Key Objectives:
- Drive Framework Adoption: Successfully guide and support the organization in adopting the AI Security Framework, ensuring they can effectively assess and manage AI-related risks.
- Integrate AI Security into Development: Oversee the update of the Secure Software Development LifeCycle (SSDLC) to formally include specific security testing activities for AI systems.
- Define the AI Guardrails Strategy: Lead the effort to test, select, and define a comprehensive strategy for deploying AI Guardrails, in close collaboration with Group Data & AI (GDAI), CyberDefense, and other key stakeholders.
- Shape the Future of Agentic AI Security: Provide expert security-by-design guidance for the development of strategic "Agentic Platform".
Key Responsibilities:
- Steer the project by animating weekly operational meetings and bi-monthly follow-ups.
- Prepare and present progress, risks, and results to the AI Security Steering Committee and contribute to the broader OneTrust program reporting.
- Act as the central point of contact, coordinating between entity representatives.
- Manage the "Triathlon Race" evaluation process for 41 entities, reviewing their AI risk assessments and use case evidence.
- Provide actionable feedback to each entity through dedicated one-page reports to help them achieve compliance and improve their security posture.
- Lead workshops to integrate AI security requirements into the SSDLC process, drawing on industry standards like the OWASP AI Testing Guide.
- Manage the AI Guardrails Proof of Concept (POC), from framing the tests and coordinating with vendors to consolidating results into a final strategy deck.
- Participate in strategic workshops to provide security recommendations for the Agentic Platform architecture and capabilities.
- Oversee the update of the AI Security Framework to incorporate recent threats and standards, preparing it for submission to the Policy Working Group.
Experience & Expertise:
- 10+ years of experience in cy