
Mission
Support the client’s AI Security Governance Program by defining, operationalizing and continuously improving the cybersecurity control framework for AI, GenAI and agentic AI use cases. The role will work with security, architecture and business teams to ensure AI initiatives are registered, assessed, governed and secured across their lifecycle.
The profile will act as the cybersecurity subject matter expert for AI governance, complementing the project manager and helping translate AI-related risks into practical controls, processes, requirements, evidences and decision criteria.
Key Responsibilities
Define and mature the security governance model for AI systems, including intake, registration, risk classification, control mapping, approvals, exceptions, monitoring and periodic reassessment.
Align the governance model with recognized frameworks such as NIST AI RMF, NIST Generative AI Profile, ISO/IEC 42001, OWASP Top 10 for LLM Applications, and local relevant ruling as EU AI Act obligations where applicable. NIST’s GenAI Profile was released to help organizations manage unique generative AI risks; ISO/IEC 42001 provides a structured AI management system standard; OWASP tracks LLM-specific risks such as prompt injection, insecure output handling, data poisoning and supply-chain vulnerabilities.
Assess AI and GenAI use cases from a cybersecurity perspective, covering:
Access control and identity context
Agentic AI permissions and tool execution
Logging, monitoring and incident response
Model exposure and misuse risk
Prompt injection and indirect prompt injection
Sensitive data leakage
Data classification and data residency
Model supply chain and third-party AI services
Human oversight and approval workflows
Security-by-design requirements for AI applications
Translate risks into practical security controls, including policies, technical requirements, architecture patterns, guardrails, evidence requirements, control owners and acceptance criteria.
The role should be able to define what “good” looks like for different AI patterns: internal copilots, M365 Copilot, custom GenAI apps, RAG systems, AI agents, vendor AI features, ML models and low-code/no-code AI automations.
Work with existing tools such as HiddenLayer, Sentra, Zenity and the AI registration/control tower process to ensure the governance model is not theoretical.
Expected activities include:
Mapping tool capabilities to governance controls
Defining required data fields in the AI registry
Establishing dashboards and control evidence
Identifying gaps between tooling coverage and policy expectations
Supporting integration with GRC, CMDB, DLP, IAM, SIEM/SOC, cloud security and data governance processes
Typical deliverables should include:
AI control framework
AI use case classification model
Security requirements for AI/GenAI projects
AI security architecture patterns
AI registry/control tower data model recommendations
Tooling-to-control mapping
Exception and risk acceptance process
KPI/KRI dashboard proposal
Security review templates
AI security awareness material for project teams
Roadmap for maturity improvement
Requirements
Must have:
8+ years in cybersecurity, with strong experience in security governance, security architecture, risk management or AppSec/CloudSec.
Real understanding of AI/GenAI security risks, especially LLM application risks, prompt injection, data leakage, model supply chain, AI agent permissions, RAG security, model/API exposure and third-party AI usage.
Ability to build governance that works operationally, not just policy documents. This is important: Nestlé likely does not need someone to explain that AI is risky; they need someone who can help make the program executable.
Experience with enterprise control frameworks
Excellent documentation and communication skills, with the ability to produce executive-ready material and technical control definitions.
Strongly desirable:
Experience with one or more of:
AI governance programs
AISPM Experience
GenAI application security reviews
M365 Copilot / enterprise copilots
AI agent governance
ML/LLM model risk management
Data Security Posture Management
Cloud security architecture
Secure SDLC / DevSecOps
Third-party AI vendor risk
GRC tooling and control evidence automation
SOC monitoring for AI-related threats
Experience with tools such as HiddenLayer, Sentra, Zenity, Wiz, Microsoft Purview, Defender, CSPM/CWPP, DLP, SIEM/SOAR, cloud-native security tooling or GRC platforms would be valuable.
Certifications / knowledge:
Useful but not mandatory:
CISSP, CISM, CRISC or equivalent
Cloud security certifications: AWS, Azure, GCP, CCSP
AI governance / AI risk training
Privacy knowledge: GDPR, DPIA, data classification
Familiarity with EU AI Act requirements for deployers of high-risk AI systems, including governance, monitoring, human oversight and logging obligations where applicable.
Benefits
Salary determined by the market and your experience
Flexible schedule 35 Hours / Week
Fully remote work (optional)
Flexible compensation (restaurant, transport, and childcare) ✌
Fully free health insurance, with a co-payment for dental services
Individual budget for training or equipment and free Microsoft certifications
English lessons
Birthday day off
Monthly bonus for electricity and Internet expenses at home
Discount on gym plan and sports activities
Plain Camp (annual team-building event)
Extra perks: events attendance and speakers, welcome pack, baby basket, Christmas basket, discount portal for employees ➕ The pleasure of always working with the latest technological tools!
Will you let us know you better?
The selection process: Simple, just 3 steps.
Phone screen
2 interviews with the team
What is Plain Concepts?
Plain Concepts is a global company of over 500 people passionate about technology and innovation. Since our founding, we have grown through technical proficiency and confidence in ideas that others might consider risky, creating custom solutions for our clients. With offices in more than 6 countries, our mission is to continue to drive cuttingedge projects around the world.
We are highly committed to technical excellence. We are known for developing highly customized projects, offering specialized technical consultancy and training.
Thanks to the great work of our technicians, we have been recognized for our ability to lead innovative projects that generate value, from artificial intelligence to blockchain, driving solutions that help companies optimize their performance.
What we do at Plain Concepts?
We pride ourselves on being a 100% technical team, dedicated to crafting custom projects from scratch, offering expert technical consultancy, and providing top-tier training.
Our approach goes beyond traditional outsourcing; we focus on creating value together with our clients.
Our teams are diverse and multidisciplinary, operating in a flat, collaborative structure.
We live and breathe AGILE principles, ensuring flexibility and efficiency in everything we do.
Knowledge-sharing is at our core: from supporting each other internally to contributing to the broader tech community through conferences, events, and talks.
Innovation drives us — even the boldest ideas are welcome here.
Transparency underpins all our relationships, fostering trust and long-term partnerships.
Want to learn more?
Check out our website! ➡ https://www.plainconcepts.com/
At Plain Concepts, we certainly seek to provide equal opportunities. We want diverse applicants regardless of race, colour, gender, religion, national origin, citizenship, disability, age, sexual orientation, or any other characteristic protected by law.