You have the opportunity to join our team and tackle business challenges in a dynamic, purpose-driven environment characterized by close collaboration with business stakeholders.
As a Domain Lead - AI Governance & Security, you will build and run the governance, risk and control framework that allows a global market leader in chemical and ingredients distribution to adopt Artificial Intelligence responsibly, securely and in line with emerging regulation such as the EU AI Act. Operating across dozens of countries, the company is accelerating its use of AI - from internal tools and pilots to customer-facing features - and needs a practical, second-line-of-defense view of the risks that come with it.
You will join the Information Security Governance, Risk and Compliance (GRC) team within the global Information Security organization, led by the Global Chief Information Security Officer (CISO), and work closely with Information Security, Enterprise Architecture, Data & Analytics, Legal, Privacy, Compliance and business stakeholders to ensure that AI systems, models, agents and AI-enabled vendors are governed throughout their lifecycle. This is a hands-on role for someone who can turn regulatory requirements and AI risks into concrete, workable controls.
Your Role and Responsibilities:
- AI Governance Framework & Policy: Define, build and maintain the AI governance framework, including the AI risk taxonomy, assessment methodology and control requirements. Contribute to AI policies, standards and guidelines (e.g., acceptable use of generative AI, model standards, data usage rules), and align AI governance with enterprise risk management, security policies and applicable regulations such as the EU AI Act and sector-specific rules.
- AI Use Case Intake & Oversight: Run the intake process for new AI initiatives - internal tools, customer-facing features and pilots. Classify use cases by risk (low, medium, high), determine the level of review and controls each one needs, embed governance checkpoints across the AI lifecycle (design, build, test, go-live, monitor), and help bring unsanctioned ('shadow') AI usage under governance.
- AI Risk Assessments & Security Controls: Design and execute AI-specific risk assessments covering data privacy and data leakage; model security (prompt injection, model exfiltration, adversarial attacks); model drift; bias, fairness, explainability and human oversight; and licensing, IP and third‑party model dependencies. Define and validate controls and technical test cases for AI systems (e.g., guardrails, output filtering, access controls, logging, red teaming), and work with security architecture, engineering and data governance teams to implement controls and remediate gaps.
- Vendor AI Risk & Due Diligence: Design AI-specific due diligence questionnaires and assessment criteria for AI vendors and models. Evaluate vendor AI offerings for security, compliance (e.g., SOC 2, ISO/IEC 42001), model documentation (model cards, data sheets) and contractual safeguards, and maintain a risk‑rated inventory of AI vendors, monitoring changes in their risk posture.
- Monitoring, Reporting & Continuous Improvement: Report AI risk posture, key incidents and governance metrics to the CISO and relevant committees. Continuously improve the AI governance program based on incidents, regulatory changes and industry best practices.
- Integration with Enterprise GRC: Ensure AI risks and controls are reflected in the enterprise risk register, policy suite and audit programs, and aligned with broader GRC tooling, workflows and reporting. Support customer AI questionnaires, RFPs and regulatory inquiries related to AI.
Your Skills and Experiences:
- A degree in information security, computer science, risk management or a related field is an advantage, but not required.
- 5+ years of experience in GRC, risk management, information security or model risk roles, including at least 2 years focused on AI governance, responsible AI and AI risk management.
- Working knowledge of the EU AI Act and ISO/IEC 42001 (AI management systems), plus familiarity with the NIST AI Risk Management Framework (AI RMF) and other emerging AI regulations.
- Proven experience assessing AI vendors, models and use cases.
- Solid understanding of AI security threats - such as prompt injection, data leakage, model theft and agent misuse - and the practical mitigations and guardrails that address them.
- Ability to translate policy and legal requirements into practical, testable controls and workflows, combining conceptual framework thinking with a pragmatic, hands‑on approach.
- Experience working with data science, ML engineering or product teams.
- Relevant certifications such as ISO/IEC 42001 Lead Implementer or Lead Auditor, IAPP AIGP, CISM or CRISC are an advantage.
- Experience with GRC platforms such as Archer or ServiceNow is a plus.
- Experience in the chemical, distribution or supply‑chain industry is a plus.
- Strong communication skills, with the ability to explain AI risks and controls clearly to technical and non‑technical stakeholders.
- Strong sense of ownership, accountability and urgency, particularly during security incidents, and the ability to collaborate effectively with internal IT teams and external service providers in a global, multicultural, cross‑functional environment.
- Eagerness to stay current with emerging AI threats, attack techniques, AI risk management frameworks and security technologies.
- Fluency in English (spoken and written) is essential; German is a plus.
What you can expect from us:
- Remote-flexible environment;
- Highly attractive salary and benefits;
- Great work‑life balance and flexibility;
- Find meaning and purpose in your day‑to‑day work; your expertise has a visible impact on the digitalization of a global industry leader;
- You will be part of a company where commitment, quality, and continuous improvement are core principles of our culture;
- Highly engaged tech community;
- International career opportunities;
- Focus on individual development.
About us:
xelerate.tech is passionate about software, tech, and people. We aim to attract the most talented engineers to deliver high-quality software products through highly performant teams.