Plain Concepts logo
Plain Concepts

Rediscover the meaning of technology | Spain, USA, UK, Germany, Netherlands, Australia and Romania.

AI Security Governance Architect

Security EngineerSecurity EngineerFull TimeRemoteMid LevelTeam 201-500Since 2006H1B No SponsorCompany SiteLinkedIn

Location

Worldwide

Posted

21 days ago

Salary

0

Seniority

Mid Level

Job Description

AI Security Governance Architect

Plain Concepts

Role Description Support the client’s AI Security Governance Program by defining, operationalizing and continuously improving the cybersecurity control framework for AI, GenAI and agentic AI use cases. The role will work with security, architecture and business teams to ensure AI initiatives are registered, assessed, governed and secured across their lifecycle. The profile will act as the cybersecurity subject matter expert for AI governance, complementing the project manager and helping translate AI-related risks into practical controls, processes, requirements, evidences and decision criteria. Key Responsibilities - AI security governance framework: - Define and mature the security governance model for AI systems, including intake, registration, risk classification, control mapping, approvals, exceptions, monitoring and periodic reassessment. - Align the governance model with recognized frameworks such as NIST AI RMF, NIST Generative AI Profile, ISO/IEC 42001, OWASP Top 10 for LLM Applications, and local relevant ruling as EU AI Act obligations where applicable. - AI use case risk assessment: - Assess AI and GenAI use cases from a cybersecurity perspective, covering: - Access control and identity context - Agentic AI permissions and tool execution - Logging, monitoring and incident response - Model exposure and misuse risk - Prompt injection and indirect prompt injection - Sensitive data leakage - Data classification and data residency - Model supply chain and third-party AI services - Human oversight and approval workflows - Security-by-design requirements for AI applications - Control design and operationalization: - Translate risks into practical security controls, including policies, technical requirements, architecture patterns, guardrails, evidence requirements, control owners and acceptance criteria. - Define what “good” looks like for different AI patterns: internal copilots, M365 Copilot, custom GenAI apps, RAG systems, AI agents, vendor AI features, ML models and low-code/no-code AI automations. - Tooling integration and control mapping: - Work with existing tools such as HiddenLayer, Sentra, Zenity and the AI registration/control tower process to ensure the governance model is not theoretical. - Expected activities include: - Mapping tool capabilities to governance controls - Defining required data fields in the AI registry - Establishing dashboards and control evidence - Identifying gaps between tooling coverage and policy expectations - Supporting integration with GRC, CMDB, DLP, IAM, SIEM/SOC, cloud security and data governance processes - Deliverables: - Typical deliverables should include: - AI control framework - AI use case classification model - Security requirements for AI/GenAI projects - AI security architecture patterns - AI registry/control tower data model recommendations - Tooling-to-control mapping - Exception and risk acceptance process - KPI/KRI dashboard proposal - Security review templates - AI security awareness material for project teams - Roadmap for maturity improvement Qualifications - 8+ years in cybersecurity, with strong experience in security governance, security architecture, risk management or AppSec/CloudSec. - Real understanding of AI/GenAI security risks, especially LLM application risks, prompt injection, data leakage, model supply chain, AI agent permissions, RAG security, model/API exposure and third-party AI usage. - Ability to build governance that works operationally, not just policy documents. - Experience with enterprise control frameworks. - Excellent documentation and communication skills, with the ability to produce executive-ready material and technical control definitions. Requirements - Experience with one or more of: - AI governance programs - AISPM Experience - GenAI application security reviews - M365 Copilot / enterprise copilots - AI agent governance - ML/LLM model risk management - Data Security Posture Management - Cloud security architecture - Secure SDLC / DevSecOps - Third-party AI vendor risk - GRC tooling and control evidence automation - SOC monitoring for AI-related threats - Experience with tools such as HiddenLayer, Sentra, Zenity, Wiz, Microsoft Purview, Defender, CSPM/CWPP, DLP, SIEM/SOAR, cloud-native security tooling or GRC platforms would be valuable. Benefits - Salary determined by the market and your experience 🤑 - Flexible schedule 35 Hours / Week 😎 - Fully remote work (optional) 🌍 - Flexible compensation (restaurant, transport, and childcare) ✌ - Fully free health insurance, with a co-payment for dental services 🚑 - Individual budget for training or equipment and free Microsoft certifications 📚 - English lessons 🗽 - Birthday day off 🌴🥳 - Monthly bonus for electricity and Internet expenses at home 💻 - Discount on gym plan and sports activities 🔝 - Plain Camp (annual team-building event) 🎪 - Extra perks: events attendance and speakers, welcome pack, baby basket, Christmas basket, discount portal for employees ➕ The pleasure of always working with the latest technological tools! Company Description Plain Concepts is a global company of over 500 people passionate about technology and innovation. Since our founding, we have grown through technical proficiency and confidence in ideas that others might consider risky, creating custom solutions for our clients. With offices in more than 6 countries, our mission is to continue to drive cutting-edge projects around the world. We are highly committed to technical excellence. We are known for developing highly customized projects, offering specialized technical consultancy and training. Thanks to the great work of our technicians, we have been recognized for our ability to lead innovative projects that generate value, from artificial intelligence to blockchain, driving solutions that help companies optimize their performance.

