Associate Director, AI Security Governance, Risk and Compliance

Verizon Verizon · Telecom · Alpharetta, GA +5

This role leads the AI Security Governance, Risk, and Compliance (GRC) team, focusing on developing and operationalizing Verizon's AI security governance program. The Associate Director will identify, assess, and treat risks associated with AI use, shape the enterprise-wide control framework, and ensure AI systems are deployed securely and responsibly, aligning with enterprise risk, regulatory, and cybersecurity requirements. Responsibilities include owning the AI GRC vision and roadmap, establishing AI-centric risk management processes, performing compliance reviews, documenting risk assessments, leading automation for AI risk assessment, overseeing an AI compliance program and dashboard, facilitating AI security training, guiding AI project prioritization, and ensuring VCS engagement in secure AI efforts.

What you'd actually do

  1. Owning the vision, roadmap, and execution of Verizon's AI GRC team.
  2. Ensuring AI-centric risk management processes and outcomes are established through policies and controls based on organizational priorities and tolerance.
  3. Performing regular reviews of AI applications for compliance and alignment, documenting the risks and mitigation strategies as part of the risk management review process.
  4. Documenting processes for information/technology risk assessments and thresholds to warrant a more in-depth review.
  5. Leading the creation of automation for 80%+ of the AI risk assessment process.

Skills

Required

  • Bachelor's degree or four or more years of work experience.
  • Eight or more years of relevant experience required, demonstrated through one or a combination of job-related work experience, military experience, or specialized training or education (non-collegiate).
  • Eight or more years of experience in IT, cybersecurity, and/or AI disciplines with progressive leadership responsibilities, including at least 3 years focused on AI/ML security technologies.
  • Experience performing comprehensive risk assessments.

Nice to have

  • Strong technical knowledge of AI / ML technologies.
  • Experience with security policy creation.
  • Experience working on third party risk assessments.
  • Demonstrated knowledge of AI related risks and mitigation strategies in particular for Generative AI solutions.
  • Comprehensive understanding of cyber based frameworks including NIST AI Risk Management Framework, MITRE ATLAS, and OWASP Top 10 LLM.
  • Knowledge of large enterprise environments, cloud infrastructure and services, network protocols, network devices, multiple operating systems (Windows, macOS, Linux, etc.), and secure architectures.
  • Strong analytical and critical thinking skills, excellent written, oral communication and presentation skills.
  • Highly collaborative with ability to articulate ideas and influence peers and senior leaders.
  • Experience working on cross-functional teams including engineering, products teams, legal and security.

What the JD emphasized

  • AI security governance program
  • AI risk management
  • AI control framework
  • AI lifecycle security
  • AI risk assessment methodologies
  • AI compliance program
  • AI security training
  • AI projects review
  • secure AI efforts
  • AI security concerns
  • AI/ML security technologies
  • AI related risks and mitigation strategies
  • Generative AI solutions
  • NIST AI Risk Management Framework
  • MITRE ATLAS
  • OWASP Top 10 LLM