Aecon Group Inc

Lead, AI Security Governance & Operations

Aecon Group Inc$120K — $125K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in security architecture, cloud security, or operations
  • Expertise in securing AI/ML and data platforms in production
  • Knowledge of identity/access management and encryption
  • Hands-on with enterprise security controls and tools
  • Proficient in translating technical risk into actionable plans

Responsibilities

  • Design and own end-to-end security for AI/ML platforms
  • Define and enforce secure controls for AI applications
  • Implement security tools to manage AI usage
  • Create detection rules for AI-specific threats
  • Manage AI-related security risks and establish standards
  • Lead third-party AI risk assessments and compliance
  • Track AI security posture and enforce remediation plans

Benefits

  • Opportunity to lead in a cutting-edge AI security role
  • Engagement with AI governance frameworks and best practices
  • Collaboration with cross-functional teams in a dynamic environment
  • Support for continuous learning and career development
  • Access to innovative security tooling and technologies
Full Job Description
What is the Opportunity?

The AI Security Governance & Operations Lead will drive the secure design, governance, and day-to-day protection of artificial intelligence (AI) and machine learning (ML) capabilities across the organization. This role blends Security Operations (SecOps) and Governance, Risk & Compliance (GRC) to ensure AI solutions - including generative AI, predictive analytics, and automation - are secure, compliant, monitored, and continuously improved. The ideal candidate bridges security architecture, operational security tooling, and practical delivery in asset-intensive environments (e.g., construction, engineering, and project delivery).

What You'll Do Here:

AI Security Architecture & Guardrails
  • Design and own end-to-end security patterns for AI/ML platforms across data ingestion, model development, training, deployment, and monitoring.
  • Define and enforce secure-by-design controls for AI (identity and access, segmentation, encryption, secrets management, secure APIs, and inference protection).
  • Establish controls for generative AI including prompt protection, data leakage prevention, misuse prevention, and output risk management.


Hands-on Security Tooling & Configuration (AI-Specific)
  • Implement and tune security controls in enterprise security tools that govern AI usage (e.g., data loss prevention, sensitivity labeling, access policies, conditional access, and tenant/app configuration).
  • Configure and validate logging, telemetry, and audit coverage for AI services, AI endpoints, and AI-enabled applications; ensure logs are usable for detection and investigations.
  • Create, test, and refine detection rules and alerting for AI-specific threats (e.g., prompt injection attempts, anomalous access, data exfiltration patterns, and unsafe plugin/connector usage).
  • Assess AI-specific tools and features as they are introduced (e.g., security posture capabilities, AI governance features) and configure security components as required to meet standards.
  • Partner with platform teams to harden AI environments (RBAC, network restrictions, private endpoints where applicable, key management, and secure CI/CD for model/application deployments).
  • Perform hands-on validation (tabletop + technical) of control effectiveness-spot checks, configuration reviews, and evidence capture for audits.


Risk, Governance & Compliance (GRC)
  • Identify and manage AI-specific security risks such as data poisoning, model inversion, prompt injection, IP leakage, and unauthorized model retraining.
  • Develop AI security standards, reference architectures, and guardrails aligned with enterprise frameworks (e.g., NIST, ISO 27001, Zero Trust) and ensure they are operationalized.
  • Support privacy, data protection, and regulatory/contractual obligations by defining AI control requirements, mapping controls to policies, and maintaining evidence.
  • Lead third-party AI risk activities with Legal, Privacy, and Risk teams (intake requirements, security assessments, and ongoing monitoring expectations).


Security Operations (SecOps) for AI
  • Act as the escalation point for AI-related security events-triage, coordinate investigation, and support containment and remediation in collaboration with SecOps.
  • Operationalize incident response playbooks for AI services and AI-enabled applications, including communications, evidence handling, and post-incident reviews.
  • Track and report AI security posture metrics (e.g., policy coverage, high-risk exceptions, recurring alert types) and drive remediation plans with owners.


Construction & Engineering Context (Preferred)
  • Apply AI security controls to construction and engineering use cases such as BIM/digital twins, predictive scheduling/cost modeling, safety analytics, computer vision for site monitoring, and AI-enabled asset lifecycle tools.
  • Understand and mitigate risks related to project data, design IP, site telemetry, and operational technology (OT) interfaces.


Collaboration & Enablement
  • Work closely with Architecture, AI, and Enterprise Technology to balance security, innovation, and delivery speed.
  • Provide security input for AI vendor selection, architecture reviews, and proofs of concept, including required controls and go-live criteria.
  • Enable responsible adoption through practical guidance, patterns, and runbooks that teams can implement (not just policy statements).
  • Advise leaders on AI risk posture and trade-offs in clear, business-relevant terms.


What You Bring to the Team:
  • 8+ years of experience in security architecture, cloud security, security engineering, or security operations.
  • Experience securing AI/ML, data analytics, or automation platforms in production environments.
  • Working knowledge of identity and access management, encryption/key management, logging/monitoring, and security incident response.
  • Hands-on experience configuring and operating security controls in enterprise security tools (policy configuration, monitoring, detection, and evidence capture).
  • Ability to translate technical risk into clear recommendations and actionable remediation plans.


Preferred Qualifications
  • Experience in construction, engineering, infrastructure, industrial, or other asset-intensive sectors.
  • Familiarity with BIM, digital twins, project management systems, or OT/ICS environments.
  • Experience with AI governance frameworks, responsible AI, model risk management, and third-party risk assessment.
  • Certifications such as CISSP, CCSP, SABSA, cloud security certifications, and/or AI-related coursework/certifications.


Reason for vacancy: New

The expected salary range for this role is $120,000 - $125,000 per year

Individual pay is determined based on several factors, including work location, education, experience, unique skills and job conditions. Other considerations may includecertifications, specialized training, and the complexity or scope of the role.

About Aecon Group Inc

Aecon Group Inc. is a Canadian construction company that provides a range of services to clients in the infrastructure, energy, and mining sectors. The company's services include construction, engineering, procurement, and project management. Aecon has completed a number of high-profile projects in Canada, including the construction of the CN Tower and the Vancouver SkyTrain. Founded in 1957, the company is headquartered in Toronto, Ontario.
Learn more about Aecon Group Inc
Size
12,000 employees
Industry
Founded
1877

Similar Jobs

More Jobs at Aecon Group Inc

More Information Technology Jobs

Find similar Lead, AI Security Governance & Operations jobs: