Security & AI Governance Lead

Tribe AI

United States

Remote

USD 180,000 - 260,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Tribe AI is seeking a Security and AI Governance Lead to own corporate security, compliance, and AI governance. You will lead security reviews, incident response, and customer-facing risk discussions while partnering with Engineering, Legal, and Delivery.

This role reports to the CTO and requires deep experience building enterprise security programs. You will shape governance for coding agents and AI workflows, drive scalable controls, and advance secure delivery across client projects.

Qualifications

  • 8+ years in security spanning enterprise security and GRC programs.
  • Led demanding security reviews, diligence sessions, and escalations with large enterprise customers.
  • Pragmatic technical depth to interrogate architectures, trace data flows, and validate controls.
  • Owned SOC 2 or ISO 27001 cycles from design through audit and remediation.
  • Credible and precise under pressure, distinguishing facts from assumptions and roadmaps from reality.
  • Able to balance strategic thinking with execution while protecting the business.

Responsibilities

  • Lead enterprise security reviews, questionnaires, diligence, and escalations with precise answers about controls and gaps.
  • Own SOC 2 program and future certifications, along with the Trust Center and evidence library.
  • Partner with GTM, Legal, and Delivery to remove security blockers while managing vendor risk and data retention.
  • Own security roadmap, risk register, policies, metrics, and executive reporting.
  • Establish and improve controls across identity, MFA, access lifecycle, encryption, logging, and SIEM.
  • Own incident readiness and response, including severity decisions and postmortems.
  • Define governance for coding agents, AI assistants, and subprocessors—data flows and retention.
  • Partner on architecture reviews, threat modeling, secure SDLC, and production readiness.
  • Turn delivery lessons into reusable controls and patterns for the team.

Skills

Security governance
GRC program
SOC 2
ISO 27001
Threat modeling
Secure SDLC
Incident response
Data protection
Vendor risk

Job description

About Tribe AI

At Tribe, we're on a mission to help enterprises realize the value of AI for their business. Every large enterprise wants to use AI to transform how they operate - but many don't have the capabilities to do it. That gap is our opportunity.

We're an AI-native services company that helps enterprises build and deploy best-in-class AI products that deliver real business impact. We partner closely with OpenAI and Anthropic, giving us rare visibility into the most advanced models, roadmaps, and GTM strategies in the world.

About the Role

Enterprise AI runs on trust. Tribe's teams work inside client environments, with client code, data, infrastructure, and systems. Before we can build, enterprise security teams need precise answers: What can our engineers access? Which tools process their data? What is logged or prevented? How are AI systems governed? Who is accountable when something goes wrong?

We have a strong foundation, including SOC 2 Type II, enterprise security assessments, a public Trust Center, and experience delivering in regulated environments. As the volume and sophistication of our work grows, we need a dedicated leader to make that posture systematic, measurable, and consistently defensible.

As Security and AI Governance Lead, you'll report to the CTO and own Tribe's corporate security, compliance program, AI governance, and client-facing security work. This is not a policy-only or back-office role. You'll build controls, lead difficult customer reviews, handle incidents, interrogate architectures and data flows, and help our teams ship securely without smothering them in process.

When the facts are distributed across Engineering, IT, Legal, and Delivery, you own the answer. You'll identify the right evidence owners, validate the underlying facts, resolve inconsistencies, and package the result into a clear, credible response. You'll be highly hands-on today and build the systems, and specialist partnerships Tribe needs as we scale.

Key Responsibilities
Customer Trust & Compliance
  • Lead enterprise security reviews, questionnaires, diligence, and escalations - giving precise answers about current controls, planned improvements, and how identified gaps are being managed.

  • Own Tribe's SOC 2 program and future certifications, along with the Trust Center, evidence library, and reusable customer security package.

  • Partner with GTM, Legal, and Delivery to remove legitimate security blockers while managing vendor risk, subprocessors, data retention, and sustainable customer commitments.

Security Program & Operations
  • Own Tribe's security roadmap, risk register, policies, exceptions, metrics, and executive reporting.

