Skip to content
All jobs

Director, AI Security

Corebridge Financial

Job
30805
Posted
Location
Houston, TX
Work type
Full Time
Tax terms
W2, Yearly
Experience
Experience open
Openings
1 opening

Skills

  • Brand
  • Accountability
  • Enterprise Architecture
  • Partnership
  • Auditing
  • Sourcing
  • Internal Control
  • Embedded Systems
  • Cadence
  • Security Architecture
  • Risk Management
  • Supply Chain Management
  • Access Control
  • API
  • Threat Modeling
  • Procurement
  • Risk Assessment
  • Build Vs Buy
  • Incident Management
  • Return On Investment

About the job

Who We Are

At Corebridge Financial, we believe action is everything. That's why every day we partner with financial professionals and institutions to make it possible for more people to take action in their financial lives, for today and tomorrow.

We align to a set of Values that are the core pillars that define our culture and help bring our brand purpose to life:

  • We are stronger as one: We collaborate across the enterprise, scale what works and act decisively for our customers and partners.
  • We deliver on commitments: We are accountable, empower each other and go above and beyond for our stakeholders.
  • We learn, improve and innovate: We get better each day by challenging the status quo and equipping ourselves for the future.
  • We are inclusive: We embrace different perspectives, enabling our colleagues to make an impact and bring their whole selves to work.

Who You'll Work With:

The Information Technology (IT) organization is the technological foundation of our business and works in collaboration with our partners from across the company. The team drives technology and digital transformation and partners with business leaders to design and execute new strategies across the company. They also ensure the necessary IT risk management and security measures are in place and aligned with enterprise architecture standards and principles.

About The Role:

The Director of AI Security will own the enterprise's AI Security Standard and the technical security program that operationalizes it - designing, implementing, and governing the controls that ensure the organization builds and consumes artificial intelligence (including generative AI, agentic AI, and third-party/embedded AI capabilities) securely and in compliance with emerging regulatory expectations.

Reporting to the Head of Cyber Data Protection and AI Security, this role works in close, continuous partnership with the Enterprise AI team, which owns the overarching AI Strategy and AI Standard (governing acceptable use, business adoption, and enterprise AI investment). The Director of AI Security ensures that standard is backed by a rigorous, enforceable security layer - covering model risk, data protection, identity, vulnerability management, and attack-path/threat modeling across the AI lifecycle, from model selection and data sourcing through deployment, monitoring, and decommissioning.

This is a hands-on leadership role for someone who can operate simultaneously at the standards/control-framework level (audit- and board-ready documentation) and the technical control level, while building a trusted, collaborative relationship with a peer team that owns adjacent AI governance.

Responsibilities:

AI Security Standard Ownership & Cross-Functional Alignment

  • Ensure the AI Security Standard is fully aligned with, and traceable to, the Enterprise AI team's AI Strategy and AI Standard - acting as the primary security liaison and co-author on any sections where the two documents intersect (approved use cases, data handling, model sourcing).
  • Partner with the Enterprise AI team to define and maintain the security review criteria feeding the Approved AI/Model List, including risk-tiering methodology for AI types (traditional ML, generative AI, agentic AI, embedded/third-party AI) and a joint exception/waiver process.
  • Co-develop Appropriate Use Policy (AUP) security requirements with the Enterprise AI team, ensuring employee-, developer-, and business-unit-facing guidance reflects both AI Standard intent and AI Security Standard controls.
  • Map AI security requirements to relevant regulatory and industry frameworks (e.g., NIST AI RMF, ISO/IEC 42001, EU AI Act, OWASP Top 10 for LLMs, MITRE ATLAS) and translate them into the internal control requirements embedded in the AI Security Standard.
  • Establish a standing governance cadence (working group, review board, or joint steering sync) with the Enterprise AI team to keep the AI Standard and AI Security Standard synchronized as AI adoption scales and regulations evolve.

AI Security Architecture & Risk Management

  • Lead security risk assessments for AI/ML pipelines, generative AI deployments, and agentic AI systems, addressing risks such as prompt injection, data leakage, model poisoning, excessive agency, insecure tool/plugin integration, and supply chain risk in third-party models.
  • Partner with data protection, identity, and vulnerability management teams to extend existing enterprise security programs into AI-specific contexts - including access controls for model endpoints, data classification for training/inference data, and secure API/agent orchestration.
  • Own attack path and threat modeling for AI assets - identifying novel and indirect attack paths introduced by AI integrations across applications, devices, and data sources, and driving remediation prioritization.
  • Evaluate and secure agent creation platforms (e.g., Copilot Studio, custom agent frameworks) used within regulated business functions, ensuring guardrails, logging, and human-in-the-loop controls are enforced.

