Back to Jobs

AI Security Operations Specialist

Not Disclosed

Job Description & Details

This is a specialized security operations role sitting right at the intersection of enterprise AI adoption and governance. If you are tired of just writing policies that nobody reads and want to actively shape how a large organization safely deploys AI, this 12-month contract-to-hire position gives you that operational leverage.

What You'll Actually Be Doing

You will spend your days bridging the gap between hardcore security engineering and everyday business users. Your primary focus will involve coordinating AI security programs, tracking down shadow IT, and managing remediation work when unapproved AI tools or MCP servers pop up. You will act as the translator who can take dense security findings from engineering teams and clearly explain to non-technical stakeholders why a specific tool was blocked and how to stay compliant.

The Core Tech Stack

You need a solid foundation in GRC and cybersecurity, with a specific lens on enterprise AI governance. Understanding MCP servers, security operations workflows, and basic AI security terminology is non-negotiable here. Experience with tools like CrowdStrike will give you a massive head start, but your ability to audit, differentiate between approved and unapproved tech, and drive remediation to completion is what will actually make you successful in this environment.

Interview Expectations

Expect the hiring manager to test your communication skills by asking you to explain a complex AI security vulnerability or a blocked unapproved tool to a non-technical department head. They want to see if you can balance security rigor without sounding like a blocker to business velocity. They will also drill down into your project coordination experience, looking for concrete examples of how you managed ongoing remediation workflows rather than just producing static documentation.

Application Advice

Make sure your resume heavily features keywords like GRC, cyber security, AI governance, security operations, and remediation. Don't just list tools; highlight instances where you successfully communicated security risks to both technical teams and business users. Emphasize your operational follow-through and organizational skills to prove you can handle the hybrid schedule and drive security programs forward.