Hybrid flexibility and a benefits package built to support everyday life and long-term security planning. This principal role supports enterprise and public sector customers by shaping AI governance and risk-informed security controls for AI-native network technologies, with a focus on compliance, audits, vendor risk, and threat modeling. You will also have the chance to influence executive-level reporting through metrics and dashboards used by the CISO and Executive Risk Committee.
Location: Ashburn, VA (hybrid). The work model includes working from home and a minimum of three days per week in the office, as set by your manager. Employees are responsible for maintaining compliance with hybrid work policies.
Responsibilities
- Design, implement, and maintain the enterprise AI Risk Management Framework aligned with NIST AI RMF, ISO 42001, and emerging global regulations such as the EU AI Act.
- Lead end-to-end execution of internal and external security audits including SOC 2 Type II and ISO 27001, managing evidence collection, remediation tracking, and auditor relationships.
- Evaluate third-party SaaS vendors and AI model providers for security posture, data privacy usage, training data retention, and regulatory compliance.
- Conduct security risk assessments and threat models for new AI/ML initiatives, LLM integrations, and core platform capabilities.
- Act as a primary security risk advisor to Product, Engineering, and Business leaders, embedding Security & Privacy by Design into product roadmaps.
- Establish metrics, KRIs, and reporting dashboards for the CISO and Executive Risk Committee regarding compliance status and emerging AI risks.
Requirements
- Bachelor’s degree or four or more years of work experience.
- Six or more years of relevant experience demonstrated through one or a combination of work and/or military experience, or specialized training.
- Six or more years of progressive experience in Information Security Risk Management, IT Audit, or Governance, Risk, and Compliance (GRC).
- Demonstrated experience evaluating risks associated with AI/ML systems, Large Language Models (LLMs), data pipeline security, or AI vendor tools.
- Proven track record leading SOC 2 Type II audits, ISO 27001 certifications, or regulatory compliance programs from preparation through remediation.
- Deep familiarity with NIST SP 800-53, NIST SP 800-171, NIST CSF, SOC 2 Type II, ISO 27001, PCI-DSS, and HIPAA, plus AI-specific frameworks including NIST AI RMF and OWASP LLM Top 10.
- Basic understanding of cloud infrastructure (AWS/GCP/Azure), API security, data pipeline architecture, or software development lifecycles (SDLC).
Technologies
NIST AI RMF, ISO 42001, EU AI Act, SOC 2 Type II, ISO 27001, AWS, GCP, Azure, NIST SP 800-53, NIST SP 800-171, NIST CSF, PCI-DSS, HIPAA, OWASP LLM Top 10, SDLC, Vanta, Drata, LogicGate, ServiceNow, IAPP Artificial Intelligence Governance Professional (AIGP), CDPSE, CRISC, CISA, CISSP, CISM
Benefits
- Medical, dental, vision
- Short and long term disability
- Basic life insurance
- Supplemental life insurance
- AD&D insurance
- Identity theft protection
- Pet insurance
- Group home & auto insurance
- Matched 401(k) savings plan
- Up to 8 company paid holidays per year
- Up to 6 personal days per year, paid
- Paid parental leave
- Adoption assistance
- Tuition assistance
- Opportunity to receive compensation in the form of premium pay such as overtime, shift differential, holiday pay, allowances, etc.
- Newly hired employees receive up to 15 days of vacation per year, which grows with additional service
- Part-timers coverage varies depending on eligibility and individual circumstances
Schedule & Compensation
Scheduled weekly hours: 40
Salary: USD 120,500 - 231,000 per yearly. The salary varies depending on location and confirmed job-related skills and experience. This is an incentive based position with the potential to earn more. For part-time roles, compensation is adjusted to reflect hours. Annual salary range for the listed location(s) on a full-time schedule: $120,500.00 - $231,000.00.
In this incentive based position, the annual salary range shown is location-dependent and tied to confirmed job-related skills and experience.