AI Security Architect
Security and resilience, a senior role
What does AI Security Architect do?
Designs the security of AI systems across their lifecycle: models, data pipelines, APIs, cloud environments and the agents that act inside them, secure by design rather than patched afterwards.
What it decides: The threat model and the controls every AI platform must carry before production.
The competencies employers name
- AI security fundamentalscore, depth expected
Understands prompt injection, data poisoning, model theft, insecure integrations and excessive agent privileges, and the controls that reduce each.
17 graded topics teach this
- Agentic AI controls and authorization boundariescore, depth expected
Governs AI agents that take actions: tool access, least privilege, interruptibility, cascading actions and accountability for what an agent did.
21 graded topics teach this
- How models work, at a governance depthcore, depth expected
Explains training, tokens, context windows, embeddings, retrieval and fine-tuning well enough to ask an engineer a precise question and spot weak evidence.
18 graded topics teach this
- Data classification, access and retentionrequired, working knowledge
Classifies information, applies least privilege, sets retention and acceptable-use rules, and controls what may enter a prompt, a log or an embedding.
19 graded topics teach this
- AI incident response and recoveryrequired, working knowledge
Classifies AI incidents by severity, runs containment, preserves evidence, manages notification, and closes the loop with lessons learned.
3 graded topics teach this
- AI vendor due diligence and third-party riskrequired, working knowledge
Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.
5 graded topics teach this
- AI evaluation and testing designrequired, working knowledge
Designs tests for factuality, robustness, fairness, safety and abuse resistance with rubrics, baselines and thresholds, and says what a score misses.
12 graded topics teach this
- AI governance operating model designpreferred, working knowledge
Designs decision rights, committees, intake, approval tiers and escalation so routine uses move and consequential uses get reviewed.
20 graded topics teach this
- Executive and board communication on AI riskpreferred, working knowledge
Turns technical uncertainty into a one-page decision: material risks, trends, exceptions, remediation, and what the board is being asked to accept.
10 graded topics teach this
Where it is taught
Counted from the graded topics that teach this role's competencies. Your own path is shorter: it skips what you already cover.
- Certified AI Practitioner: Workplace Foundations32 topics
- Certified AI Governance Professional (CAIGP)17 topics
- Certified AI Data Governance Professional (CADGP)16 topics
- Certified Agentic AI Governance Professional (CAAGP)13 topics
- Certified AI Transformation Professional (CATP)11 topics
- The AI Lobbyist: Certified AI Policy Strategist9 topics
- EU AI Act Implementation Expert9 topics
Check your readiness for this role
Add what you already have (optional)
Roles that feed into it
- Security Engineer
- Cloud Security Engineer
- Security Architect
- DevSecOps Engineer
Where it leads
- Principal AI Security Architect
- Director of AI Security
- Chief Information Security Officer, AI security focus
Backgrounds that reach it fastest
What postings tend to name
Frameworks: Google SAIF, OWASP Top 10 for LLM Applications, NIST AI RMF, Zero Trust.
Credentials often listed: CISSP, CCSP, CISA, CRISC, AIGP, Cloud security certifications. GAGE does not issue these and does not prepare for their exams; the record you earn here is your own graded evidence, which stands beside them.
Questions
- What threats are specific to AI systems?
- Prompt injection, data poisoning, model theft, adversarial inputs, supply-chain dependencies on third-party models, and agents that hold more privilege than any task needs.