  • Establish and continuously improve controls across identity, SSO and MFA, access lifecycle, MDM, EDR, encryption, DLP, patching, BYOD, vulnerability management, logging, and SIEM.

  • Own incident readiness and response, including severity decisions, cross-functional coordination, client communication, tabletop exercises, postmortems, and durable remediation.

AI & Secure Delivery
  • Define governance for coding agents, AI assistants, model providers, and subprocessors—including approved accounts, data flows, retention, telemetry, and human oversight.

  • Partner with Forward Deployed Architects and infrastructure leads on architecture reviews, threat modeling, secure SDLC, authentication, client segmentation, observability, and production readiness.

  • Turn recurring customer requirements and delivery lessons into reusable controls and patterns while determining what Tribe should build, automate, outsource, or support with dedicated hires.

About You
  • You have 8+ years in security and have built or substantially improved an enterprise security and GRC program spanning identity, endpoints, data protection, monitoring, vendor risk, and incident response.

  • You have personally led demanding security reviews, questionnaires, diligence sessions, and escalations with large enterprise customers.

  • You have pragmatic technical depth: you can interrogate an architecture, trace a data flow, challenge an implementation, and determine what evidence would prove a control.

  • You have owned a SOC 2 or ISO 27001 cycle from control design and scope through audit and remediation.

  • You are credible and precise under pressure, distinguishing confirmed facts from assumptions, current controls from roadmap items, and meaningful risk from security theater.

  • You bring high agency and sound judgment, moving comfortably between strategy and execution while protecting the business without becoming a bottleneck.

Nice to Have
  • Experience securing AI or ML systems, including model providers, agentic workflows, telemetry, evaluations, and emerging AI-specific risks.

  • Experience in an AI-native services, consulting, or forward-deployed engineering environment

Why Join Us
  • Impact: Ship AI systems that don't just demo well but run at scale in Fortune 000 enterprises.

  • Growth: Stay hands-on with cutting-edge frameworks while developing field-tested instincts.

  • Variety: Solve problems across industries, from finance to healthcare to defense.

  • Culture: Work in a team that prizes resilience, creativity, and winning over process.

  • Trajectory: Build both your technical and consulting muscles in one of the most demanding roles in AI delivery.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security & AI Governance Lead United States / Remote · Full Time $260K – $300K • Offers Equity
Security & AI Governance Lead United States / Remote · Full Time $260K – $300K • Offers Equity

Tribe • Northern (KY)

Remote
USD 140,000 - 190,000
Forward Deployed AI Architect
Forward Deployed AI Architect

Tribe AI • United States

On-site
USD 150,000 - 190,000
AI Security & Governance Lead
AI Security & Governance Lead

Tribe AI • United States

Remote
USD 180,000 - 260,000
EA to Co-Founder and CEO
EA to Co-Founder and CEO

Tribe • New York (NY)

On-site
USD 100,000 - 150,000
People Operations Generalist United States / Remote · Full Time $150K – $180K • Offers Equity
People Operations Generalist United States / Remote · Full Time $150K – $180K • Offers Equity

Tribe • Northern (KY)

Remote
USD 85,000 - 115,000
AI Product Manager - Agency Exp Required (NYC-based)
AI Product Manager - Agency Exp Required (NYC-based)

TribalScale • New York (NY)

On-site
USD 120,000 - 170,000
AI Product Manager - Media Experience Required (NYC or Toronto)
AI Product Manager - Media Experience Required (NYC or Toronto)

TribalScale • New York (NY)

On-site
USD 110,000 - 165,000
Accounting Lead
Accounting Lead

Tribe AI • United States

On-site
USD 150,000 - 230,000
Governance, Risk and Compliance Lead
Governance, Risk and Compliance Lead

Thinking Machines Lab Inc. • San Francisco (CA), Northern (KY)

On-site
USD 225,000 - 350,000
Health, dental, and vision benefits
Unlimited PTO
Paid parental leave
+1
GRC Engineer
GRC Engineer

Aegis AI • United States

On-site
USD 120,000 - 180,000