About the Role
The Senior Principal Cyber Security Architect – AI will act as the lead security architecture advisor for AI-related initiatives across the organisation, providing strategic and technical guidance to ensure AI systems are designed, deployed, and operated securely. This role will identify AI-specific security risks and define practical controls to protect AI-enabled services, shaping the organisation’s AI security architecture, governance, and standards.
Responsibilities
- Provide senior security architecture leadership for AI initiatives, ensuring AI systems and services are secure by design and aligned with enterprise cyber security strategy, risk appetite, and regulatory expectations.
- Define and maintain AI security principles, standards, guardrails, reference architectures, design patterns, and production readiness criteria across the AI lifecycle.
- Advise on secure architecture for AI platforms, MLOps pipelines, data pipelines, model registries, vector databases, RAG solutions, prompt orchestration layers, APIs, AI agents, and cloud-based AI services.
- Design and support implementation of security controls across identity and access management, privileged access, secrets management, encryption, key management, network security, secure APIs, logging, monitoring, resilience, and incident response.
- Conduct AI-focused risk assessments, threat modelling, architecture reviews, and control gap assessments for new and existing AI use cases.
- Identify and support mitigation of AI-specific risks, including data leakage, prompt injection, model extraction, model inversion, training data poisoning, insecure output handling, excessive agency, insecure RAG implementations, supply chain compromise, and unauthorised access.
- Partner with engineering, data science, platform, and security teams to embed security into AI development, MLOps, CI/CD pipelines, deployment workflows, and operational monitoring.
- Advise on secure handling of training, validation, test, and production data, including data minimisation, anonymisation, access control, retention, lineage, provenance, and protection of confidential or regulated information.
- Assess security risks associated with third-party AI platforms, foundation models, SaaS AI tools, APIs, open-source models, datasets, plugins, extensions, and model marketplaces.
- Define security requirements for AI vendor due diligence, procurement, onboarding, contractual review, and ongoing supplier assurance.
- Work with security operations and incident response teams to define AI-specific logging, monitoring, detection, investigation, and response requirements.
- Monitor AI security developments, emerging threats, attack techniques, industry standards, and regulatory expectations, translating them into practical internal controls and guidance.
- Promote AI security awareness across engineering, production, data science, business, and technology teams through guidance, workshops, reusable patterns, and stakeholder engagement.
- Support the Director of Cyber Security Architecture with AI security strategy, governance, reporting, and other duties as required.
Requirements
- Significant experience in cyber security architecture, application security, cloud security, platform security, data security, or technology risk.
- Practical understanding of AI, machine learning, generative AI, large language models, MLOps, cloud AI services, and AI-enabled application architectures.
- Experience designing, reviewing, or implementing security controls for complex technology environments.
- Experience conducting risk assessments, threat modelling, security architecture reviews, and control gap assessments.
- Understanding of AI-specific threats, including prompt injection, data leakage, data poisoning, model extraction, model inversion, insecure output handling, supply chain compromise, and misuse of AI agents.
- Knowledge of secure software development, DevSecOps, CI/CD pipelines, APIs, identity and access management, encryption, logging, monitoring, and vulnerability management.
- Experience working with cloud platforms and modern data architectures.
- Ability to translate complex technical risks into clear business language for senior stakeholders.
- Strong communication, documentation, stakeholder management, and influencing skills.
- Experience working with AI/ML engineering teams, data science teams, AI platform teams, or product teams delivering AI-enabled services.
- Experience with MLOps platforms, model registries, feature stores, vector databases, RAG architectures, prompt orchestration frameworks, or AI agent frameworks.
- Experience with AI, GenAI, or LLM security testing, red teaming, or adversarial testing.
- Familiarity with relevant AI security and governance frameworks such as NIST AI RMF, OWASP Top 10 for LLM Applications, MITRE ATLAS, ISO/IEC 42001, ISO 27001, NCSC/CISA secure AI guidance, CSA AI Controls Matrix, and applicable AI or privacy regulations.
- Experience assessing third-party AI services, SaaS AI tools, open-source models, foundation model providers, or cloud AI platforms.
