Principal - Cybersecurity Audit, Risk & Governance Architect – AI & Emerging Tech

Verizon Business Ntwk Srvs
  • Ashburn, Virginia
    5 days ago

    Job Description

    When you join Verizon

    You want more out of a career. A place to share your ideas freely — even if they’re daring or different. Where the true you can learn, grow, and thrive. At Verizon, we power and empower how people live, work and play by connecting them to what brings them joy. We do what we love — driving innovation, creativity, and impact in the world. Our V Team is a community of people who anticipate, lead, and believe that listening is where learning begins. In crisis and in celebration, we come together — lifting our communities and building trust in how we show up, everywhere & always. Want in? Join the #VTeamLife.

    What you’ll be doing...


    We are seeking an experienced Security Risk & Compliance Lead to shape the future of our products and services for our enterprise and public sector customers specifically for security risk, audit readiness, and AI governance. In this role, you will bridge the gap between traditional security compliance, enterprise risk management, and the safe deployment of AI native network technologies. You will work closely with VBG stakeholders to establish risk-informed controls that enable rapid innovation while protecting our customer data and system integrity.


    Key Responsibilities:


    • AI Governance & Risk Management: Design, implement, and maintain the enterprise AI Risk Management Framework aligned with NIST AI RMF, ISO 42001, and emerging global regulations (e.g., EU AI Act).
    • Audit & Compliance Management: Lead end-to-end execution of internal and external security audits (SOC 2 Type II, ISO 27001, etc.), managing evidence collection, remediation tracking, and auditor relationships.
    • Third-Party AI & Vendor Risk: Evaluate third-party SaaS vendors and AI model providers for security posture, data privacy usage, training data retention, and regulatory compliance.
    • Threat Modeling & Risk Assessments: Perform security risk assessments and threat models on new AI/ML initiatives, LLM integrations, and core platform capabilities.
    • Cross-Functional Advisory: Serve as the primary security risk advisor to Product, Engineering, and Business leaders, embedding "Security & Privacy by Design" into product roadmaps.
    • Metrics & Board Reporting: Establish metrics, KRIs, and reporting dashboards for the CISO and Executive Risk Committee regarding compliance status and emerging AI risks.

    What we’re looking for...


    You'll need to have:


    • Bachelor’s degree or four or more years of work experience.
    • Six or more years of relevant experience required, demonstrated through one or a combination of work and/or military experience, or specialized training.
    • Six or more years of progressive experience in Information Security Risk Management, IT Audit, or Governance, Risk, and Compliance (GRC). 
    • Demonstrated experience evaluating risks associated with AI/ML systems, Large Language Models (LLMs), data pipeline security, or AI vendor tools.
    • Proven track record leading SOC 2 Type II audits, ISO 27001 certifications, or regulatory compliance programs from preparation through remediation. 
    • Deep familiarity with NIST SP 800-53 / NIST SP 800-171 / NIST CSF, SOC 2 Type II, ISO 27001, PCI-DSS, and HIPAA, and AI-specific frameworks (NIST AI RMF, OWASP LLM Top 10).
    • Basic understanding of cloud infrastructure (AWS/GCP/Azure), API security, data pipeline architecture, or software development lifecycles (SDLC).

    Even better if you have one or more of the following:


    • Have one or more certification such as;  IAPP Artificial Intelligence Governance Professional (AIGP), CDPSE, CRISC (Certified in Risk and Information Systems Control), CISA (Certified Information Systems Auditor) and/or CISSP, CISM.
    • Experience implementing or operating modern GRC automation platforms (e.g., Vanta, Drata, LogicGate, ServiceNow). Demonstrated experience setting up Continuous Control Monitoring (CCM) or automated evidence-polling integrations.
    • Knowledge and experience in project managing multiple and simultaneous assessments and audits for continuous authorizations.
    • Exceptional written and verbal communication skills with a proven ability to translate complex technical/regulatory requirements into actionable business guidance.

    If Verizon and this role sound like a fit for you, we encourage you to apply even if you don’t meet every “even better” qualification listed above.

    Where you’ll be working

    In this hybrid role, you'll have a defined work location that includes working from home and a minimum of three days per week in the office, which will be set by your manager. Employees are responsible for maintaining compliance with hybrid work policies.

    Scheduled Weekly Hours

    40

    Equal Employment Opportunity 

    Verizon is an equal opportunity employer. We evaluate qualified applicants without regard to veteran status, disability or other legally protected characteristics.

    Benefits and Compensation

    Our benefits are designed to help you move forward in your career, and in areas of your life outside of Verizon. From health and wellness benefit options including: medical, dental, vision, short and long term disability, basic life insurance, supplemental life insurance, AD&D insurance, identity theft protection, pet insurance and group home & auto insurance. We also offer a matched 401(k) savings plan, up to 8 company paid holidays per year and up to 6 personal days per year, paid parental leave, adoption assistance and tuition assistance, plus other incentives, we’ve got you covered with our award-winning total rewards package. Depending on the role, employees have the opportunity to receive compensation in the form of premium pay such as overtime, shift differential, holiday pay, allowances, etc. Newly hired employees receive up to 15 days of vacation per year, which grows with additional service. For part-timers, your coverage will vary as you may be eligible for some of these benefits depending on your individual circumstances.

    The salary will vary depending on your location and confirmed job-related skills and experience. This is an incentive based position with the potential to earn more. For part-time roles, your compensation will be adjusted to reflect your hours.

    The annual salary range for the location(s) listed on this job requisition based on a full-time schedule is: $120,500.00 - $231,000.00.

    Numbers & Facts

    LocationAshburn, Virginia

    Skills

    • Amazon Web Services (AWS)unmatched
    • Artificial Intelligence (AI)unmatched
    • Auditingunmatched
    • Automationunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • Compensation and Benefitsunmatched
    • Cross-Functionalunmatched
    • Customer/Client Researchunmatched
    • Data Managementunmatched
    • Emerging Technologyunmatched
    • Enterprise Protectionunmatched
    • External Auditunmatched
    • GCP (Good Clinical Practices)unmatched
    • Governmentunmatched
    • HIPAA (Health Insurance Portability and Accountability Act)unmatched
    • ISO (International Organization for Standardization)unmatched
    • Information Technology & Information Systemsunmatched
    • Information Technology/Systems Auditunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internal Auditunmatched
    • Internet Securityunmatched
    • Maintain Complianceunmatched
    • Metricsunmatched
    • Microsoft Windows Azureunmatched
    • Modeling Languagesunmatched
    • PCI-DSSunmatched
    • Presentation/Verbal Skillsunmatched
    • Privacy Controlsunmatched
    • Product Designunmatched
    • Product Engineeringunmatched
    • Product Planningunmatched
    • Project/Program Managementunmatched
    • Regulationsunmatched
    • Regulatory Complianceunmatched
    • Regulatory Requirementsunmatched
    • Reporting Dashboardsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Risk Management Framework (RMF)unmatched
    • Security Analysisunmatched
    • Security Auditingunmatched
    • Security Complianceunmatched
    • ServiceNowunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Software as a Service (SaaS)unmatched
    • Threat Modelingunmatched
    • Threat and risk analysis (TRA)unmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder