Principal Information Security Risk Management - AI
Core
Ensuring enterprise-wide Generative AI, Agentic AI, LLMs, and ML security programs are effective, risk-aligned, and defensible through independent challenge, governance, and validation.
Role type
Principal Information Security Risk Management (AI)
Builds
Secure and trustworthy GenAI and agent-based systems aligned to risk appetite and regulatory expectations
Domain
Financial services / AI Security
Deliverable
production ML models
Required skills
GenAI and LLM security, Three Lines of Defense model, risk-based governance, control validation, regulatory compliance, executive-level risk translation, fintech experience, NIST AI RMF, ISO/IEC 42001, secure AI development practices
Preferred skills
None explicitly stated
Technologies
LLMs, Agentic AI systems, orchestration frameworks, RAG pipelines, MCP, APIs
Responsibilities
Provide independent challenge and oversight of GenAI and agentic AI systems across design, deployment, and operation; Define and maintain AI security policies, standards, and control requirements for LLMs, prompt-based systems, and autonomous agents; Perform control validation and effectiveness testing for prompt handling, model outputs, agent autonomy, and data access; Assess and challenge risks related to prompt injection, data leakage, model misuse, and third-party models; Deliver risk-based reporting and insights on GenAI/agentic risks, control gaps, and systemic weaknesses; Provide oversight of AI platforms, orchestration frameworks, and tooling to ensure secure configuration and governance; Partner with First Line teams, Risk, Compliance, Legal, and Audit to ensure alignment with internal policies and emerging regulatory expectations; Support regulatory exams and internal audits as the AI Security Second Line SME
Seniority
Principal, strategy & mentorship