
Director, Artificial Intelligence Security – Safeguards
Posted Sep 14

Posted Sep 14
This is a fully remote position, open to applicants in United States.
• Lead the strategy, roadmap, and implementation of Finance of America’s AI Security and Safeguards program.
• Develop controls, select appropriate tools, and assess program maturity.
• Conduct AI red teaming, adversarial testing, model and AI-enabled application security assessments, guardrail and control validation, detection engineering, and configuration and tuning of AI security tools.
• Act as the enterprise's subject matter expert in AI security.
• Recruit, nurture, and manage a small team as program demand and approved headcount allow.
• Maintain an up-to-date inventory of AI systems across the organization and manage the discovery process.
• Create and implement safeguards against AI-specific threats, including prompt injection, model and data poisoning, unauthorized model access, over-privileged agentic tools, insecure agent-to-tool integration protocols like MCP, and the risk of losing sensitive or nonpublic personal information.
• Incorporate AI-specific security requirements into procurement, third-party risk management, change control, and the software development lifecycle.
• Perform security evaluations of proposed AI use cases and provide approval, conditional, or rejection recommendations.
• Collaborate with Legal, Compliance, Technology Risk, Enterprise Risk, and model risk teams to meet regulatory, fair lending, and consumer protection responsibilities.
• Work alongside the Security Operations Center and Emerging Technology teams to develop AI-related detection, investigation, and response capabilities.
• Establish and communicate indicators of AI risk posture and control effectiveness to the CISO, technology leadership, risk committee, and board members.
• Draft and uphold AI-related information security policies, standards, and guidelines.
• Assist in producing evidence for internal audits, external audits, and regulatory examinations.
• Monitor the evolving AI threat landscape, regulatory expectations, and control frameworks.
• Provide advice and critical assessment of AI initiatives to ensure a balance between innovation, technical feasibility, compliance, and risk appetite.
• A minimum of 8 years of experience in information security, risk management, security operations, or information technology.
• At least 3 years dedicated to AI or machine learning security, data security, security engineering, or emerging technology risk.
• Bachelor’s Degree in Computer Science, Information Security, Data Science, or a related field.
• Experience in building or scaling a security program from its early stages.
• Proven experience securing AI systems in production, including large language model applications, retrieval pipelines, agentic workflows, and third-party AI services.
• Working knowledge of U.S. laws and regulations related to financial services technology and cybersecurity, such as the Gramm-Leach-Bliley Act Safeguards Rule, New York Department of Financial Services cybersecurity requirements, and state privacy and breach notification laws.
• Familiarity with NIST AI Risk Management Framework, NIST Cybersecurity Framework 2.0, ISO/IEC 42001, Google Secure AI Framework (SAIF), and OWASP Top 10 for Large Language Model Applications.
• Hands-on experience with AI security monitoring, red teaming, and adversarial testing of models and AI-enabled applications.
• Proficient in standard security technologies and investigative methods for security or compliance incidents.
• Capability to produce documentation that is audit-ready and examination-ready.
• Strong analytical and project management abilities.
• Excellent written and verbal communication skills.
• Background in lending, mortgage, or financial services is preferred.
• Familiarity with consumer protection and considerations for vulnerable customers is a plus.
• Health insurance.
• Dental insurance.
• Vision insurance.
• Life insurance.
• Paid time-off benefits.
• Flexible spending account.
• 401(k) with employer match.
• Employee Stock Purchase Plan (ESPP).
Mercor
Mercor
Mercor
Mercor
Get handpicked remote jobs straight to your inbox weekly.