Confidential mandate

Adversarial ML Robustness Director — Insurance Decisioning

Planned Hiring / New

Adversarial ML Robustness Director mandate in Vancouver, Canada · Insurance Decisioning

A Vancouver insurer needs an independent director to test model evasion, poisoning and extraction risks, delivering an accepted production-grade robustness operating model across five months.

The mandate

Pricing, fraud and document models are validated for statistical performance but not for strategic manipulation by applicants, brokers, organised fraud rings or compromised data suppliers. Existing penetration tests stop at APIs, while model validation assumes input distributions remain honest. The defined problem is to establish measurable robustness against evasion, poisoning, extraction and inference without redesigning the insurer's entire model-risk framework.

The deliverables are a threat-ranked model inventory, attacker-capability profiles, abuse test harness, robust-performance measures, training-data integrity controls, extraction monitoring, incident thresholds and an engineering-validation runbook. Tests must distinguish ordinary drift from deliberate manipulation, account for attacker adaptation and avoid exposing personal or underwriting-sensitive data in research environments.

Milestone one on 30 October 2026 delivers the agreed model perimeter and adversary hypotheses. Milestone two on 4 December provides validated attacks and baseline degradation; milestone three on 22 January 2027 completes mitigations and monitoring pilots across two models; final delivery on 26 February requires independent model-validation acceptance, operator training and repeatable regression execution.

The CRO, chief underwriter, model-validation head and CISO will accept delivery when attacks reproduce under controlled conditions, robustness measures preserve legitimate cohort performance within tolerance, monitoring detects seeded manipulation and client engineers execute the regression suite unaided. A mitigation that improves aggregate resistance while creating unexplained protected-group or customer effects will not pass final acceptance.

The client provides model artefacts, governed feature data, training lineage, API test environments, underwriting expertise, fraud cases and independent validators. The consultant cannot alter production decisions, approve model risk, determine customer treatment or retain sensitive training data outside authorised environments; client teams deploy every mitigation and preserve formal model ownership.

Why this is external work

Model developers and validators are equipped for performance and governance testing but lack concentrated experience of adaptive adversaries. Security testers do not normally evaluate model decision boundaries or training integrity. An independent specialist can create realistic abuse evidence without protecting an existing model or selling a replacement platform.

What you will own

  • Rank models by attacker incentive, query access, decision value, training influence and potential customer or financial harm.
  • Define evasion, poisoning, extraction and inference scenarios with realistic knowledge, budget, feedback and adaptation assumptions.
  • Build controlled attack harnesses that preserve test-data governance while producing reproducible model and business outcomes.
  • Measure robust performance by attack cost, decision degradation, legitimate-cohort effect, transferability and mitigation durability.
  • Design training-data provenance, anomaly review, rate control, output restriction and extraction-detection patterns for priority models.
  • Establish adversarial incident thresholds linking observed behaviour to investigation, model restriction, retraining and customer-impact review.
  • Transfer hypotheses, test code, result evidence and regression governance through client-run validation and engineering cycles.

Candidate qualifications

  • Led adversarial machine-learning assurance for deployed financial, insurance, fraud or other high-impact decision models.
  • Can evidence reproducible evasion, poisoning, extraction or inference tests that materially changed production model controls.
  • Quantified robustness alongside legitimate-user performance, fairness, operational latency and attacker adaptation rather than attack success alone.
  • Governed sensitive training data, feature lineage and test environments across model engineering, validation and cybersecurity teams.
  • Designed monitoring or rate controls that detected strategic model probing without relying on generic API-abuse thresholds.
  • Delivered a regression and incident method accepted by independent model risk and subsequently operated by internal teams.

Non-negotiables

  • Available for all Vancouver and Toronto milestones across the five-month calendar.
  • Independent of model, fraud, data and adversarial-testing vendors that could benefit from recommendations.
  • Will not export sensitive training data or make production underwriting and customer decisions.
  • Has director or principal-level adversarial-ML authority beyond conventional model validation or penetration testing.
  1. 49 words maximum. Which adversarial ML test most changed a deployed model's control design?
  2. 49 words maximum. How would you distinguish deliberate evasion from ordinary distribution drift?
  3. 49 words maximum. What acceptance measure prevents robustness work from harming legitimate customer cohorts?

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.