CybersecurityJobs.io
← Back to all jobs

Job Description

In this Principal Security Risk & Compliance lead role, you will help shape how an organization audits, governs, and manages security risk across enterprise AI programs and emerging network technologies. Working in a hybrid environment in Ashburn, you will connect security compliance with broader enterprise risk management to support safe, auditable deployment of AI capabilities.

What You’ll Do

  • Design, implement, and maintain the enterprise AI Risk Management Framework aligned to NIST AI RMF, ISO 42001, and emerging global regulations such as the EU AI Act.
  • Lead end-to-end internal and external security audits, including SOC 2 Type II and ISO 27001, by managing evidence collection, remediation tracking, and auditor relationships.
  • Assess third-party AI and SaaS providers for security posture, data privacy practices (including usage and training data retention), and regulatory compliance.
  • Conduct security risk assessments and threat modeling for new AI/ML initiatives, LLM integrations, and core platform capabilities.
  • Act as the primary security risk advisor to Product, Engineering, and Business leaders, supporting “Security & Privacy by Design” within product roadmaps.
  • Create metrics, KRIs, and reporting dashboards for the CISO and Executive Risk Committee covering compliance status and emerging AI risks.

What You’ll Need

  • Bachelor’s degree or four or more years of work experience.
  • Six or more years of relevant experience, shown through work and/or military experience, or specialized training.
  • Six or more years of progressive experience in Information Security Risk Management, IT Audit, or Governance, Risk, and Compliance (GRC).
  • Experience evaluating risks tied to AI/ML systems, Large Language Models (LLMs), data pipeline security, or AI vendor tools.
  • A proven track record leading SOC 2 Type II audits, ISO 27001 certifications, or regulatory compliance programs from preparation through remediation.
  • Deep familiarity with NIST SP 800-53, NIST SP 800-171, NIST CSF, SOC 2 Type II, ISO 27001, PCI-DSS, and HIPAA, plus AI frameworks such as NIST AI RMF and OWASP LLM Top 10.
  • Basic understanding of cloud infrastructure (AWS/GCP/Azure), API security, data pipeline architecture, or SDLC.

Technologies and Frameworks

  • NIST AI RMF
  • ISO 42001
  • EU AI Act
  • SOC 2 Type II
  • ISO 27001
  • NIST SP 800-53 / NIST SP 800-171
  • NIST CSF
  • PCI-DSS
  • HIPAA
  • OWASP LLM Top 10
  • AWS, GCP, Azure
  • SDLC

Even Better If You Have

  • One or more certifications including IAPP Artificial Intelligence Governance Professional (AIGP), CDPSE, CRISC, CISA, CISSP, and/or CISM.
  • Experience implementing or operating GRC automation platforms such as Vanta, Drata, LogicGate, or ServiceNow, including experience setting up Continuous Control Monitoring (CCM) or automated evidence-polling integrations.
  • Knowledge and experience managing multiple simultaneous assessments and audits for continuous authorizations.
  • Exceptional written and verbal communication skills, with the ability to translate complex technical and regulatory requirements into actionable business guidance.

Location, Type, and Schedule

  • Location: Ashburn, VA (hybrid)
  • Type: Full-time
  • Schedule: 40 hours per week

Hybrid Work Expectations

  • Hybrid role with a defined work location that includes working from home and a minimum of three days per week in the office, set by your manager.
  • Employees are responsible for maintaining compliance with hybrid work policies.

Compensation and Benefits

  • Salary: USD 120,500 - 231,000 per year
  • Medical, Dental, Vision
  • Short and long term disability
  • Basic life insurance, Supplemental life insurance, AD&D insurance
  • Identity theft protection
  • Pet insurance
  • Group home & auto insurance
  • Matched 401(k) savings plan
  • Up to 8 company paid holidays per year
  • Up to 6 personal days per year, paid
  • Paid parental leave
  • Adoption assistance
  • Tuition assistance
  • Opportunity for compensation in the form of premium pay such as overtime, shift differential, holiday pay, and allowances
  • Newly hired employees receive up to 15 days of vacation per year, which grows with additional service
  • Compensation adjusted for part-time roles based on hours
  • Salary incentive based position with potential to earn more

Similar Jobs