- As Form Energy scales, AI tools are becoming embedded in how our teams write, code, analyze, and make decisions — through AI applications, custom skills, plugins, and autonomous agents deployed across the business
- The Manager of AI Applications will own the full lifecycle of these tools: evaluating and reviewing new AI applications before adoption, securing them against data-exposure and misuse risk, deploying and configuring them for business use, and managing their ongoing performance, access, and governance
- This is a hands‑on, cross‑functional role that combines security judgment, IT operations discipline, and a genuine curiosity about how AI systems behave — bridging the gap between fast‑moving AI capabilities and the guardrails Form Energy needs to adopt them safely and effectively
- Own the intake and review process for new AI applications, skills, plugins, and agents — assessing business value, data access, permission scope, and vendor security posture before approval
- Lead security review of AI tools, including evaluating data handling and retention practices, model/vendor trust boundaries, prompt‑injection and jailbreak exposure, third‑party plugin risk, and integration permissions (OAuth scopes, API access, connected data sources)
- Manage deployment and configuration of approved AI applications across the organization, including access provisioning, environment/tenant setup, and rollout communication and training
- Establish and maintain an inventory and risk register of all AI applications, skills, plugins, and agents in use, tracking ownership, data scope, and review status — including inactive or abandoned deployments
- Define and enforce guardrails for agentic tools specifically — reviewing what actions an agent is authorized to take autonomously (e.g., sending communications, modifying records, executing code) and setting approval thresholds, logging, and rollback procedures
- Monitor usage, cost, and performance of deployed AI tools, and manage the ongoing vendor relationship including contract renewals, model/version updates, and deprecation planning
- Partner with IT security, legal, and business stakeholders to develop and maintain AI usage policy, acceptable‑use guidelines, and an approval workflow that scales with demand without becoming a bottleneck
- Investigate and respond to AI‑related incidents (e.g., data leakage through a connected tool, unexpected agent behavior, plugin compromise), coordinating remediation and post‑incident review
- Build lightweight documentation, training, and office‑hours support to help employees use approved AI tools effectively and safely, and to route new requests through the review pipeline
- Stay current on the fast‑changing AI application, plugin, and agent landscape, and proactively flag emerging capabilities or risks relevant to Form Energy
Benefits
- 100% of medical, dental, and vision premiums covered for employees
- Health insurance coverage begins first day of employment
- Health Savings Account
- Generous PTO policies to enable employees to recharge when needed
- An Employee Resource Program that provides mental health counseling services, legal guidance, financial resources, and other helpful consulting services
- 80% of the total medical, dental, and vision premiums covered for dependents
- 12 weeks of paid parental leave, 14 weeks for the birthing parent
- Access to a Dependent Care Account
- Access to a Health Flexible Spending Account
- Access to a Commuter Benefits Account
- Access to an Adoption Assistance Flexible Spending Account
- Stock options granted to all employees
- Stock equity education and tax advice service provided by Carta
- Company sponsored 401k
- Access to an annual budget for professional development
- License to complete Gallup’s Strengths Finder Assessment and ongoing resources
- 100% employer-sponsored coverage life insurance, and short and long‑term disability policies
Strong stakeholder management skills: able to run an intake/review process that business teams actually use, and to say no to risky requests without becoming a blockerWorking knowledge of AI/LLM security concepts — data exfiltration risk, prompt injection, model access controls, plugin/tool permission scopes, and agent autonomy riskClear written and verbal communication; able to translate technical AI risk into guidance non-technical stakeholders can act onDirect experience evaluating, deploying, or managing AI applications, copilots, or LLM-based tools in a business or enterprise IT settingProject and program management skills: able to track a growing portfolio of tools, vendors, and review cycles with clear documentation and measurable outcomesComfort with SaaS security fundamentals: OAuth and API permission review, third‑party integration risk assessment, and access governance