Zoom is a company focused on building the best collaboration platform for enterprises. They are seeking an AI Governance Security Engineer to own risk assessment across various AI governance domains and define controls that enable safe AI adoption at scale.
Responsibilities:
- Conducting risk evaluations of AI use cases across GenAI, agentic AI, shadow AI, and AI gateway/MCP domains, scoring exposure using Likelihood and Impact methodology and maintaining the AI governance risk register
- Identifying security gaps in GenAI deployments including prompt injection, data leakage, model misuse, and output handling, and recommending targeted controls
- Assessing agentic AI systems for risks around autonomy, tool access, privilege escalation, and unintended action, and defining monitoring requirements
- Detecting and evaluating shadow AI and local/unsanctioned AI usage, quantifying risk and recommending detection and enforcement approaches
- Evaluating AI security tooling including AI gateways, CASB/SWG, Model Context Protocol governance solutions, and agentic monitoring platforms for functional requirements and integration
- Contributing to security frameworks, architectural standards, and policies that translate the AI Governance Risk Charter into concrete technical requirements and control implementations
- Applying security engineering judgment across network, endpoint, cloud, and data security domains to support architecture reviews, risk assessments, and incident response
- Partnering with AI/ML, engineering, and enterprise teams through collaborative working groups to identify security solutions and tracking execution
Requirements:
- 5+ years of experience in security engineering, cybersecurity, or a closely related field
- Demonstrated understanding of cybersecurity frameworks, compliance requirements, and emerging threat landscapes
- Hands-on experience with risk assessment and risk management methodologies, including impact-based prioritization
- Working knowledge of modern AI/ML systems and the security risks they introduce (LLMs, generative AI, agentic systems)
- Working knowledge of core security domains beyond AI (e.g., network, endpoint, cloud, or data security) sufficient to contribute to architecture reviews and risk assessments
- Experience securing GenAI, agentic AI, or LLM-based applications in enterprise environments would be a bonus
- Familiarity with AI gateways, Model Context Protocol (MCP), CASB/SWG, or DLP tooling
- Experience detecting and governing shadow IT / shadow AI usage would be advantageous
- Threat modeling experience applied to AI or novel technology environments
- Experience contributing to incident response, detection engineering, or purple team exercises would be a bonus