AI Governance Security Engineer
Charleston, Kanawha County, West Virginia, 25329, USA
Listed on 2026-07-27
-
IT/Tech
AI Engineer (Applied/Software), Cybersecurity, AI Evaluation
What you can expect
You'll own risk assessment across four AI governance domains:
GenAI Security, Agentic AI Security, Shadow AI detection, and AI Gateway/Model Context Protocol governance, identifying where emerging AI use cases create exposure. Working with AI/ML teams and security engineering, you'll define the controls, tooling, and standards that enable Zoom to adopt AI safely 'll operationalize the AI Governance Risk Charter while contributing your security engineering judgment across network, endpoint, cloud, and data security domains.
Zoom's Enterprise Security team is building the security foundation for how AI is adopted, deployed, and governed across Zoom. Our team is lean and multi-domain, operating across AI governance, cloud, network, endpoint, and data security. We solve emerging risks through collaboration, shared ownership, and the ability to flex across domains rather than staying in narrow specializations.
Responsibilities- Conducting risk evaluations of AI use cases across GenAI, agentic AI, shadow AI, and AI gateway/MCP domains, scoring exposure using Likelihood and Impact methodology and maintaining the AI governance risk register.
- Identifying security gaps in GenAI deployments including prompt injection, data leakage, model misuse, and output handling, and recommending targeted controls.
- Assessing agentic AI systems for risks around autonomy, tool access, privilege escalation, and unintended action, and defining monitoring requirements.
- Detecting and evaluating shadow AI and local/unsanctioned AI usage, quantifying risk and recommending detection and enforcement approaches.
- Evaluating AI security tooling including AI gateways, CASB/SWG, Model Context Protocol governance solutions, and agentic monitoring platforms for functional requirements and integration.
- Contributing to security frameworks, architectural standards, and policies that translate the AI Governance Risk Charter into concrete technical requirements and control implementations.
- Applying security engineering judgment across network, endpoint, cloud, and data security domains to support architecture reviews, risk assessments, and incident response.
- Partnering with AI/ML, engineering, and enterprise teams through collaborative working groups to identify security solutions and tracking execution.
- Have 5+ years of experience in security engineering, cybersecurity, or a closely related field, demonstrated understanding of cybersecurity frameworks, compliance requirements, and emerging threat landscapes.
- Bring hands-on experience with risk assessment and risk management methodologies, including impact-based prioritization.
- Possess working knowledge of modern AI/ML systems and the security risks they introduce (LLMs, generative AI, agentic systems). Have working knowledge of core security domains beyond AI (e.g., network, endpoint, cloud, or data security) sufficient to contribute to architecture reviews and risk assessments.
- Bring experience securing GenAI, agentic AI, or LLM-based applications in enterprise environments would be a bonus. As well as familiarity with AI gateways, Model Context Protocol (MCP), CASB/SWG, or DLP tooling.
- Have experience detecting and governing shadow IT / shadow AI usage would be advantageous. As well as threat modeling experience applied to AI or novel technology environments.
- Leverage experience contributing to incident response, detection engineering, or purple team exercises would be a bonus.
Minimum:
$98,900.00
Maximum:
$
In addition to the base salary and/or OTE listed Zoom has a Total Direct Compensation philosophy that takes into consideration; base salary, bonus and equity value.
Note:
Starting pay will be based on a number of factors and commensurate with qualifications & experience.
We also have a location based compensation structure; there may be a different range for candidates in this and other locations
Anticipated Position Close Date:08/06/26
Ways of WorkingWays of Working Our structured hybrid approach is centered around our offices and remote work environments. The work style of each role, Hybrid, Remote, or In-Person…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).