We are looking for an experienced Security, Privacy & Trust Lead to build and operationalize a pragmatic security and privacy program for an AI-driven platform. The role covers cybersecurity, privacy engineering, AI security, third-party risk, incident response, secure software development, and responsible AI.
Key Responsibilities
- Conduct end-to-end security and privacy assessments across mobile apps, APIs, cloud infrastructure, IAM, data stores, AI/LLM services, integrations, logging, and CI/CD.
- Perform threat modeling, identify vulnerabilities and privacy risks, and create a prioritized remediation roadmap.
- Develop and operationalize security and privacy policies, including information security, data retention, incident response, vendor risk, privacy impact assessments, and responsible AI.
- Establish data lifecycle, retention/deletion, anonymization, and member data-rights processes.
- Develop and test an Incident Response & Breach Notification Plan, including a tabletop exercise.
- Assess third-party vendors, DPAs, subprocessors, data sharing, and security/privacy controls.
- Establish AI security controls covering prompt injection, data leakage, AI memory, model retention, agent permissions, tool access, unsafe outputs, logging, and human oversight.
- Assess application, cloud, API, IAM, encryption, DevSecOps, vulnerability management, backup, and secure SDLC practices.
- Support readiness for SOC 2, NIST CSF, NIST AI RMF, OWASP, CCPA/CPRA, and GDPR.
- Provide executive/Board-level reporting on risks, remediation, and security maturity.
- Current-State Security & Privacy Assessment
- Security Remediation Roadmap
- Data Inventory, Data Flow & Retention Schedule
- Security & Privacy Policy Library
- Incident Response & Breach Plan
- Data Subject Rights Procedure
- Vendor Security & DPA Framework
- Privacy Impact Assessment Process
- AI Security & Responsible AI Framework
- Executive/Board Security Readout
Qualifications
- 8+ years in application/product security, cloud security, privacy engineering, security architecture, GRC, or related areas.
- Strong experience with SaaS, cloud-native, mobile, or AI-enabled applications.
- Hands‑on knowledge of AWS, APIs, OAuth/OIDC, IAM, Docker, CI/CD, DevSecOps, encryption, and secure SDLC.
- Experience with AI/LLM security and emerging GenAI risks.
- Strong understanding of privacy‑by‑design, data retention/deletion, consent, and data subject rights.
- Experience with vendor risk management, DPAs, incident response, and security policies.
- Working knowledge of SOC 2, NIST, OWASP, CCPA/CPRA, and GDPR.
- Startup/scale‑up security program experience preferred.
Ideal Candidate
A pragmatic, hands‑on security leader who can move seamlessly between architecture reviews, threat modeling, AI security, privacy policies, vendor assessments, incident response, and executive/Board discussions.
The ideal candidate can clearly prioritize what must be addressed before launch, what comes next, and what can mature as the business scales