Related Categories

Related Job Pages

More Security Engineer Jobs

Deutsche Telekom IT Solutions logo

Deal Support Specialist Cyber Security

Deutsche Telekom IT Solutions

As Hungary’s most attractive employer in 2025 (according to Randstad’s representative survey), Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees. We have hundreds of large customers, corporations in Germany and in other European countries. DT-ITS received the Best in Educational Cooperation award from HIPA in 2019, acknowledged as the Most Ethical Multinational Company in 2019. The company continuously develops its four sites in Budapest, Debrecen, Pécs and Szeged and is looking for skilled IT professionals to join its team.

Full TimeRemoteTeam 5,001-10,000

Role Description - Administration and maintenance of opportunities and leads in Magenta-Force (Salesforce) - Creation and processing of internal sales support orders using workflow tools (e.g. ZDF) - Supporting the sales organization throughout the opportunity lifecycle - Updating opportunity status and sales activities based on input from Sales Experts - Preparation and tracking of offers based on standardized templates - Preparation of commercial calculations and pricing sheets based on predefined standards and input from Sales Experts - Supporting pricing and quotation processes for customer opportunities - Coordination and tracking of smaller sales initiatives and bid activities - Supporting order administration and purchasing processes including DealReg creation - Monitoring open tasks and deadlines related to sales opportunities - Supporting tender and procurement portals during bidding processes - Maintaining internal tracking lists and sales-related documentation - Coordinating onboarding and collaboration activities for internal bid teams - Ensuring accuracy and completeness of commercial data and deal-related documentation Qualifications - German and English language skills at minimum B2 level (spoken and written) - Strong organizational and coordination skills - Structured and proactive way of working - Ability to manage multiple tasks and deadlines in parallel - Strong communication skills and willingness to work in international teams - Good knowledge of MS Office applications, especially Excel and Word - Affinity for numbers and analytical thinking - High attention to detail and quality orientation - Customer- and service-oriented mindset - Basic understanding of IT and/or Cyber Security topics Requirements - Experience in sales support, bid management or back-office operations - Experience working with CRM systems such as Salesforce - Experience with commercial calculations, pricing or quotation support - Experience in international corporate environments - Familiarity with procurement or tendering processes Benefits - Supportive, bondable team - Helpful colleagues in Germany (as your future direct contacts) - *Please be informed that our remote working possibility is only available within Hungary due to European taxation regulation.

Hungary

Marketing and Technical Manager

Graymont

Graymont, founded in 1948 and headquartered in Richmond, British Columbia, Canada, is a global leader in lime and limestone solutions essential to a wide range of industries. The c

Title: Marketing and Technical Manager Location: Remote United States FunctionSales & Marketing/Quality Control/Supply Chain/Customer Service ClassificationSalaried Job Description: Full-time, Permanent This is a remote position located in any state or province where Graymont operates The Marketing & Technical Manager will grow and develop Graymont’s business portfolio by uncovering, developing, leading, managing and commercializing new business opportunities; Lead the strategic new business development projects which meet the objectives of Graymont and act as an industry expert in the new business development and applications markets as assigned. Responsibilities • Convert Graymont’s strategic plan into measurable new business development and applications objectives and goals with details and plans to achieve these objectives • Establish key industry contacts and build relationships designed to increase business opportunities for Graymont • Review all new business opportunities for fit with the Graymont’s strategy and advise accordingly, while collaborating across all relevant business teams and functions to identify and take advantages of synergies to increase competitive advantage • Identify new growth opportunities via existing and/or new product application developments or adjacent synergies • Play a pivotal role in directing the work of R&D towards meeting the needs of Graymont and customers, while utilizing stage gate project management tools to determine the priorities, needs and decisions of assigned projects • Assist in the development and implementation of testing protocols to validate Graymont’s products for customer applications • Extend Graymont’s influence into the marketplace, by actively attending trade shows and conferences and determining the appropriate trade shows for future attendance • Determine, create and manage the brand management and marketing tools for the market areas assigned • As a subject matter expert, lead training and development for other members of the marketing team and other Graymont business teams within assigned market areas • Identify potential opportunities for collaborations, partnerships and/or acquisitions • Other responsibilities as assigned while also acting as a participative and collaborative team member of Graymont’s marketing, new business development and commercial team Qualifications • Professional Experience: Proven experience with 10+ years of industry experience in an operations, process, sales & marketing, technical or related role, preferably in lime & limestone industrial applications • Education: A Bachelor’s degree in materials science, mining and/or chemical engineering, chemistry, or a related field with 10+ years of experience, advanced degree is preferred • Sound finance, business and commercial acumen • Demonstrated ability to develop business relationships and convert them into business opportunities • Excellent numerical and verbal reasoning skills • Strong communication skills, with the ability to engage effectively at all levels of the organization • Travel Requirement: Willingness and ability to travel as required, both domestically and internationally, to production plants, customer sites, and other locations as needed • Language Proficiency: Bilingual English/French is an asset Who We Are Founded in 1948, Graymont is a trusted global leader in essential calcium-based solutions. Professionally managed and family-owned, we proudly serve a wide range of markets, customers, and communities in North America and Asia Pacific. Graymont is also the strategic partner of Grupo Calidra, the largest lime producer in Latin America. Graymont’s strategy is anchored in its strong commitment to its core values of integrity, respect, teamwork, innovation, excellence, accountability, and long-term perspective. Central to our philosophy is a long-term approach to our business, built on a solid commitment to sustainable growth and focus on decarbonization, all of which is embodied in our mission statement: Contributing to a decarbonized world by providing essential lime and limestone solutions.

