AI Enablement & Governance - AI Security & Controls Lead
Listed on 2026-07-27
-
IT/Tech
Cybersecurity, Information Security & Data Protection, AI Engineer (Applied/Software), AI Evaluation
AI Enablement & Governance – Security & Controls Lead
The AI Enablement & Governance – Security & Controls Lead enables secure, responsible, and scalable AI adoption by defining, implementing, and evaluating AI-specific security and risk controls across the AI lifecycle.
This role serves as a bridge between AI engineering, information security, privacy, and third-party risk teams, ensuring that incremental AI risks introduced by models, training data, RAG architectures, and autonomous or semi-autonomous agents are appropriately controlled by design.
The role partners closely with AI Engineering, Third-Party Supplier Governance, Information Security, Privacy, and Risk teams to identify AI-specific control gaps, define practical control requirements, support secure implementation, and evaluate effectiveness. The focus is on AI-specific security concerns—not replacing existing security programs, but extending them thoughtfully for AI.
ResponsibilitiesAI Security, Policy, Standards & Guidance
- Partnering directly with AI Engineers & Developers, Information Security and governance teams to define AI-specific security and risk management standards covering AI/ML models, RAG solutions, and agentic architectures.
- Translating enterprise security principles and risk frameworks into AI-appropriate guidance, addressing topics such as, model access control and abuse prevention, prompt and context security, data leakage, memorization, and inference risks, agent autonomy boundaries and safeguards
- Define AI runtime monitoring and incident response expectations, aligned to (and extending as needed) existing incident response playbooks.
- Ensuring AI security guidance remains aligned with evolving technology patterns, external expectations, and internal architectures, and external expectations (e.g. NIST AI RMF/CSF, NYDFS AI Cybersecurity, ISO/IEC 42001)
- Contributing to the broader AI policy hierarchy by ensuring security requirements are clearly mapped to AI governance policies, controls and standards.
Third-Party AI & Model Risk Support
- Partnering with third-party risk and supplier governance teams to Identify AI-specific risks introduced by vendors, models, platforms, and APIs.
- Defining AI security control expectations for vendors and managed services
- Supporting evaluation of vendor AI security posture, including training data handling, model protections, monitoring, and incident response capabilities.
- Contributing AI-specific input to due diligence, onboarding, and ongoing vendor risk assessments.
Cross-Functional Enablement & Advisory Support
- Acting as a trusted advisor to AI engineering, product, privacy, and security teams on how to safely design and deploy AI systems.
- Providing practical guidance that balances security rigor with business velocity.
- Helping teams understand what "secure by design" means for AI, without imposing unnecessary friction.
- 5+ years of relevant experience (or equivalent expertise) in information security, technology risk, AI governance, model risk management, privacy engineering, or related roles.
- Strong understanding of AI architectures, Machine learning pipelines, Retrieval-augmented generation (RAG), Agentic and tool-using AI patterns
- Demonstrated ability to translate technical AI and security concepts into clear control expectations and guidance.
- Experience working cross-functionally with engineering, security, privacy, and risk teams.
- Practical, risk-based mindset with strong judgment and attention to detail.
- Excellent written communication skills; ability to create clear, defensible documentation.
- Relevant certifications preferred (e.g., AAISM, CISSP, CISM, CRISC, AIGP, cloud security certifications).
- Bachelor's degree in Computer Science, Engineering, or related field, or equivalent practical experience
Application and Interview
By applying for a position with Alight, you understand that, should you be made an offer, it will be contingent on your undergoing and successfully completing a background check consistent with Alight's employment policies. Background checks may include some or all the following based on the nature of the position: SSN/SIN validation, education verification,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).