Principal - Cybersecurity Audit, Risk & Governance Architect – AI & Emerging Tech
Job Description
In this Principal Security Risk & Compliance lead role, you will help shape how an organization audits, governs, and manages security risk across enterprise AI programs and emerging network technologies. Working in a hybrid environment in Ashburn, you will connect security compliance with broader enterprise risk management to support safe, auditable deployment of AI capabilities.
What You’ll Do
- Design, implement, and maintain the enterprise AI Risk Management Framework aligned to NIST AI RMF, ISO 42001, and emerging global regulations such as the EU AI Act.
- Lead end-to-end internal and external security audits, including SOC 2 Type II and ISO 27001, by managing evidence collection, remediation tracking, and auditor relationships.
- Assess third-party AI and SaaS providers for security posture, data privacy practices (including usage and training data retention), and regulatory compliance.
- Conduct security risk assessments and threat modeling for new AI/ML initiatives, LLM integrations, and core platform capabilities.
- Act as the primary security risk advisor to Product, Engineering, and Business leaders, supporting “Security & Privacy by Design” within product roadmaps.
- Create metrics, KRIs, and reporting dashboards for the CISO and Executive Risk Committee covering compliance status and emerging AI risks.
What You’ll Need
- Bachelor’s degree or four or more years of work experience.
- Six or more years of relevant experience, shown through work and/or military experience, or specialized training.
- Six or more years of progressive experience in Information Security Risk Management, IT Audit, or Governance, Risk, and Compliance (GRC).
- Experience evaluating risks tied to AI/ML systems, Large Language Models (LLMs), data pipeline security, or AI vendor tools.
- A proven track record leading SOC 2 Type II audits, ISO 27001 certifications, or regulatory compliance programs from preparation through remediation.
- Deep familiarity with NIST SP 800-53, NIST SP 800-171, NIST CSF, SOC 2 Type II, ISO 27001, PCI-DSS, and HIPAA, plus AI frameworks such as NIST AI RMF and OWASP LLM Top 10.
- Basic understanding of cloud infrastructure (AWS/GCP/Azure), API security, data pipeline architecture, or SDLC.
Technologies and Frameworks
- NIST AI RMF
- ISO 42001
- EU AI Act
- SOC 2 Type II
- ISO 27001
- NIST SP 800-53 / NIST SP 800-171
- NIST CSF
- PCI-DSS
- HIPAA
- OWASP LLM Top 10
- AWS, GCP, Azure
- SDLC
Even Better If You Have
- One or more certifications including IAPP Artificial Intelligence Governance Professional (AIGP), CDPSE, CRISC, CISA, CISSP, and/or CISM.
- Experience implementing or operating GRC automation platforms such as Vanta, Drata, LogicGate, or ServiceNow, including experience setting up Continuous Control Monitoring (CCM) or automated evidence-polling integrations.
- Knowledge and experience managing multiple simultaneous assessments and audits for continuous authorizations.
- Exceptional written and verbal communication skills, with the ability to translate complex technical and regulatory requirements into actionable business guidance.
Location, Type, and Schedule
- Location: Ashburn, VA (hybrid)
- Type: Full-time
- Schedule: 40 hours per week
Hybrid Work Expectations
- Hybrid role with a defined work location that includes working from home and a minimum of three days per week in the office, set by your manager.
- Employees are responsible for maintaining compliance with hybrid work policies.
Compensation and Benefits
- Salary: USD 120,500 - 231,000 per year
- Medical, Dental, Vision
- Short and long term disability
- Basic life insurance, Supplemental life insurance, AD&D insurance
- Identity theft protection
- Pet insurance
- Group home & auto insurance
- Matched 401(k) savings plan
- Up to 8 company paid holidays per year
- Up to 6 personal days per year, paid
- Paid parental leave
- Adoption assistance
- Tuition assistance
- Opportunity for compensation in the form of premium pay such as overtime, shift differential, holiday pay, and allowances
- Newly hired employees receive up to 15 days of vacation per year, which grows with additional service
- Compensation adjusted for part-time roles based on hours
- Salary incentive based position with potential to earn more