29 Sep
|
NLB Services
|
Noida
29 Sep
NLB Services
Noida
Scope of Responsibility
PLATFORM ARCHITECTURE
- Own the overall technical architecture of a multi-agent AI platform defining component boundaries, data flows, integration patterns, and deployment topologies across cloud environments (Azure and GCP)
- Architect the Model Abstraction Layer decoupling agent orchestration logic from specific model providers and versions, enabling zero-downtime model upgrades and multi-cloud model serving flexibility
- Define and maintain the Blue-Green deployment architecture parallel environment management, traffic shifting strategy, rollback procedures, and regression testing gates for model version changes
- Design scalable Kubernetes-based deployment topology (AKS / GKE) node pool architecture, namespace isolation, pod security policies, Workload Identity Federation, resource quota management
SECURITY ARCHITECTURE
- Architect the BYOC (Bring Your Own Cloud) deployment model ensuring all platform components operate within the client institution's cloud tenant with zero data egress to Anaptyss infrastructure
- Design the offline cryptographic licensing system — RSA-4096 JWT-based license enforcement that operates without network dependency, supporting both air-gapped and hybrid deployment modes
- Define encryption architecture: CMEK via Azure Key Vault / GCP Cloud KMS for at-rest encryption; TLS 1.3 for in-transit; confidential computing enclaves for in-processing
- Architect network security posture: VPC Service Controls (GCP) / Azure Private Endpoints, Private Service Connect / Private Link for model serving, no public IP surfaces on core components
- Define identity and access architecture: AAD/Entra ID or Google Cloud Identity SSO integration, Workload Identity Federation for service-to-service authentication, RBAC with principle of least privilege
- Design audit logging architecture — immutable audit trail system capturing every agent action, HITL decision, evidence retrieval, and output version in structured, tamper-evident form
AI SYSTEM ARCHITECTURE
- Architect the agentic pipeline framework — multi-stage workflow orchestration, inter-agent communication protocols, state persistence across HITL gates, and graceful degradation on component failure
- Define the RAG (Retrieval Augmented Generation) architecture — embedding model selection, vector store integration, chunking and indexing strategy, retrieval precision and recall optimisation, context window management for large document corpora
- Design deterministic tool architecture — separation of AI reasoning layer from data retrieval layer, tool interface contracts, error handling, evidence validation logic, and auditability of every data access operation
- Architect stateless agent execution — ensuring no cross-session memory accumulation, no passive learning from runtime data, and full reproducibility of pipeline outputs given equivalent inputs
CLOUD & INFRASTRUCTURE ARCHITECTURE
- Design multi-cloud deployment architecture supporting both Azure and GCP — abstracting cloud-specific components behind common interfaces while leveraging cloud-native managed services appropriately on each platform
- Architect data persistence layer: relational database (Azure SQL / Cloud SQL PostgreSQL)
for structured outputs and audit trail; object storage (Azure Blob / GCS) for document and artefact storage — with appropriate partitioning, indexing, retention, and CMEK encryption
- Design observability architecture: telemetry strategy (Azure Monitor + App Insights / GCP Cloud Monitoring + Cloud Logging) that provides operational visibility while keeping all telemetry within the client's cloud tenant
- Define container image supply chain security: image signing (Sigstore/Binary Authorization), registry architecture (Azure Container Registry / Google Artifact Registry), Kubernetes admission control for signature verification
INTEGRATION ARCHITECTURE
- Design the enterprise system integration layer — defining connectivity patterns for read-only evidence retrieval from ERP, identity/access management, GRC, and workflow systems across on-premises and cloud-hosted environments
- Architect GRC platform integration — defining output delivery formats (JSON, PDF, CSV), API-based and file-based delivery patterns, and data mapping between ANA's output schema and client GRC platform import specifications
- Define the client deployment package architecture — Helm charts, Terraform modules, container image delivery via shared registry, cryptographic signature verification, and zero-Anaptyss-access deployment process
Required Experience & Skills
