AI Security and Data Protection Governance and Controls VP
Listed on 2026-09-16
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Who We Are Looking For
We are looking for a Vice President, AI Security and Data Protection Governance and Controls reporting directly to the Managing Director, Data Protection. You will establish and oversee the enterprise governance framework for secure and resilient AI and data protection capabilities, translating strategy into policies, standards, controls, risk decisions, and measurable remediation programs. You will partner across Security, Technology, Risk, Compliance, Legal, Procurement, and the business to embed security-by-design, resilient controls, and adaptable technology standards and AI security and data protection requirements across enterprise platforms, applications, and third-party services.
Whythis role is important to us
The team you will be joining is part of Global Cybersecurity, a function vital to protecting the confidentiality, integrity, availability, and resilience of the firm’s information and technology environment. This role is critical to preparing the organization for emerging AI, data, and emerging technology risks, reducing long-term security and data protection risk, supporting regulatory and audit readiness, and coordinating a controlled transition to secure and resilient AI and data protection capabilities.
WhatYou Will Be Responsible For
- Establish and maintain the enterprise governance framework, policies, standards, decision rights, and accountability model for AI security, data protection, and emerging technology risk.
- Govern the discovery, inventory, classification, and risk assessment of AI models, data assets, security controls, platforms, applications, integrations, and technology dependencies.
- Define risk-based prioritization criteria using data sensitivity, retention period, business criticality, external exposure, and migration complexity, including long-term data exposure and emerging technology risk.
- Design minimum control requirements, testing procedures, evidence standards, exception processes, compensating controls, and remediation expectations across applications, infrastructure, cloud, networks, identity, and data platforms.
- Establish and oversee the enterprise roadmap for transitioning vulnerable security and data protection implementations to approved approved secure technologies and control solutions, including delivery milestones, control gates, dependencies, and risk escalation.
- Partner with Security Architecture and Engineering to embed AI security and data protection and security-by-design and adaptable control requirements into solution design, architecture reviews, engineering standards, and reusable implementation patterns.
- Define AI security and data protection requirements and due-diligence criteria for third-party products, cloud services, strategic vendors, contracts, and technology evaluations.
- Serve as the subject-matter authority for AI security and data protection governance in engagements with senior leadership, Risk, Compliance, Internal Audit, external auditors, clients, and regulators.
- Establish dashboards, key risk indicators, and performance measures for inventory coverage, AI and data risk exposure, control compliance, exceptions, migration progress, remediation, and residual risk.
- Lead and develop a team responsible for governance, control oversight, risk assessment, program coordination, and cross-functional execution.
These skills will help you succeed in this role
- Deep understanding of AI security, data protection, security architecture, governance, risk, and control principles, AI security and data protection, and security-by-design, resilient controls, and adaptable technology standards.
- Ability to translate complex technical and emerging risks into clear policies, standards, controls, investment priorities, and executive decisions.
- Strong governance, technology risk, control design, exception management, and assurance capabilities within a large, regulated organization.
- Proven leadership of complex, cross-functional cybersecurity or technology transformation programs with measurable outcomes and clear accountability.
- Executive communication and influencing skills across Security, Engineering, Infrastructure, Cloud, Application Development, Risk, Legal, Procurement, Audit, and business teams.
- Data-driven, risk-based decision making with strong attention to detail, strategic judgment, and a focus on sustainable risk reduction.
- Commitment to simplification, standardization, collaboration, and scalable governance.
Preferred…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).