- Experience creating security standards, control frameworks, technical patterns, policies, or governance processes.
- Experience in a regulated industry such as financial services, healthcare, telecommunications, energy, defence, or critical infrastructure would be advantageous.
Skills
- Cyber security architecture
- Application security
- Cloud security
- Platform security
- Data security
- Technology risk
- AI
- Machine learning
- Generative AI
- Large language models
- MLOps
- Cloud AI services
- AI-enabled application architectures
- Risk assessments
- Threat modelling
- Security architecture reviews
- Control gap assessments
- AI-specific threats
- Prompt injection
- Data leakage
- Data poisoning
- Model extraction
- Model inversion
- Insecure output handling
- Supply chain compromise
- Misuse of AI agents
- Secure software development
- DevSecOps
- CI/CD pipelines
- APIs
- Identity and access management
- Encryption
- Logging
- Monitoring
- Vulnerability management
- Cloud platforms
- Modern data architectures
- Communication
- Documentation
- Stakeholder management
- Influencing skills
- AI/ML engineering
- Data science
- AI platform development
- Product development
- MLOps platforms
- Model registries
- Feature stores
- Vector databases
- RAG architectures
- Prompt orchestration frameworks
- AI agent frameworks
- AI security testing
- GenAI security testing
- LLM security testing
- Red teaming
- Adversarial testing
- NIST AI RMF
- OWASP Top 10 for LLM Applications
- MITRE ATLAS
- ISO/IEC 42001
- ISO 27001
- NCSC/CISA secure AI guidance
- CSA AI Controls Matrix
- AI regulations
- Privacy regulations
- Third-party AI services assessment
- SaaS AI tools assessment
- Open-source models assessment
- Foundation model provider assessment
- Cloud AI platform assessment
- Security standards development
- Control framework development
- Technical pattern development
- Policy writing
- Governance process development
- Regulated industry experience
- Risk management
- Pragmatic security control design
- Analytical skills
- Problem-solving skills
- Cross-functional collaboration
- Working with ambiguity
- Working with emerging technology
- Working in fast-moving delivery environments
- Standards development
- Policy writing
Experience Level
- Senior
Salary/Compensations
- CAD $129000 to $180000 annually
Benefits
- Flexible working environment
- Volunteer time off
- LinkedIn Learning
- Employee-Assistance-Program (EAP)
About the Company
- NIQ is the world’s leading consumer intelligence company, delivering the most complete understanding of consumer buying behavior and revealing new pathways to growth.
- In 2023, NIQ combined with GfK, bringing together the two industry leaders with unparalleled global reach.
- With a holistic retail read and the most comprehensive consumer insights—delivered with advanced analytics through state-of-the-art platforms—NIQ delivers the Full View™.
- NIQ is an Advent International portfolio company with operations in 100+ markets, covering more than 90% of the world’s population.
Equal Opportunity
- All employment decisions at NIQ are made without regard to race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, genetic information, marital status, veteran status, or any other characteristic protected by applicable laws.
- NIQ may utilize artificial intelligence (AI) tools at various stages of the recruitment process, including résumé screening, candidate assessments, interview scheduling, job matching, communication support, and certain administrative tasks that help streamline workflows.
- These tools are intended to improve efficiency and support fair and consistent evaluation based on job-related criteria.
- All use of AI is governed by NIQ’s principles of fairness, transparency, human oversight, and inclusion.
- Final hiring decisions are made exclusively by humans.
- NIQ regularly reviews its AI tools to help mitigate bias and ensure compliance with applicable laws and regulations.
- If you have questions, require accommodations, or wish to request human review were permitted by law, please contact your local HR representative.
- For more information, please visit NIQ’s AI Safety Policies and Guiding Principles: https://nielseniq.com/global/en/info/niqs-ai-safety-policies/
- We invite individuals who share our dedication to inclusivity and equity to join us in making a meaningful impact.
- To learn more about our ongoing efforts in diversity and inclusion, please visit the https://nielseniq.com/global/en/news-center/diversity-inclusion
