HCLTech
Agentic AI Security Specialist

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Title: Agentic AI Security Specialist
Role Overview
As an Agentic AI Security Specialist, you will secure the bank’s autonomous, multi-agent AI ecosystems. Unlike static machine learning models, agentic systems possess tool-use capabilities, multi-step planning, and execution autonomy, introducing complex security boundaries.
You will design secure architectures, perform specialized threat modeling, conduct offensive security testing, and engineer advanced detection metrics to ensure autonomous agents operate safely within strict UK banking regulations.
Location: London, UK (Hybrid)
Sector: Highly Regulated Financial Services / Banking
Experience Level: Senior / Specialist
Experience & Background Requirements
Cyber Security Foundations:
- 5+ years of dedicated professional experience in Cyber Security Engineering, Security Architecture, Detection Engineering, or DevSecOps within highly regulated environments (ideally Banking/FinTech).
AI Security Domain:
- 2+ years of hands-on experience focusing explicitly on AI/ML Security, covering LLM guardrails, adversarial machine learning, or security engineering for automated execution pipelines.
Skill Matrix Overview
Core Domain
Primary Skills (Critical for Day 1)
- Security Architecture
- Threat Modeling
- Security Engineering
- Advanced Threat Protection
- DevOps
- Agile Methodology & Tools
- Threat Management
- Detection Engineering
- Offensive Security Testing
- Response Engineering
- Cyber Threat Hunting
- Digital Forensics
- Engineering & Strategy
- AI Literacy
- Python
- Go Programming Language
- Customer Centricity
- Continuous Learning
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Secondary Skills (Supportive & Operational)
Primary Roles & Responsibilities
Agentic Threat Modeling & Secure Engineering
- Perform specialized Threat Modeling on multi-agent orchestrations, focusing on tool-use vulnerabilities, autonomous execution manipulation, goal-jacking, and cascading agent failures.
- Architect secure execution environments (Security Engineering) and sandboxes to isolate autonomous agents, ensuring strict enforcement of the principle of least privilege.
- Implement real-time proxy guardrails and Advanced Threat Protection boundaries to intercept malicious prompts, indirect prompt injections, and data exfiltration vectors.
Offensive Simulation & Detection Engineering
- Execute Offensive Security Testing specifically mimicking adversarial machine learning tactics against agent reasoning loops, vector databases, and memory layers.
- Design custom Detection Engineering logic to identify anomalous agent behaviors, API misuses, and malicious intent vectors before downstream execution occurs.
- Develop automated orchestration pathways (Response Engineering) to instantly isolate, throttle, or terminate rogue agent threads without disrupting core systems.
Core Language & Automation Engineering
- Write production-grade security proxies, wrapper interfaces, and low-latency validation controls using Python and the Go Programming Language.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Secondary Roles & Responsibilities
Proactive Threat Hunting & Forensics
- Conduct proactive Cyber Threat Hunting exercises to uncover hidden signs of systemic poisoning, persistent agent manipulation, or silent model exploitation.
- Perform advanced Digital Forensics on complex agent memory logs, tracking step-by-step reasoning patterns and API execution loops following anomalous events.
Governance, Delivery, & Enablement
- Embed security guardrails smoothly into production deployment loops using DevOps pipelines (CI/CD) and automated testing frameworks.
- Operate within high-velocity teams using Agile Methodology & Tools (e.g., Jira, Confluence) to cleanly deliver tasks inside sprint timelines.
- Maintain a mindset of Customer Centricity, ensuring that heavy security layers and model guardrails do not negatively disrupt the user experience.
- Commitment to Continuous Learning, tracking the fast-evolving landscape of agentic frameworks (e.g., LangChain, AutoGen, CrewAI) and modern security benchmarks (MITRE ATLAS, OWASP Top 10 for LLMs).
Regulatory Context
Architectures must be engineered to comply natively with stringent UK and international banking regulations, including:
- DORA (Digital Operational Resilience Act): Ensuring operational resilience of autonomous systems under stress.
- FCA & PRA Guidelines: Adhering to strict compliance for automated decision-making pipelines and accountability frameworks.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location