Haystack
← Back to Jobs
Technology
SI

Cybersecurity AI Risk and Governance Director

Source InfotechDenver, CO🇺🇸United StatesPosted Sep 28, 2026

Quick Overview

Seniority
Leader
Work mode
On Site
Location
Denver, CO, United States
Posted
3 days ago
AWSEncryptionMachine LearningAzureGenerative AIGoogle CloudLLM

Job Description

Title: Cybersecurity AI Risk and Governance Director, Global
Location: Denver, CO or Ashburn, VA. 
Hybrid (3 Days On-Site)

Cybersecurity Department
The AI Cybersecurity Director is responsible for the technical security, risk management, and governance enforcement of artificial intelligence (AI), machine learning (ML), and large language model (LLM) systems deployed across operational, OT, and enterprise environments.
This role serves as the technical and security authority for AI security, ensuring AI systems are architected, deployed, and operated with appropriate controls for data protection, model integrity, access governance, monitoring, and human-in-the-loop decision enforcement. The AI Cybersecurity Director ensures AI technologies deliver business value without introducing unacceptable cyber, operational, safety, workforce, or regulatory risk, in alignment with the Global Policies and Standards.
In addition, this role will support broader cybersecurity governance, risk, and compliance (GRC) activities, helping ensure cybersecurity risks, controls, policies, and compliance requirements are effectively governed and aligned with the enterprise cybersecurity program.

Essential Functions
• Establish enterprise governance for detection, classification, and management of unauthorized (shadow) AI across business units, in coordination with centralized AI functions.
• Define and enforce security architecture standards for AI, ML, and LLM platforms across cloud, hybrid, on-prem, and OT-adjacent environments.
• Provide security design oversight and approval for AI systems, including data pipelines, model hosting, inference paths, APIs, and integrations.
• Define enterprise methodology for AI security assessment covering architecture, design, and implementation across applications, agents, and workflows.
• Ensure AI architectures enforce segmentation, least privilege, deterministic behavior, and fail-safe operation, particularly where OT or critical infrastructure data is involved.
• Establish AI-specific incident response playbooks and lead response to AI-related security, safety, or governance incidents.
• Enforce controls preventing unauthorized model retraining, autonomous learning, or use of live production or OT data outside approved intent.
• Define security requirements for explain ability, traceability, and output validation where AI influences operational, workforce, safety, or compliance outcomes.
• Drive alignment with ISO 42001 and related AI governance standards across applicable teams.

Cybersecurity Governance, Risk, and Compliance
• Support the development and ongoing maturity of enterprise cybersecurity governance, risk, and compliance practices, policies, standards, and controls.
• Support cybersecurity risk identification, assessment, treatment, escalation, exception, and acceptance processes, including maintenance of appropriate risk and remediation documentation.
• Help align cybersecurity controls and requirements with applicable organizational policies, regulatory requirements, contractual obligations, and recognized security frameworks.
• Support cybersecurity control assessments, compliance activities, audit readiness, remediation tracking, and ongoing monitoring of control effectiveness.
• Partner with Cybersecurity, Legal, Privacy, Risk, Compliance, Technology, and business stakeholders to communicate material risks, control gaps, remediation activities, and governance requirements.

AI Data Protection and Trust Boundaries
• Enforce protections against prompt injection, data leakage, hallucination risk, unauthorized context expansion, and external model training exposure.
• Ensure sensitive enterprise, operational, personnel, and contractual data is not exposed to or retained by external AI platforms without approved safeguards.
• Approve and oversee AI data ingestion pipelines, enforcing purpose limitation, data minimization, and classification requirements.
• Validate encryption, access logging, retention, and deletion controls for data used by AI systems.
• Define and enforce controls preventing cross-domain data correlation that violates trust boundaries or governance constraints.

AI Threat, Risk, and Monitoring Management
• Perform AI-specific threat modeling, including risks such as data poisoning, model theft, inference abuse, output manipulation, and decision integrity compromise.
• Integrate AI threats into enterprise cybersecurity and OT risk models, including definition of compensating controls and escalation for systems exceeding risk tolerance.
• Own and maintain the AI risk register covering confidentiality, integrity, availability, explainability, data quality, model drift, adversarial attacks, and business impact.
• Ensure AI systems generate telemetry, logging, and audit trails sufficient to detect misuse, drift, or anomalous behavior.
• Integrate AI security monitoring into SOC, SIEM, and enterprise incident response workflows.

OT and Critical Infrastructure Safeguards
• Enforce prohibitions on autonomous AI control of OT assets, including power, cooling, BMS, fire suppression, and physical access systems.
• Validate one-way data flows, read-only access models, and manual override requirements where AI consumes OT telemetry.
• Partner with OT and infrastructure teams to ensure AI enhances visibility and decision support without compromising safety, reliability, or uptime.
• Oversee security reviews of vendor-provided and embedded AI capabilities, including model behavior, data handling, and contractual protections.
• Define and enforce minimum security and governance requirements for AI vendors, including audit rights and termination conditions.

Required Qualifications
• Bachelor’s degree in Cybersecurity, Computer Science, Data Science, Engineering, or related field, or equivalent experience.
• Minimum 10+ years of experience in cybersecurity, security architecture, or risk engineering roles.
• Hands-on experience securing data pipelines, APIs, cloud platforms, and analytics or ML-enabled systems.
• Strong understanding of identity, access management, encryption, logging, and secure system design.
• Experience supporting or leading cybersecurity governance, risk, and compliance activities, including risk assessments, control governance, policy and standards management, compliance, or audit readiness.

Preferred Qualifications
• Direct experience securing AI/ML platforms, LLMs, or analytics pipelines.
• Experience with cloud security (Azure, AWS, Google Cloud Platform) and SaaS-based AI platforms.
• Familiarity with OT, critical infrastructure, or safety-critical environments.
• Security certifications such as CISSP, CCSP, CISM, or cloud security certifications.

Key Skills & Competencies
• AI and machine learning security
• LLM and generative AI risk management
• Security architecture and threat modeling
• Data protection and access governance
• Incident response and forensic analysis
• Cross-functional technical leadership
• Cybersecurity governance, risk, and compliance

Similar jobs