Information Security Application and Compliance Analyst

Vinson & Elkins

Houston (TX)

On-site

USD 110,000 - 150,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Vinson & Elkins in Houston seeks an Information Security Application and Compliance Analyst to design, evaluate, and establish AI security frameworks, standards, tool sets and governance controls to support secure AI application development and use.

This role anchors the firm’s AI security and governance capability, including independent evaluation of AI-generated code and AI/ML systems, and helps mature organizational capability in this space.

Qualifications

  • Associate degree or equivalent; bachelor’s preferred in information systems or cybersecurity.
  • 2–4 years in AI application security, secure code review, SDLC or AI governance.
  • Strong communication and teamwork skills; ability to document audit evidence.
  • Maintain security certifications such as CISSP, CISA or equivalent.

Responsibilities

  • Independently identifies and evaluates AI-generated code and AI/ML models for security risks and governance implications.
  • Designs AI security frameworks, standards, tool sets and governance controls for secure AI development and vendor tools.
  • Partners with security, compliance and technology teams to implement AI governance policies and control documentation.
  • Provides backup support to the security team; administers security tools and coordinates incident triage and remediation.
  • Supports third‑party/vendor risk activities, security questionnaires and audit evidence collection.

Skills

AI security assessment
Code review
SDLC practices
Policy & governance
Communication
Team collaboration
Scripting: PowerShell/Python
Audit evidence documentation

Education

Associate degree
Bachelor’s degree preferred

Tools

SIEM
EDR/AV
Vulnerability management
DLP
SAST/DAST/SCA
Microsoft 365
Purview
Copilot
Anthropic Claude
Harvey

Job description

The Information Security Application and Compliance Analyst is responsible for designing, evaluating, and establishing AI security framework, standards, tool sets and governance controls to support secure AI application development and use. This role anchors the firm’s AI security and governance capability, including independent evaluation of AI-generated code and AI/ML systems, and helps mature organizational capability in this emerging space. Under general supervision, the individual in this role also provides supporting security and compliance activities across the firm- including administering and monitoring information security applications, performing initial triage and remediation tracking for application-related security events, assisting technology teams in reducing risk throughout the application development lifecycle and supporting. security governance activities such as third-party/vendor risk support, secure development life cycle (SDLC) and use of AI, cloud, and other development tools, client and internal assessments, evidence collection, control documentation, and continuous improvement of security policies, standards, and procedures. For the full jobdescription, please click on the More Info icon.

