praktikumjobs.ch
← All jobs

Cybersecurity Consulting Internship – AI Gateway: benchmarking solutions and securing the AI gateway

Wavestone1

Employment type
Internship
Location
Switzerland
First posted
Apply now

The adoption of generative AI in companies has become massive in just a few months: multiplication of model providers, business applications, copilots and now autonomous agents. This proliferation most often occurs without a single point of entry: each team directly consumes provider APIs, with its own keys, its own quotas and its own rules, which deprives the company of any consolidated visibility into usages, costs and data transmitted to the models.

In response, a new architectural component is becoming essential: the AI Gateway, a gateway centralizing all calls to AI models. Much like what API Gateways were for application architectures, it handles multi-model routing, key and quota management, cost control, observability, but also and above all, security controls specific to AI: prompt and response filtering, protection against prompt injection, sensitive data leak prevention, access compartmentalization and traceability for compliance purposes (GDPR, nLPD, EU AI Act). The market is currently structuring, with heterogeneous offerings: open source solutions, cloud vendor building blocks and specialized players. Our clients, in Switzerland and elsewhere, are currently questioning us about the choice and securing of this component that has become critical.

  1. Internship objective
  2. The study phase

Reporting to the Swiss office of Wavestone, the objective of the internship is to conduct a tool-based benchmark of AI Gateway solutions on the market and to define, then demonstrate, a secure reference architecture allowing a company to centralize and control all of its generative AI usages.

Preparatory work:

The achievement of the objectives requires preparatory work on the following points:

  • State of the art of the AI Gateway: positioning within an enterprise architecture, differences with a classic API Gateway, mapping of market solutions (open source, cloud vendors, specialized players) and their deployment models.
  • Panorama of risks specific to generative AI and their frameworks (OWASP Top 10 for LLMs, MITRE ATLAS, NIST AI RMF, EU AI Act, nLPD/GDPR) in order to identify the controls that the gateway must actually carry.
  • Collection of use cases and constraints representative of our clients: multi-vendor, data sovereignty and hosting, regulated sectors (banking, health, public sector), consumption by autonomous agents and by business applications.

We propose an internship structured around the following objectives:

Objective 1: Build an evaluation grid and benchmark AI Gateway solutions on the market

  • Define an objective and weighted evaluation grid covering the major expected axes of a gateway: security functionalities, routing and multi-model support, cost and quota governance, observability, performance (latency, throughput), integration into the existing ecosystem (IAM, SIEM, CI/CD) and solution maturity.
  • Select a representative panel of solutions, deploy them in a laboratory and confront them with comparable test scenarios, in order to produce measured rather than declarative results.
  • Formalize the results in the form of a comparison exploitable in missions: strengths and limits of each solution, recommendation scenarios by client typology and associated costs.

Objective 2: Define a reference architecture for the securing of the AI Gateway

  • Design a reference architecture positioning the gateway as a single control point: authentication and authorization of consumers (users, applications, agents), centralized management of secrets and provider keys, compartmentalization by environment and by use case.
  • Specify the security controls to be applied to flows: prompt and response filtering, detection and blocking of prompt injections, sensitive data leak prevention (DLP, anonymization), safeguards on the use of tools by agents, rate limiting and protection against abuse.
  • Define the detection and compliance component: exploitable logging of calls, indicators and alerts reported to the SOC, traceability of data transmitted to models and evidence elements expected by regulators.

Objective 3: Test the selected architecture in a realistic environment

  • Implement a demonstrator in an isolated laboratory: deployment of the selected solution, connection of several model providers (open models executed locally and commercial) and representative consuming applications, including an autonomous agent.
  • Test the robustness of controls through an offensive testing campaign on the demonstrator: direct and indirect prompt injection, data exfiltration, filter bypassing, abusive use of quotas and tools exposed to agents.
  • Capitalize on the lessons learned in a form directly reusable in missions: commented target architecture, secure configuration framework, AI Gateway audit checklist and deployment recommendations.
  1. Contributions to the consulting firm

As a trainee consultant, you will also be required to contribute to the operational missions of our clients.

We also give you the possibility to participate actively in the internal life of the firm through:

  • Support for the development of our Cybersecurity expertise: contribution to prospecting actions and the preparation of commercial proposals.
  • Monitoring and internal sharing on the securing of generative AI: evolutions of the AI Gateway market, frameworks and applicable regulatory frameworks.
  • Production of materials aimed at acculturating other firm employees to the uses and limits of these technologies.
  • Participation in even

Automatically translated from the original.

Posted 1 week ago