Worldwide
Booz Allen Hamilton logo

Network Security Engineer

Booz Allen Hamilton

Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp

Design and implement secure network solutions for critical missions, collaborating with stakeholders to assess requirements, support hardware acquisition, and resolve complex interoperability issues while ensuring compliance with security best...

Ohio + 7 moreAll locations: Ohio | Maryland | Florida | Pennsylvania | Texas | Illinois | Oklahoma | Utah

Expert Security Engineer

Altera Digital Health

Altera Digital Health is dedicated to reshaping the future of healthcare by providing innovative digital health solutions that improve the delivery and quality of care. Altera's su

Job Title: Expert Security Engineer Location: US, Canada (Remote) Employment Type: Full-time Job Description: About Altera Altera, a member of the N. Harris Computer Corporation family, delivers health IT solutions that support caregivers around the world. These include the Sunrise, Paragon Daneli, TouchWorks EHR, Altera Opal, Ventus, HealthQuest and dbMotion solutions. At the intersection of technology and the human experience, Altera Digital Health is driving a new era of healthcare, in which innovation and expertise can elevate care delivery and inspire healthier communities across the globe. A new age in healthcare technology has just begun. Position Summary As an Expert Security Engineer at Altera, you will be at the forefront of our proactive security efforts, specializing in ethical hacking and penetration testing. This role is critical for actively identifying and exploiting vulnerabilities across our applications, infrastructure, and cloud environments. We are seeking a highly skilled individual with a deep understanding of application architecture and security controls, capable of independently uncovering security flaws and articulating complex findings to diverse audiences. Key Responsibilities - Ethical Hacking & Penetration Testing: Lead and execute advanced penetration tests and ethical hacking engagements against Altera's critical systems, applications, and networks to identify and exploit security weaknesses. - Application Security Expertise: Conduct in-depth security reviews of applications, with a strong focus on understanding how they are built (e.g., Java-based applications) to uncover design flaws, coding vulnerabilities, and misconfigurations. - Vulnerability Identification & Exploitation: Independently identify, analyze, and validate security vulnerabilities with high fidelity, demonstrating the ability to exploit them to assess potential impact. - Tool Proficiency: Leverage and master industry-standard penetration testing tools. - Reporting & Communication: Clearly articulate complex technical findings, security risks, and actionable remediation strategies through comprehensive written reports and compelling presentations to both technical teams and non-technical stakeholders, including customers. - Consultation & Guidance: Provide expert consultation to development, operational, and other business units on secure design principles, application of security best practices, and the effective use of advanced security technologies. - Threat Intelligence: Maintain heightened awareness of current security vulnerabilities, attack vectors, and mitigation techniques, proactively communicating relevant findings and recommendations. Role Requirements - Total Years of Experience: 5 years of progressive experience in cybersecurity, with a minimum of 3 years dedicated to ethical hacking, penetration testing, and application security. - Mandatory Skills: - Proven expertise in ethical hacking and penetration testing methodologies, including network, web application, API, and cloud penetration testing. - Deep understanding of application security principles, secure coding practices, and common vulnerabilities (e.g., OWASP Top 10, SANS Top 25). - Expert-level proficiency with penetration testing tools. - Strong understanding of application architecture and development. - Demonstrated ability to independently identify, validate, and exploit security vulnerabilities with high fidelity. - Exceptional verbal and written communication skills, with the ability to clearly articulate complex technical findings, risks, and remediation strategies to diverse audiences. - Strong presentation skills, capable of conveying security insights and recommendations effectively to customers and internal stakeholders. - Experience with cloud security assessments (e.g., Microsoft Azure Security). - Familiarity with various security technologies (e.g., EDR, IDS/IPS, Firewalls, SIEM, Vulnerability Management tools) from an attacker's perspective. - Good to Have/Preferred Skills: - Experience with scripting languages (e.g., Python, PowerShell) for automation and custom tool development. - Relevant offensive security certifications such as OSCP, OSWE, GPEN, GWAPT, or other advanced GIAC certifications. - Industry-recognized certifications like CISSP, CompTIA Security+, or CySA+. - Expert knowledge of Linux and Windows operating systems. - Experience in security engineering, operations, and design best practices. - Bachelor's degree in computer science, Cybersecurity, Information Technology, or a related technical field. Salary range $100,000 - $120,000 USD

Canada
$100K - $120K / year