Primary
  • Independently identifies and evaluates AI-generated code, AI/ML systems, and model behavior to assess security risks and governance implications. Works with development teams and security management to identify and recommend AI security and compliance tools plus mitigation strategies for AI-related security vulnerabilities and design flaws.
  • Designs and recommends AI security frameworks, standards, tool sets and governance controls for the firm's adoption of AI-assisted software development and AI enabled vendor tools. Establishes best practices for secure AI application development and use.
  • Partners with security management, compliance, and technology teams to develop and implement AI governance policies, procedures, and control documentation. Assists in policy and standard updates related to AI security and compliance.
Secondary
  • Provides backup support to the security team on routine information security operations, including administration and monitoring of security tools, incident triage, and remediation coordination.
  • Administers, monitors, and tunes information security applications and integrations (e.g., vulnerability management, endpoint protection, DLP, phishing defense, SIEM/SOAR, and application security scanning tools) to detect and reduce risk.
  • Handles technical 2nd level user support escalations on security issues from the help desk. Acts as liaison between Information Security and the help desk, as well as national and international IT support managers. Performs initial triage of security events impacting applications and supporting platforms; coordinates containment, remediation tracking, and documentation in accordance with incident response procedures.
  • Monitors and manages security tools such as EPM, antivirus, SIEM, phishing, vulnerability management, and DLP solutions to help detect and protect from security vulnerabilities, incidents, and data loss.
  • Partners with infrastructure, application, AI and cloud teams to implement secure configuration baselines, least-privilege access, and compensating controls; assists with troubleshooting technical issues with information security applications.
  • Coordinates and communicates with TDS resources on implementation and remediation of identified security vulnerabilities and deficiencies, including verification of fixes and reporting of status/metrics.
  • Assists with access governance activities (e.g., privileged access reviews, application account administration support, and evidence for user/system access controls) in alignment with policy and audit requirements.
  • Supports security compliance initiatives including certification programs, internal/client assessments, policy/standard updates, control testing, and audit evidence collection and retention.
  • Assists with third-party/vendor risk activities, including security questionnaires, documentation review, tracking of remediation items, and ongoing monitoring support.
  • Contributes to security awareness content and guidance related to secure application use, data handling, and phishing defense.
  • Performs other duties as assigned.
Education
  • Minimum Qualifications
  • Associate's degree or equivalent college coursework required; Bachelor’s degree in Information Systems, Computer Science, Cybersecurity, or a related field preferred.
  • Equivalent work experience may be considered in lieu of a degree.
Experience
  • Two to four years’ experience in AI application security, secure code review, SDLC practices, or AI governance functions supporting information security applications and/or application security and compliance functions, such as vulnerability management, security scanning, endpoint protection, identity and access processes, security assessment support and incident response.
  • Strong communication skills plus team and collaborative skills are preferred.
Special Knowledge
  • Working knowledge of secure SDLC concepts and common application security risks (e.g., OWASP Top 10), AI Security risks and governance frameworks, as well as security control concepts (e.g., access control, logging/monitoring, change management, data protection) with emphasis on Artificial Intelligence in a development environment.
Technical Skills
  • Experience with AL/ML security assessment and code review methodologies.
  • Experience with Microsoft Windows, Microsoft 365, Microsoft Purview and Artificial Intelligence applications such as Microsoft Copilot, Anthropic Claude, and Harvey.
  • Experience with security tooling such as SIEM, EDR/AV, vulnerability management platforms, DLP, email/phishing defense, and application security testing tools (SAST/DAST/SCA) preferred.
  • Ability to analyze logs and findings, create clear remediation guidance, and perform validation.
  • Scripting/automation experience (PowerShell and/or Python) is a plus. Familiarity with cloud and AI platforms and CI/CD processes is recommended.
Attributes
  • Ability to resolve problems in a timely manner, prioritize effectively, and communicate clearly and professionally with both technical and non-technical stakeholders.
  • Ability to work independently and apply professional judgment in evaluating complex AI security issues.
  • Strong documentation skills with attention to detail for audit evidence.
  • Ability to work successfully in a team environment with limited supervision and to manage multiple workstreams simultaneously.
Qualifications
  • Maintain or obtain a current security certification such as Security+, SSCP, CSSLP, CISSP, CISA, AAISM, or similar.
  • Must be able to maintain confidentiality regarding all firm information.
Working Conditions
  • Job is performed in a typical office environment or under Work From Home (WFH) guidelines, but is subject to time pressures and constraints, and is often dependent on input from others.
  • Periodic requirements for after-hours projects and support.

The above statements are intended to describe the general nature and level of work being performed by persons assigned to this job. They are not intended to be an exhaustive list of all duties, responsibilities, qualifications and skills required of personnel so classified. The firm reserves the right to revise or modify this job description at any time.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Application and Compliance Analyst - Austin, Dallas, Houston
Information Security Application and Compliance Analyst - Austin, Dallas, Houston

Vinson & Elkins • Dallas (TX)

On-site
USD 110,000 - 160,000
Information Security Application and Compliance Analyst - Austin, Dallas, Houston
Information Security Application and Compliance Analyst - Austin, Dallas, Houston

Vinson & Elkins • Mesquite (TX)

On-site
USD 95,000 - 125,000
IT Security Analyst
IT Security Analyst

Fortegra • Jacksonville (FL)

On-site
USD 85,000 - 120,000
Information Security Engineer
Information Security Engineer

Dealer Tire • United States

On-site
USD 120,000 - 155,000
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
Information Technology Security Analyst
Information Technology Security Analyst

Brooksource • Allentown

On-site
USD 75,000 - 95,000
AI Security Analyst-- BHADC5698041
AI Security Analyst-- BHADC5698041

Compunnel Inc. • United States

On-site
USD 70,000 - 90,000
Compliance, Security & AI Governance Analyst
Compliance, Security & AI Governance Analyst

Alliance Enterprises, Inc. • United States

On-site
USD 80,000 - 110,000
Health care benefits
Retirement benefits (e.g., 401(k))
Paid time off
+1
AI Security Analyst | Camden Corporate Office
AI Security Analyst | Camden Corporate Office

Camden Development, Inc. • Houston (TX)

On-site
USD 100,000 - 130,000
Health insurance
401(k) plan
Flexible work hours
Senior Security AI Engineer
Senior Security AI Engineer

Imperial PFS • Kansas City (MO)

On-site
USD 130,000 - 160,000