Director, AI Security

Corebridge Financial•Houston, TX
•Hybrid

About The Position

The Director of AI Security will own the enterprise’s AI Security Standard and the technical security program that operationalizes it — designing, implementing, and governing the controls that ensure the organization builds and consumes artificial intelligence (including generative AI, agentic AI, and third-party/embedded AI capabilities) securely and in compliance with emerging regulatory expectations. Reporting to the Head of Cyber Data Protection and AI Security, this role works in close, continuous partnership with the Enterprise AI team, which owns the overarching AI Strategy and AI Standard (governing acceptable use, business adoption, and enterprise AI investment). The Director of AI Security ensures that standard is backed by a rigorous, enforceable security layer — covering model risk, data protection, identity, vulnerability management, and attack-path/threat modeling across the AI lifecycle, from model selection and data sourcing through deployment, monitoring, and decommissioning. This is a hands-on leadership role for someone who can operate simultaneously at the standards/control-framework level (audit- and board-ready documentation) and the technical control level, while building a trusted, collaborative relationship with a peer team that owns adjacent AI governance.

Requirements

  • 10+ years in cybersecurity, with at least 3–5 years focused on data protection, cloud security, or emerging technology risk; demonstrated ownership of a formal security standard or governance framework.
  • Direct experience authoring or operationalizing AI security standards (or directly transferable experience in data protection/data governance standards) at an enterprise level, including experience partnering with an adjacent team that owns broader AI strategy/policy.
  • Strong understanding of AI/ML lifecycle risks, generative AI security concerns, and emerging agentic AI risk patterns.
  • Familiarity with relevant frameworks: NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, MITRE ATLAS, EU AI Act, NIST 800-53/CSF.
  • Experience with Microsoft security/identity stack and/or vulnerability management platforms (e.g., Qualys VMDR) as applied to AI asset inventory and control coverage.
  • Experience with AI Security platforms (e.g. Varonis Atlas) to discover and monitor AI usage, evaluate AI interactions, perform security testing of AI models and collect compliance events data related to AI usage.
  • Experience in regulated industries (financial services, healthcare, defense, critical infrastructure) and ability to translate regulatory requirements into technical/administrative controls.
  • Demonstrated ability to build effective, collegial working relationships across peer teams with adjacent but distinct ownership (e.g., co-authoring standards, joint governance boards) without formal authority over those teams.
  • Bachelor’s degree or equivalent experience; relevant certifications a plus (CISSP, CCSP, AI governance certifications, etc.).

Nice To Haves

  • Experience building or contributing to a risk intelligence / GRC platform that aggregates vulnerability, asset, and attack-path data across applications, devices, and people.
  • Experience with M&A security due diligence, including assessing AI/data risk in acquired entities.
  • Background in OT/ICS or classified/high-assurance environments.
  • Experience configuring or evaluating agent orchestration platforms (e.g., Microsoft Copilot Studio) for security and compliance.
  • Hands-on experience building and deploying AI applications, including generative AI or agent-based solutions.
  • Demonstrated experience automating security assessments and operational processes through workflow platforms, scripting, or AI-enabled solutions, with measurable improvements in speed, quality, or control effectiveness.

Responsibilities

  • Ensure the AI Security Standard is fully aligned with, and traceable to, the Enterprise AI team’s AI Strategy and AI Standard — acting as the primary security liaison and co-author on any sections where the two documents intersect (approved use cases, data handling, model sourcing).
  • Partner with the Enterprise AI team to define and maintain the security review criteria feeding the Approved AI/Model List, including risk-tiering methodology for AI types (traditional ML, generative AI, agentic AI, embedded/third-party AI) and a joint exception/waiver process.
  • Co-develop Appropriate Use Policy (AUP) security requirements with the Enterprise AI team, ensuring employee-, developer-, and business-unit-facing guidance reflects both AI Standard intent and AI Security Standard controls.
  • Map AI security requirements to relevant regulatory and industry frameworks (e.g., NIST AI RMF, ISO/IEC 42001, EU AI Act, OWASP Top 10 for LLMs, MITRE ATLAS) and translate them into the internal control requirements embedded in the AI Security Standard.
  • Establish a standing governance cadence (working group, review board, or joint steering sync) with the Enterprise AI team to keep the AI Standard and AI Security Standard synchronized as AI adoption scales and regulations evolve.
  • Lead security risk assessments for AI/ML pipelines, generative AI deployments, and agentic AI systems, addressing risks such as prompt injection, data leakage, model poisoning, excessive agency, insecure tool/plugin integration, and supply chain risk in third-party models.
  • Partner with data protection, identity, and vulnerability management teams to extend existing enterprise security programs into AI-specific contexts — including access controls for model endpoints, data classification for training/inference data, and secure API/agent orchestration.
  • Own attack path and threat modeling for AI assets — identifying novel and indirect attack paths introduced by AI integrations across applications, devices, and data sources, and driving remediation prioritization.
  • Evaluate and secure agent creation platforms (e.g., Copilot Studio, custom agent frameworks) used within regulated business functions, ensuring guardrails, logging, and human-in-the-loop controls are enforced.
  • Serve as the primary security stakeholder in AI procurement, vendor risk assessments, and build-vs-buy decisions for AI capabilities.
  • Partner with Legal, Privacy, Compliance, and Data Governance teams to ensure AI initiatives meet regulatory obligations (data privacy, sector-specific regulation, third-party risk).
  • Build and lead a small team (or dotted-line working group) of AI security engineers/analysts as the program scales. Utilize support from MSSP and specialized contractors as the team scales.
  • Report AI security posture, control maturity, and incident trends to the Head of Cyber Data Protection and AI Security, and support executive/board-level reporting as needed.
  • Lead incident response planning and tabletop exercises specific to AI security failure modes (model misuse, data exfiltration via AI tools, agent misbehavior).
  • Develop training and awareness programs to help engineering, product, and business teams understand and apply the AI Security Standard in coordination with Enterprise AI’s broader AI Standard training.
  • Act as an internal advisor/enabler — helping teams adopt AI safely rather than acting purely as a gatekeeper.
  • Track the token/compute cost and risk-remediation ROI of using frontier AI models for security use cases (e.g., automated vulnerability triage, code remediation) to inform build decisions.

Benefits

  • Medical, dental and vision insurance plans
  • Mental health support
  • Wellness initiatives
  • Retirement benefits options
  • 401(k) Plan with a generous dollar-for-dollar Company matching contribution of up to 6% of eligible pay and a Company contribution equal to 3% of eligible pay
  • Employee Assistance Program
  • Confidential counseling services and resources
  • Matching charitable donations up to $5,000
  • Volunteer Time Off (up to 16 hours annually)
  • Paid Time Off (at least 24 days)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service