Unknown Company
In this Principal Security Risk & Compliance lead role, you will help shape how an organization audits, governs, and manages security risk across enterprise AI programs and emerging network technologies. Working in a hybrid environment in Ashburn, you will connect security compliance with broader enterprise risk management to support safe, auditable deployment of AI capabilities.
What You’ll Do
- Design, implement, and maintain the enterprise AI Risk Management Framework aligned to NIST AI RMF , ISO 42001 , and emerging global regulations such as the EU AI Act .
- Lead end-to-end internal and external security audits , including SOC 2 Type II and ISO 27001 , by managing evidence collection, remediation tracking, and auditor relationships.
- Assess third-party AI and SaaS providers for security posture, data privacy practices (including usage and training data retention), and regulatory compliance.
- Conduct security risk assessments and threat modeling for new AI/ML initiatives , LLM integrations , and core platform capabilities.
- Act as the primary security risk advisor to Product, Engineering, and Business leaders, supporting “Security & Privacy by Design ” within product roadmaps.
- Create metrics, KRIs , and reporting dashboards for the CISO and Executive Risk Committee covering compliance status and emerging AI risks.
What You’ll Need
- Bachelor’s degree or four or more years of work experience .
- Six or more years of relevant experience, shown through work and/or military experience, or specialized training.
- Six or more years of progressive experience in Information Security Risk Management, IT Audit, or Governance, Risk, and Compliance (GRC).
- Experience evaluating risks tied to AI/ML systems , Large Language Models (LLMs) , data pipeline security , or AI vendor tools.
- A proven track record leading SOC 2 Type II audits, ISO 27001 certifications, or regulatory compliance programs from preparation through remediation.
- Deep familiarity with NIST SP 800-53 , NIST SP 800-171 , NIST CSF , SOC 2 Type II , ISO 27001 , PCI-DSS , and HIPAA , plus AI frameworks such as NIST AI RMF and OWASP LLM Top 10 .
- Basic understanding of cloud infrastructure (AWS/GCP/Azure), API security , data pipeline architecture , or SDLC .
Technologies and Frameworks
- NIST AI RMF
- ISO 42001
- EU AI Act
- SOC 2 Type II
- ISO 27001
- NIST SP 800-53 / NIST SP 800-171
- NIST CSF
- PCI-DSS
- HIPAA
- OWASP LLM Top 10
- AWS, GCP, Azure
- SDLC
Even Better If You Have
- One or more certifications including IAPP Artificial Intelligence Governance Professional (AIGP) , CDPSE , CRISC , CISA , CISSP , and/or CISM .
- Experience implementing or operating GRC automation platforms such as Vanta , Drata , LogicGate , or ServiceNow , including experience setting up Continuous Control Monitoring (CCM) or automated evidence-polling integrations.
- Knowledge and experience managing multiple simultaneous assessments and audits for continuous authorizations.
- Exceptional written and verbal communication skills, with the ability to translate complex technical and regulatory requirements into actionable business guidance.
Location, Type, and Schedule
- Location: Ashburn, VA (hybrid)
- Type: Full-time
- Schedule: 40 hours per week
Hybrid Work Expectations
- Hybrid role with a defined work location that includes working from home and a minimum of three days per week in the office , set by your manager.
- Employees are responsible for maintaining compliance with hybrid work policies.
Compensation and Benefits
- Salary: USD 120,500 - 231,000 per year
- Medical, Dental, Vision
- Short and long term disability
- Basic life insurance, Supplemental life insurance, AD&D insurance
- Identity theft protection
- Pet insurance
- Group home & auto insurance
- Matched 401(k) savings plan
- Up to 8 company paid holidays per year
- Up to 6 personal days per year, paid
- Paid parental leave
- Adoption assistance
- Tuition assistance
- Opportunity for compensation in the form of premium pay such as overtime, shift differential, holiday pay, and allowances
- Newly hired employees receive up to 15 days of vacation per year, which grows with additional service
- Compensation adjusted for part-time roles based on hours
- Salary incentive based position with potential to earn more
Principal - Cybersecurity Audit, Risk & Governance Architect – AI & Emerging Tech in ashburn at Unknown Company
This position is listed as part time and hybrid.