岗位描述
Lead delivery of HSBC's enterprise AI Safety & Evaluation capability, aligned to Group AI strategy and Responsible AI goals. Build and run scalable AI safety testing (e.g., orange teaming, simulation, automated evals) and challenge guardrails, complementing Cyber and Model Risk Management testing. Translate technical findings into decision-ready business risk assessments (impact/likelihood, acceptance criteria, go/no-go recommendations) and evidence for governance, approvals, and audit. Test end-to-end solution controls (human-in-the-loop, monitoring, escalation, fallback/kill-switch), plus GenAI security risks (prompt injection, tool/RAG poisoning, permissions, agent controls). Assess data/privacy/information governance (provenance, usage rights, cross-border/retention, PII leakage, memorisation) and operational resilience (availability, latency, outage scenarios, safe degradation, drift/safety regression monitoring). Define risk-tiered metrics (KRIs/KPIs), automate regression benchmarks, and embed evaluation into LLMOps/CI/CD as release gates with traceable reporting. Contribute to internal standards, frameworks, and the operating model for AI safety assurance across the AI lifecycle, embedding responsible AI principles into measurable controls. Provide senior SME leadership across CAIO, Risk, Cyber, and AI teams; monitor emerging AI risks and industry developments; engage externally to shape best practice. Strong hands-on knowledge of AI/ML engineering, including GenAI/LLMs and common deployment patterns (APIs, pipelines, MLOps/LLMOps). Experience embedding guardrails and safety controls throughout model build and release lifecycles. Practical model evaluation experience across performance, bias/fairness, explainability, and robustness. Proven AI safety testing capability (red teaming, adversarial testing, scenario-based evaluation). Solid understanding of AI cyber threats (prompt injection, data leakage, adversarial attacks) and threat modelling; able to partner with Cyber teams to run threat-led testing. Familiar with risk/governance in regulated environments (MRM and operational risk), including documenting test outcomes and linking them to approval decisions. Experience applying recognised frameworks such as NIST AI RMF, ISO/IEC 42001, and MAESTRO.