ARCHITECTURE & SYSTEMS DESIGN — ESSENTIAL
- 8+ years in enterprise software architecture, with at least 3 years in AI/ML platform architecture
- Demonstrable experience designing production systems that were deployed in regulated environments — financial services, healthcare, government, or equivalent — where architectural decisions had compliance and regulatory implications
- Deep expertise in cloud-native architecture on Azure and/or GCP — proven ability to design production systems using managed services, Kubernetes, IAM, encryption, and networking on at least one platform; working familiarity with the other
- Experience designing BYOC (Bring Your Own Cloud) or tenant-isolated deployment models — where customer data must remain within the customer's cloud environment
- Hands-on experience with confidential computing — Azure Confidential Computing (DCv3/Intel SGX), GCP Confidential VMs (AMD SEV/Intel TDX), or equivalent — at the architecture level (not necessarily implementation detail)
AI PLATFORM ARCHITECTURE — ESSENTIAL
- Deep understanding of LLM inference architecture — model serving patterns, API integration, token economics, latency optimisation, and failure mode handling at production scale
- Hands-on experience architecting agentic AI systems — multi-agent orchestration, tool use frameworks, ReAct patterns, state management across agent handoffs
- RAG system architecture experience — embedding model selection and deployment,
vector database design (pgvector, Pinecone, Weaviate, Vertex AI Vector Search, or equivalent), retrieval pipeline optimisation
- LLMOps / MLOps architecture — model versioning strategy, Blue-Green model deployment, regression testing gates, monitoring for model drift and output quality degradation
- Understanding of LLM security attack surfaces — prompt injection, data exfiltration via model outputs, context window manipulation — and architectural mitigations
SECURITY ARCHITECTURE — ESSENTIAL
- Cryptographic systems design — asymmetric key cryptography (RSA), JWT architecture, offline license enforcement, key management lifecycle
- Cloud security architecture — encryption at rest (CMEK), encryption in transit (TLS), encryption in processing (confidential computing), secrets management, network perimeter design
- Identity and access architecture — SSO integration (SAML/OIDC), Workload Identity Federation, RBAC design, principle of least privilege applied at cloud IAM level
- Audit logging and compliance architecture — immutable log design, audit trail completeness, log retention and tamper-evidence for regulated environments
- Familiarity with bank technology risk frameworks — OCC guidelines, Federal Reserve SR Letters, FFIEC guidance — sufficient to understand what an examiner will look for in a system architecture review
ENGINEERING CREDIBILITY — ESSENTIAL
- Ability to produce architecture artefacts that engineering teams can build from — not high-level slides but component diagrams, data flow specifications, interface contracts, security boundary definitions, and deployment topology documentation
- Experience producing technical documentation for external review — by enterprise architecture teams, information security teams, model risk management functions, and regulatory examiners
- Proficiency in Python and/or TypeScript — sufficient to review code, prototype architectural concepts, and engage credibly with engineering teams on implementation decisions
Robust Advantages:
- Experience engaging directly with bank technology risk, information security, or enterprise architecture teams as a vendor — having your architecture reviewed, questioned, and approved through institutional governance processes
- Multi-cloud architecture experience — having designed and deployed the same logical system on both Azure and GCP with appropriate cloud-native service mapping
- Experience with confidential computing at implementation depth — enclave programming, attestation, sealed storage
- Background in designing licensing and IP protection systems for software deployed in customer environments
- SOC 2 Type II audit preparation — having worked with auditors to document and evidence security controls
What We Offer:
- A technically demanding problem space that very few architect roles offer — governed agentic AI in federally regulated environments, combining confidential computing, multi-cloud security, and LLM architecture
- Exposure to the most technically sophisticated buyers in enterprise software — bank CDOs, Chief AI Officers, and Enterprise Architects who will probe every architectural decision
📌 Artificial Intelligence Architect (Noida)
🏢 NLB Services
📍 Noida