Who You’ll Work With:
The Information Technology (IT) organization is the technological foundation of our business and works in collaboration with our partners from across the company. The team drives technology and digital transformation and partners with business leaders to design and execute new strategies across the company. They also ensure the necessary IT risk management and security measures are in place and aligned with enterprise architecture standards and principles.
About The Role:
The Director of AI Security will own the enterprise’s AI Security Standard and the technical security program that operationalizes it — designing, implementing, and governing the controls that ensure the organization builds and consumes artificial intelligence (including generative AI, agentic AI, and third-party/embedded AI capabilities) securely and in compliance with emerging regulatory expectations.
Reporting to the Head of Cyber Data Protection and AI Security, this role works in close, continuous partnership with the Enterprise AI team, which owns the overarching AI Strategy and AI Standard (governing acceptable use, business adoption, and enterprise AI investment). The Director of AI Security ensures that standard is backed by a rigorous, enforceable security layer — covering model risk, data protection, identity, vulnerability management, and attack-path/threat modeling across the AI lifecycle, from model selection and data sourcing through deployment, monitoring, and decommissioning.
This is a hands-on leadership role for someone who can operate simultaneously at the standards/control-framework level (audit- and board-ready documentation) and the technical control level, while building a trusted, collaborative relationship with a peer team that owns adjacent AI governance.
Responsibilities:AI Security Standard Ownership & Cross-Functional Alignment- Ensure the AI Security Standard is fully aligned with, and traceable to, the Enterprise AI team’s AI Strategy and AI Standard — acting as the primary security liaison and co-author on any sections where the two documents intersect (approved use cases, data handling, model sourcing).
- Partner with the Enterprise AI team to define and maintain the security review criteria feeding the Approved AI/Model List, including risk-tiering methodology for AI types (traditional ML, generative AI, agentic AI, embedded/third-party AI) and a joint exception/waiver process.
- Co-develop Appropriate Use Policy (AUP) security requirements with the Enterprise AI team, ensuring employee-, developer-, and business-unit-facing guidance reflects both AI Standard intent and AI Security Standard controls.
- Map AI security requirements to relevant regulatory and industry frameworks (e.g., NIST AI RMF, ISO/IEC 42001, EU AI Act, OWASP Top 10 for LLMs, MITRE ATLAS) and translate them into the internal control requirements embedded in the AI Security Standard.
- Establish a standing governance cadence (working group, review board, or joint steering sync) with the Enterprise AI team to keep the AI Standard and AI Security Standard synchronized as AI adoption scales and regulations evolve.
AI Security Architecture & Risk Management- Lead security risk assessments for AI/ML pipelines, generative AI deployments, and agentic AI systems, addressing risks such as prompt injection, data leakage, model poisoning, excessive agency, insecure tool/plugin integration, and supply chain risk in third-party models.
- Partner with data protection, identity, and vulnerability management teams to extend existing enterprise security programs into AI-specific contexts — including access controls for model endpoints, data classification for training/inference data, and secure API/agent orchestration.
- Own attack path and threat modeling for AI assets — identifying novel and indirect attack paths introduced by AI integrations across applications, devices, and data sources, and driving remediation prioritization.
- Evaluate and secure agent creation platforms (e.g., Copilot Studio, custom agent frameworks) used within regulated business functions, ensuring guardrails, logging, and human-in-the-loop controls are enforced.
Program & Cross-Functional Leadership- Serve as the primary security stakeholder in AI procurement, vendor risk assessments, and build-vs-buy decisions for AI capabilities.
- Partner with Legal, Privacy, Compliance, and Data Governance teams to ensure AI initiatives meet regulatory obligations (data privacy, sector-specific regulation, third-party risk).
- Build and lead a small team (or dotted-line working group) of AI security engineers/analysts as the program scales. Utilize support from MSSP and specialized contractors as the team scales.
- Report AI security posture, control maturity, and incident trends to the Head of Cyber Data Protection and AI Security, and support executive/board-level reporting as needed.
- Lead incident response planning and tabletop exercises specific to AI security failure modes (model misuse, data exfiltration via AI tools, agent misbehavior).
Enablement & Culture- Develop training and awareness programs to help engineering, product, and business teams understand and apply the AI Security Standard in coordination with Enterprise AI’s broader AI Standard training.
- Act as an internal advisor/enabler — helping teams adopt AI safely rather than acting purely as a gatekeeper.
- Track the token/compute cost and risk-remediation ROI of using frontier AI models for security use cases (e.g., automated vulnerability triage, code remediation) to inform build decisions.
Skills and Qualifications:- 10+ years in cybersecurity, with at least 3–5 years focused on data protection, cloud security, or emerging technology risk; demonstrated ownership of a formal security standard or governance framework.
- Direct experience authoring or operationalizing AI security standards (or directly transferable experience in data protection/data governance standards) at an enterprise level, including experience partnering with an adjacent team that owns broader AI strategy/policy.
- Strong understanding of AI/ML lifecycle risks, generative AI security concerns, and emerging agentic AI risk patterns.
- Familiarity with relevant frameworks: NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, MITRE ATLAS, EU AI Act, NIST 800-53/CSF.
- Experience with Microsoft security/identity stack and/or vulnerability management platforms (e.g., Qualys VMDR) as applied to AI asset inventory and control coverage.
- Experience with AI Security platforms (e.g. Varonis Atlas) to discover and monitor AI usage, evaluate AI interactions, perform security testing of AI models and collect compliance events data related to AI usage.
- Experience in regulated industries (financial services, healthcare, defense, critical infrastructure) and ability to translate regulatory requirements into technical/administrative controls.
- Demonstrated ability to build effective, collegial working relationships across peer teams with adjacent but distinct ownership (e.g., co-authoring standards, joint governance boards) without formal authority over those teams.
- Bachelor’s degree or equivalent experience; relevant certifications a plus (CISSP, CCSP, AI governance certifications, etc.).
Preferred Qualifications:- Experience building or contributing to a risk intelligence / GRC platform that aggregates vulnerability, asset, and attack-path data across applications, devices, and people.
- Experience with M&A security due diligence, including assessing AI/data risk in acquired entities.
- Background in OT/ICS or classified/high-assurance environments.
- Experience configuring or evaluating agent orchestration platforms (e.g., Microsoft Copilot Studio) for security and compliance.
- Hands-on experience building and deploying AI applications, including generative AI or agent-based solutions.
- Demonstrated experience automating security assessments and operational processes through workflow platforms, scripting, or AI-enabled solutions, with measurable improvements in speed, quality, or control effectiveness.
Compensation
Not all candidates will be eligible for the upper end of the salary range. The actual compensation offered will ultimately be dependent on multiple factors, which may include the candidate’s geographic location, skills, experience and other qualifications.
In addition, the position is eligible for a discretionary bonus in accordance with the terms of the applicable incentive plan.
Corebridge also offers a range of competitive benefits as part of the total compensation package, as detailed below.
Work Location
This position is based in Corebridge Financial’s Houston, TX office and is subject to our hybrid working policy, which gives colleagues the benefits of working both in an office and remotely.
Open to considering remote candidates.
#LI-RL1 #LI-SAFG #LI-Hybrid #LI-Remote