Lead, AI Security Governance & Operations

AeconToronto, ON
CA$120,000 - CA$125,000

About The Position

The AI Security Governance & Operations Lead will drive the secure design, governance, and day-to-day protection of artificial intelligence (AI) and machine learning (ML) capabilities across the organization. This role blends Security Operations (SecOps) and Governance, Risk & Compliance (GRC) to ensure AI solutions - including generative AI, predictive analytics, and automation - are secure, compliant, monitored, and continuously improved. The ideal candidate bridges security architecture, operational security tooling, and practical delivery in asset-intensive environments (e.g., construction, engineering, and project delivery).

Requirements

  • 8+ years of experience in security architecture, cloud security, security engineering, or security operations.
  • Experience securing AI/ML, data analytics, or automation platforms in production environments.
  • Working knowledge of identity and access management, encryption/key management, logging/monitoring, and security incident response.
  • Hands-on experience configuring and operating security controls in enterprise security tools (policy configuration, monitoring, detection, and evidence capture).
  • Ability to translate technical risk into clear recommendations and actionable remediation plans.

Nice To Haves

  • Experience in construction, engineering, infrastructure, industrial, or other asset-intensive sectors.
  • Familiarity with BIM, digital twins, project management systems, or OT/ICS environments.
  • Experience with AI governance frameworks, responsible AI, model risk management, and third-party risk assessment.
  • Certifications such as CISSP, CCSP, SABSA, cloud security certifications, and/or AI-related coursework/certifications.

Responsibilities

  • Design and own end-to-end security patterns for AI/ML platforms across data ingestion, model development, training, deployment, and monitoring.
  • Define and enforce secure-by-design controls for AI (identity and access, segmentation, encryption, secrets management, secure APIs, and inference protection).
  • Establish controls for generative AI including prompt protection, data leakage prevention, misuse prevention, and output risk management.
  • Implement and tune security controls in enterprise security tools that govern AI usage (e.g., data loss prevention, sensitivity labeling, access policies, conditional access, and tenant/app configuration).
  • Configure and validate logging, telemetry, and audit coverage for AI services, AI endpoints, and AI-enabled applications; ensure logs are usable for detection and investigations.
  • Create, test, and refine detection rules and alerting for AI-specific threats (e.g., prompt injection attempts, anomalous access, data exfiltration patterns, and unsafe plugin/connector usage).
  • Assess AI-specific tools and features as they are introduced (e.g., security posture capabilities, AI governance features) and configure security components as required to meet standards.
  • Partner with platform teams to harden AI environments (RBAC, network restrictions, private endpoints where applicable, key management, and secure CI/CD for model/application deployments).
  • Perform hands-on validation (tabletop + technical) of control effectiveness—spot checks, configuration reviews, and evidence capture for audits.
  • Identify and manage AI-specific security risks such as data poisoning, model inversion, prompt injection, IP leakage, and unauthorized model retraining.
  • Develop AI security standards, reference architectures, and guardrails aligned with enterprise frameworks (e.g., NIST, ISO 27001, Zero Trust) and ensure they are operationalized.
  • Support privacy, data protection, and regulatory/contractual obligations by defining AI control requirements, mapping controls to policies, and maintaining evidence.
  • Lead third-party AI risk activities with Legal, Privacy, and Risk teams (intake requirements, security assessments, and ongoing monitoring expectations).
  • Act as the escalation point for AI-related security events—triage, coordinate investigation, and support containment and remediation in collaboration with SecOps.
  • Operationalize incident response playbooks for AI services and AI-enabled applications, including communications, evidence handling, and post-incident reviews.
  • Track and report AI security posture metrics (e.g., policy coverage, high-risk exceptions, recurring alert types) and drive remediation plans with owners.
  • Apply AI security controls to construction and engineering use cases such as BIM/digital twins, predictive scheduling/cost modeling, safety analytics, computer vision for site monitoring, and AI-enabled asset lifecycle tools.
  • Understand and mitigate risks related to project data, design IP, site telemetry, and operational technology (OT) interfaces.
  • Work closely with Architecture, AI, and Enterprise Technology to balance security, innovation, and delivery speed.
  • Provide security input for AI vendor selection, architecture reviews, and proofs of concept, including required controls and go-live criteria.
  • Enable responsible adoption through practical guidance, patterns, and runbooks that teams can implement (not just policy statements).
  • Advise leaders on AI risk posture and trade-offs in clear, business-relevant terms.

Benefits

  • Services and benefits needed to support your mental, emotional, and physical well-being.
  • Aecon University
  • tuition reimbursement
  • Leadership Programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service