprise reference architectures and governance requirements for foundation models, third-party AI services, AI-enabled business solutions, autonomous agents, and emerging AI technologies.
- Partner with architecture, engineering, cloud, data, privacy, legal, compliance, model risk, and cyber defense teams to integrate AI security requirements into solution design, development, testing, deployment, monitoring, and operational processes.
- Serve as the senior AI security architect and trusted advisor to executive leadership, governance committees, and technology stakeholders on AI security risks, control requirements, regulatory expectations, and architectural decisions.
- Define architecture requirements for Agentic AI solutions, including authorization boundaries, tool access controls, human oversight requirements, audit logging, runtime monitoring, and containment mechanisms.
- Lead AI threat modeling, security assessments, red teaming activities, control validation exercises, and security reviews for high-risk AI implementations.
- Evaluate emerging AI technologies and security capabilities and provide strategic recommendations regarding enterprise adoption, risk management, and security architecture direction.
- Support regulatory examinations, audits, risk assessments, and governance reviews by defining security controls, architecture standards, and evidence requirements for AI-enabled solutions.
POSITION SPECIFICATIONS
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Engineering, Artificial Intelligence, or a related field, or equivalent combination of education, certifications, and experience.
- 12+ years of experience in cybersecurity, security architecture, secure engineering, technology risk management, or related disciplines.
- 7+ years of experience leading enterprise security architecture initiatives, architecture teams, or strategic cybersecurity programs.
- Strong knowledge of enterprise security architecture, networking, operating systems, web applications, APIs, software development, automation, cloud security, and modern cybersecurity practices.
- Experience performing architecture reviews, threat modeling, risk analysis, security assessments, and control design across complex enterprise environments.
- Deep understanding of cyber threats, attack techniques, security monitoring, incident response, penetration testing, red teaming, and security control validation.
- Experience designing and securing cloud environments, including AWS, Microsoft Azure, and Google Cloud Platform.
- Strong knowledge of identity and access management, including Active Directory, Azure Active Directory, identity governance, multi-factor authentication, certificate management, machine identities, and privileged access controls.
- Deep understanding of AI, Machine Learning, Large Language Models (LLMs), Generative AI, Retrieval-Augmented Generation (RAG), model operations, and Agentic AI architectures.
- Experience securing AI-enabled applications, APIs, model integrations, cloud-native services, AI platforms, and third-party AI capabilities.
- Knowledge of AI-specific security risks and controls, including prompt security, model integrity, adversarial machine learning, AI governance, model monitoring, and runtime security controls.
- Experience supporting audits, regulatory assessments, governance reviews, and risk management activities within highly regulated industries.
- Experience aligning AI and cybersecurity controls with frameworks such as NIST, ISO, OWASP, SOX, SWIFT, AI risk management frameworks, model risk management standards, and applicable regulatory requirements.
- Strong executive communication and stakeholder management skills with the ability to explain complex technical concepts and risks to senior management and business leaders.
- Understanding of third-party AI risk, model provenance, responsible AI principles, data governance, privacy obligations, and enterprise governance processes.
- Experience developing security standards, architecture principles, reference architectures, and governance frameworks for enterprise technology initiatives.
- Professional certifications such as CISSP, CISM, CCSP, GIAC, GSEC, CSSLP, SABSA, cloud security certifications, or AI governance certifications a plus.
SMBC’s employees participate in a Hybrid workforce model that provides employees with an opportunity to work from home, as well as, from an SMBC office. SMBC requires that employees live within a reasonable commuting distance of their office location. Prospective candidates will learn more about their specific hybrid work schedule during their interview process. Hybrid work may not be permitted for certain roles, including, for example, certain FINRA-registered roles for which in-office attendance for the entire workweek is required.
SMBC provides reasonable accommodations during candidacy for applicants with disabilities consistent with applicable federal, state, and local law. If you need a reasonable accommodation during the application process, please let us know at accommodations@smbcgroup.com.
Nearest Major Market: Charlotte