Back to Jobs
Tribe AI
AI & Machine Learning 3h ago

Security and AI Governance Lead

Tribe AI
United StatesUnited States
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

DevOps1h 38mFree Trial ✨
Start 10-Day Free Trial
Machine Learning41mFree Trial ✨
Start 10-Day Free Trial
AI EngineerCybersecurityData Science & Analytics

Want to know if you're a match for this job?

Calculate My Match Score

About the Role

Enterprise AI runs on trust. Tribe’s teams work inside client environments, with client code, data, infrastructure, and systems. Before we can build, enterprise security teams need precise answers: What can our engineers access? Which tools process their data? What is logged or prevented? How are AI systems governed? Who is accountable when something goes wrong?

We have a strong foundation, including SOC 2 Type II, enterprise security assessments, a public Trust Center, and experience delivering in regulated environments. As the volume and sophistication of our work grows, we need a dedicated leader to make that posture systematic, measurable, and consistently defensible.

As Security and AI Governance Lead, you’ll report to the CTO and own Tribe’s corporate security, compliance program, AI governance, and client-facing security work. This is not a policy-only or back-office role. You’ll build controls, lead difficult customer reviews, handle incidents, interrogate architectures and data flows, and help our teams ship securely without smothering them in process.

When the facts are distributed across Engineering, IT, Legal, and Delivery, you own the answer. You’ll identify the right evidence owners, validate the underlying facts, resolve inconsistencies, and package the result into a clear, credible response. You’ll be highly hands-on today and build the systems, and specialist partnerships Tribe needs as we scale.

Key Responsibilities

Customer Trust & Compliance

  • Lead enterprise security reviews, questionnaires, diligence, and escalations—giving precise answers about current controls, planned improvements, and how identified gaps are being managed.
  • Own Tribe’s SOC 2 program and future certifications, along with the Trust Center, evidence library, and reusable customer security package.
  • Partner with GTM, Legal, and Delivery to remove legitimate security blockers while managing vendor risk, subprocessors, data retention, and sustainable customer commitments.

Security Program & Operations

  • Own Tribe’s security roadmap, risk register, policies, exceptions, metrics, and executive reporting.
  • Establish and continuously improve controls across identity, SSO and MFA, access lifecycle, MDM, EDR, encryption, DLP, patching, BYOD, vulnerability management, logging, and SIEM.
  • Own incident readiness and response, including severity decisions, cross-functional coordination, client communication, tabletop exercises, postmortems, and durable remediation.

AI & Secure Delivery

  • Define governance for coding agents, AI assistants, model providers, and subprocessors—including approved accounts, data flows, retention, telemetry, and human oversight.
  • Partner with Forward Deployed Architects and infrastructure leads on architecture reviews, threat modeling, secure SDLC, authentication, client segmentation, observability, and production readiness.
  • Turn recurring customer requirements and delivery lessons into reusable controls and patterns while determining what Tribe should build, automate, outsource, or support with dedicated hires.

About You

  • You have 8+ years in security and have built or substantially improved an enterprise security and GRC program spanning identity, endpoints, data protection, monitoring, vendor risk, and incident response.
  • You have personally led demanding security reviews, questionnaires, diligence sessions, and escalations with large enterprise customers.
  • You have pragmatic technical depth: you can interrogate an architecture, trace a data flow, challenge an implementation, and determine what evidence would prove a control.
  • You have owned a SOC 2 or ISO 27001 cycle from control design and scope through audit and remediation.
  • You are credible and precise under pressure, distinguishing confirmed facts from assumptions, current controls from roadmap items, and meaningful risk from security theater.
  • You bring high agency and sound judgment, moving comfortably between strategy and execution while protecting the business without becoming a bottleneck.

Nice to Have

  • Experience securing AI or ML systems, including model providers, agentic workflows, telemetry, evaluations, and emerging AI-specific risks.
  • Experience in an AI-native services, consulting, or forward-deployed engineering environment.

Why Join Us

  • Impact: Ship AI systems that don’t just demo well but run at scale in Fortune 500 enterprises.
  • Growth: Stay hands-on with cutting-edge frameworks while developing field-tested instincts.
  • Variety: Solve problems across industries, from finance to healthcare to defense.
  • Culture: Work in a team that prizes resilience, creativity, and winning over process.
  • Trajectory: Build both your technical and consulting muscles in one of the most demanding roles in AI delivery.

How would you rate this job post?

See what other professionals think about this role.

banner

Tribe AI is an enterprise artificial intelligence deployment and forward-deployed engineering firm engineered to build, scale, and compound production-grade machine learning systems for Fortune 500 enterprises and hyper-growth organizations. Operating at the intersection of elite talent networks, custom generative AI infrastructure, and hands-on technical execution, the company eliminates the pervasive "POC graveyard" phenomenon—where over 80% of enterprise AI prototypes fail to reach production due to legacy data silos, security bottlenecks, and lack of internal engineering bandwidth—by embedding top-tier machine learning engineers, data scientists, and researchers directly inside client engineering teams. Moving beyond traditional strategic consultancies and off-the-shelf wrappers, Tribe AI equips enterprises with end-to-end model fine-tuning, retrieval-augmented generation (RAG) pipelines, proprietary data activation, and custom LLM orchestrations with elite, scalable, and audit-ready precision. Under the hood, its operational engine—bolstered by deep partnerships with frontier AI labs, forward-deployed engineering squads, AWS cloud-native ML services (SageMaker, Rekognition), and automated compliance frameworks—natively handles complex data ingestion, high-concurrency model inference, enterprise agentic workflows, and secure, on-premise or VPC deployments. What sets Tribe AI apart is its outcome-driven deployment model; by combining world-class technical talent with proprietary engineering tooling, the firm delivers production AI solutions up to 3x faster than industry norms, enabling business leaders to convert raw data into compound competitive advantages.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More
Security and AI Governance Lead at Tribe AI | HireSkys