xelys jobs xelys jobs

AI Security Governance Architect

Plain Concepts

full-remoteseniorpermanentsecurityengineering-management Full remote 65 days ago via WTTJ

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

AI SecurityGenAILLM SecuritySecurity GovernanceRisk ManagementGRCDevSecOpsCloud SecurityEU AI ActData Privacy

About the role

Role Overview

Join Plain Concepts (working for Nestlé) as an AI Security Governance Architect. You will support the client’s AI Security Governance Program by defining, operationalizing, and continuously improving a cybersecurity control framework for AI, GenAI, and agentic AI use cases.

Responsibilities

  • Define and continuously improve the cybersecurity control framework for AI/GenAI across the full lifecycle.
  • Work with security, architecture, and business teams to ensure AI initiatives are:
    • registered,
    • assessed,
    • governed, and
    • secured.
  • Act as the AI governance cybersecurity subject matter expert by translating AI-related risks into:
    • practical controls, processes, and requirements,
    • evidence expectations, and
    • decision criteria.
  • Build governance that is operationally executable (not just policy documents).

Key Requirements

  • Strong understanding of AI/GenAI security risks, especially for LLM applications, including:
    • prompt injection
    • data leakage
    • model supply chain
    • AI agent permissions
    • RAG security
    • model/API exposure and third-party AI usage
  • 8+ years in cybersecurity with experience in one or more of:
    • security governance
    • security architecture
    • risk management
    • AppSec/CloudSec
  • Experience building/using enterprise control frameworks and running AI governance programs.
  • Experience in ML/LLM model risk management and Data Security Posture Management.
  • Ability to produce executive-ready documentation and clear technical control definitions.

Nice-to-Haves

  • Familiarity with AISPM and GenAI application security reviews.
  • Experience with SOC monitoring for AI-related threats.
  • Cloud security architecture experience.
  • GRC tooling and control evidence automation.
  • Secure SDLC / DevSecOps.
  • Third-party AI vendor risk management.
  • Tool familiarity (examples): HiddenLayer, Sentra, Zenity, Wiz, Microsoft Purview, Defender, CSPM/CWPP, DLP, SIEM/SOAR.
  • AI agent governance experience.
  • Certifications:
    • CISSP, CISM, CRISC (or equivalent)
    • Cloud security certs: AWS, Azure, GCP, CCSP
  • Privacy knowledge: GDPR, DPIA, data classification.
  • Familiarity with the EU AI Act requirements for deployers of high-risk AI systems (governance, monitoring, human oversight, logging where applicable).

Location/Work Model

  • Full remote

About Plain Concepts

Plain Concepts is a technology consulting and services company focused on helping enterprises design and operationalize governance and security programs. The role described is centered on AI security governance, aligning cybersecurity controls with AI/GenAI/agentic AI lifecycle needs for a major client (Nestlé).

Scraped 5/21/2026