Program & Cross-Functional Leadership

  • Serve as the primary security stakeholder in AI procurement, vendor risk assessments, and build-vs-buy decisions for AI capabilities.
  • Partner with Legal, Privacy, Compliance, and Data Governance teams to ensure AI initiatives meet regulatory obligations (data privacy, sector-specific regulation, third-party risk).
  • Build and lead a small team (or dotted-line working group) of AI security engineers/analysts as the program scales. Utilize support from MSSP and specialized contractors as the team scales.
  • Report AI security posture, control maturity, and incident trends to the Head of Cyber Data Protection and AI Security, and support executive/board-level reporting as needed.
  • Lead incident response planning and tabletop exercises specific to AI security failure modes (model misuse, data exfiltration via AI tools, agent misbehavior).

Enablement & Culture

  • Develop training and awareness programs to help engineering, product, and business teams understand and apply the AI Security Standard in coordination with Enterprise AI's broader AI Standard training.
  • Act as an internal advisor/enabler - helping teams adopt AI safely rather than acting purely as a gatekeeper.
  • Track the token/compute cost and risk-remediation ROI of using frontier AI models for security use cases (e.g., automated vulnerability triage, code remediation) to inform build decisions.

Skills and Qualifications:

  • 10+ years in cybersecurity, with at least 3-5 years focused on data protection, cloud security, or emerging technology risk; demonstrated ownership of a formal security standard or governance framework.
  • Direct experience authoring or operationalizing AI security standards (or directly transferable experience in data protection/data governance standards) at an enterprise level, including experience partnering with an adjacent team that owns broader AI strategy/policy.
  • Strong understanding of AI/ML lifecycle risks, generative AI security concerns, and emerging agentic AI risk patterns.
  • Familiarity with relevant frameworks: NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, MITRE ATLAS, EU AI Act, NIST 800-53/CSF.
  • Experience with Microsoft security/identity stack and/or vulnerability management platforms (e.g., Qualys VMDR) as applied to AI asset inventory and control coverage.
  • Experience with AI Security platforms (e.g. Varonis Atlas) to discover and monitor AI usage, evaluate AI interactions, perform security testing of AI models and collect compliance events data related to AI usage.
  • Experience in regulated industries (financial services, healthcare, defense, critical infrastructure) and ability to translate regulatory requirements into technical/administrative controls.
  • Demonstrated ability to build effective, collegial working relationships across peer teams with adjacent but distinct ownership (e.g., co-authoring standards, joint governance boards) without formal authority over those teams.
  • Bachelor's degree or equivalent experience; relevant certifications a plus (CISSP, CCSP, AI governance certifications, etc.).

Preferred Qualifications:

  • Experience building or contributing to a risk intelligence / GRC platform that aggregates vulnerability, asset, and attack-path data across applications, devices, and people.
  • Experience with M&A security due diligence, including assessing AI/data risk in acquired entities.
  • Background in OT/ICS or classified/high-assurance environments.
  • Experience configuring or evaluating agent orchestration platforms (e.g., Microsoft Copilot Studio) for security and compliance.
  • Hands-on experience building and deploying AI applications, including generative AI or agent-based solutions.
  • Demonstrated experience automating security assessments and operational processes through workflow platforms, scripting, or AI-enabled solutions, with measurable improvements in speed, quality, or control effectiveness.

Compensation

Not all candidates will be eligible for the upper end of the salary range. The actual compensation offered will ultimately be dependent on multiple factors, which may include the candidate's geographic location, skills, experience and other qualifications.

In addition, the position is eligible for a discretionary bonus in accordance with the terms of the applicable incentive plan.

Corebridge also offers a range of competitive benefits as part of the total compensation package, as detailed below.

Work Location

This position is based in Corebridge Financial's Houston, TX office and is subject to our hybrid working policy, which gives colleagues the benefits of working both in an office and remotely.

Open to considering remote candidates.

#LI-RL1 #LI-SAFG #LI-Hybrid #LI-Remote

This role is deemed a "covered associate" under SEC Rule 206(4)-5, 17 CFR 275.206(4)-5, Political contributions by certain investment advisers, and other federal and state pay-to-play rules. Candidates for the role must not have made any political contributions that, under 17 CFR 275.206(4)-5 or other federal or state pay-to-play regulations, would disqualify the candidate or Corebridge Financial from conducting Corebridge Financial's business, or that would otherwise create a conflict of interest for Corebridge Financial. Applicants who are selected to move forward with the application process will be required to disclose all U.S. political contributions they and their household family members have made over the past two years.

Why Corebridge?

At Corebridge Financial, we prioritize the health, well-being, and work-life balance of our employees. Our comprehensive benefits and wellness program is designed to support employees both personally and professionally, ensuring that they have the resources and flexibility needed to thrive.

Benefit Offerings Include:

Similar jobs

See all jobs