Lead Security Governance & Risk Engineer (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Lead Security Governance & Risk Engineer (Cybersecurity/AI): Managing and automating the technology and third-party risk registers with an accent on AI risk governance and quantitative risk analysis. Focus on implementing ISO 42001 readiness, automating risk scoring, and translating technical risks into financial business impact.
Location: Must be based in the United States
Company
empowers creators to own their destiny by making first-party data accessible and actionable for personalized experiences in ecommerce and beyond.
What you will do
- Operate and maintain the technology and third-party risk register and taxonomy.
- Lead AI risk governance and drive readiness for ISO/IEC 42001 certification.
- Develop automated risk scoring by integrating vendor and application risk signals.
- Perform cyber risk quantification using FAIR or similar methods to enable rational investment decisions.
- Coordinate with the Technology Risk Committee and provide independent oversight as a second line of defense.
- Collaborate cross-functionally with Engineering, Product, Legal, and Finance to track and remediate audit findings.
Requirements
- 7+ years of experience in information security, technology risk, or operational risk within complex organizations.
- Strong command of cyber risk quantification (FAIR, riskquant, or similar).
- Hands-on engineering ability with SQL, Python, and API integration for data ETL and automation.
- Working knowledge of NIST CSF, RMF, ISO 27000 series, ISO 42001, SOC 2, and PCI DSS.
- Ability to operate as a second line of defense and engage credibly with senior architects and security teams.
- Must be based in the United States.
Nice to have
- Experience evolving GRC models toward automated or AI-enabled risk capabilities.
- Expertise in AI governance, model risk, or responsible-AI programs.
- Proficiency with BI tools like Tableau for building KPI, KRI, and KCI dashboards.
- Relevant certifications such as CISSP, CISM, CRISC, Open FAIR, or ISO Lead Auditor.
- Experience with AWS security controls, Kubernetes, or container security.
Culture & Benefits
- Comprehensive health, welfare, and wellbeing benefits.
- Participation in an annual cash bonus plan and equity options.
- Inclusive environment that values unique backgrounds and encourages employees to be their whole self.
- Commitment to responsible AI use and high-trust security standards.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →