UK remote
Senior Security Engineer - AI
About this role
QRT is a global quantitative and systematic investment manager, operating across all liquid asset classes. We are a data- and technology-driven organization applying scientific methods to investing. Our collaborative culture and focus on innovation enable us to solve complex challenges and deliver high-quality returns for our investors. The AI Security function is engineering the controls that allow the firm to adopt frontier AI quickly and safely.
The function works across engineering, infrastructure, cloud and security to build controls into the platforms, inference gateways and developer tooling already used across the firm. Your future role within QRT We are seeking an exceptional Staff Security Engineer to join our AI Security function. The role is expected to involve the following activities: • Design and implement security controls in the inference gateways, platforms and developer tooling used across the firm, delivered as code and configuration.
• Embed controls in the systems that engineering teams already work in, so that the secure option is the default. • Define the standards and patterns other teams adopt when building with AI. • Define who an internal agent acts as, what it is permitted to reach and how those decisions are enforced. • Build telemetry that records what ran, on whose behalf and against what. • Establish how agent and automation activity is proven after the fact for audit and investigation.
• Secure developer harnesses, plugins, and the dependency and model provenance they rely on. • Own secrets handling and vulnerability management across the AI tooling the firm depends on. • Set provenance and integrity requirements for models and components introduced into the firm. • Threat model live systems across platform and gateway security, agent identity and permissioning, and the AI supply chain. • Deliver the remediation resulting from threat modelling directly.
• Identify gaps in control coverage and prioritise remediation against risk and delivery constraints. • Take and document control decisions in areas where no established answer exists. • Set and own the technical direction for the function’s core areas and help define how the function works. • Drive the adoption of secure defaults and governed identities and gateways with a reliable audit trail. Your present skillset • Experience with LLM platforms, inference gateways or agent frameworks.