AI Security Governance Architect
Plain Concepts
full-remoteseniorpermanentsecurityengineering-management Full remote 65 days ago via WTTJ
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
AI SecurityGenAILLM SecuritySecurity GovernanceRisk ManagementGRCDevSecOpsCloud SecurityEU AI ActData Privacy
About the role
Role Overview
Join Plain Concepts (working for Nestlé) as an AI Security Governance Architect. You will support the client’s AI Security Governance Program by defining, operationalizing, and continuously improving a cybersecurity control framework for AI, GenAI, and agentic AI use cases.
Responsibilities
- Define and continuously improve the cybersecurity control framework for AI/GenAI across the full lifecycle.
- Work with security, architecture, and business teams to ensure AI initiatives are:
- registered,
- assessed,
- governed, and
- secured.
- Act as the AI governance cybersecurity subject matter expert by translating AI-related risks into:
- practical controls, processes, and requirements,
- evidence expectations, and
- decision criteria.
- Build governance that is operationally executable (not just policy documents).
Key Requirements
- Strong understanding of AI/GenAI security risks, especially for LLM applications, including:
- prompt injection
- data leakage
- model supply chain
- AI agent permissions
- RAG security
- model/API exposure and third-party AI usage
- 8+ years in cybersecurity with experience in one or more of:
- security governance
- security architecture
- risk management
- AppSec/CloudSec
- Experience building/using enterprise control frameworks and running AI governance programs.
- Experience in ML/LLM model risk management and Data Security Posture Management.
- Ability to produce executive-ready documentation and clear technical control definitions.
Nice-to-Haves
- Familiarity with AISPM and GenAI application security reviews.
- Experience with SOC monitoring for AI-related threats.
- Cloud security architecture experience.
- GRC tooling and control evidence automation.
- Secure SDLC / DevSecOps.
- Third-party AI vendor risk management.
- Tool familiarity (examples): HiddenLayer, Sentra, Zenity, Wiz, Microsoft Purview, Defender, CSPM/CWPP, DLP, SIEM/SOAR.
- AI agent governance experience.
- Certifications:
- CISSP, CISM, CRISC (or equivalent)
- Cloud security certs: AWS, Azure, GCP, CCSP
- Privacy knowledge: GDPR, DPIA, data classification.
- Familiarity with the EU AI Act requirements for deployers of high-risk AI systems (governance, monitoring, human oversight, logging where applicable).
Location/Work Model
- Full remote
About Plain Concepts
Plain Concepts is a technology consulting and services company focused on helping enterprises design and operationalize governance and security programs. The role described is centered on AI security governance, aligning cybersecurity controls with AI/GenAI/agentic AI lifecycle needs for a major client (Nestlé).
Scraped 5/21/2026