← Trabalhos

Solution Architect, Agentic AI with Security and Compliance Focus (hands-on, long-term)

Orçamento: $50.0 - $70.0 HOURLY / FULL_TIME ⭐ 0.00 (0) CHE

python, small-10-99-employees, software-architecture, solution-architecture, typescript, react-js, application-security, cloud-security

Qualificações preferidas

  • Tipo de talento: Independente
  • Localização: Europe
  • Experiência: Especialista
  • Inglês: Fluente
  • Job Success: 80%+
  • Rising Talent preferido
ABOUT SWISPER Swisper is a Swiss AI platform for regulated industries. We build multi-agent orchestration that runs across institutions rather than inside a single company. Our first deployments are live in production, with SBB, the Swiss national railway, as our mobility partner since August 2026. We build on existing foundation models and do not train our own. We are looking for one senior contractor who combines business architecture, solution architecture, hands-on development and IT security in the same person. Remote, full-time, long-term, with occasional travel. Please note: we are hiring an individual freelancer. We do not consider agencies, agency accounts, staffing firms or subcontracted teams. Proposals from agencies will not be reviewed. THE WORK - Design the end-to-end architecture of the agentic AI solutions: business capabilities and processes, agent design, integrations, data flows and infrastructure. - Own the security architecture: threat models for prompt injection and tool misuse, permission and identity models for agent actions, data classification and residency, secrets handling, and audit trails that survive a review. - Build what you design. You work in our stack with Claude Code, our MCP servers, domain agents and supervisor agent, and you deliver running code alongside the architecture. - Close the loop to delivery. You write the specifications, keep the backlog sharp and drive features from concept to launch with our engineering team. - Translate regulatory requirements (DORA, EU AI Act, FINMA outsourcing, FADP and GDPR) into concrete technical controls our engineers can implement. - Drive our security certifications to completion: SOC 2 Type II and ISO 27001. You design the control set, close the gaps in our platform and processes, prepare the evidence, and run the engagement with the audit firm. - Maintain the certified state afterwards: control owners, recurring evidence collection, internal reviews, and readiness for annual surveillance audits. - Carry the security due diligence that regulated clients run on us: architecture documentation, security questionnaires, third-party risk assessments, and remediation of penetration test findings. - Run workshops and architecture reviews with client architects and security officers, remotely and occasionally on site. WHAT YOU BRING - A track record as solution architect or technical lead on systems that reached production in a regulated industry, ideally banking, insurance or public infrastructure. - Hands-on engineering in Python and TypeScript, with real API and integration work. You still "write" code every day. - Genuine security depth: application and cloud security, IAM, secure integration patterns, threat modelling. Certifications such as ISC2, CISSP, CCSP, TOGAF or SABSA are welcome, evidence of practice counts more. - Working knowledge of LLM-based systems: retrieval, tool calling, MCP, agent orchestration, and how to test a system whose output is not deterministic. - The ability to run a workshop with business stakeholders and then argue implementation detail with an engineer, credibly in both rooms. - Resilience. You stay precise when three client deadlines collide and a production issue lands on top. - Fluent English, written and spoken, at a level that holds up in front of a client. - Full working-day overlap with Central European Time. - Willingness to travel to Zurich and client sites ad hoc, at our cost. EU base strongly preferred. NICE TO HAVE - German at working level. - Experience taking a company through SOC 2 or ISO 27001 for the first time, on the company side rather than the audit side. - Wealth management, payments or core banking integration experience. - Compliance automation, or having been on the receiving end of an audit. - Product ownership experience in an agile setup, SAFe or comparable. WHAT THIS ENGAGEMENT IS REALLY LIKE We are a small team running production systems for regulated clients at startup pace. That means real deadlines, client escalations and stretches where the load is heavy and sustained. We expect full ownership when something breaks, and this should be your primary engagement rather than one of several you run in parallel. In exchange you get short decisions, direct contact with the founders, and an architecture decision that can be in production the same week. You are taking over an established scope with a structured handover, so you inherit context rather than a blank page. ENGAGEMENT - Start: immediately - 42 hours per week, hourly contract, long-term - Remote, EU base - Individual freelancers only, no agencies - NDA signed before access to our platform and client material
Abrir na Upwork

AI proposal draft

Generate a short cover letter for this job. Edit before sending.

Sign in to generate an AI proposal draft.

Entrar