via Icims
$85K - 130K a year
Lead AI security practice by setting standards, conducting architecture reviews, and ensuring secure AI adoption across Microsoft environment while partnering with data, legal, and risk teams to govern AI workloads and maintain compliance with Zero Trust.
Bachelor's degree and 5-8+ years in enterprise security architecture or operations with proficiency in Microsoft security technologies and AI-specific security risks and governance frameworks.
Location: Any location in the United States Work Arrangement: Remote A Day in the Life The AI Security Manager is responsible for leading the firm's AI security practice, setting security standards for AI-enabled systems, autonomous agents, and multi-platform AI workloads across the Microsoft environment. This role serves as the day-to-day security authority for AI adoption: conducting enterprise architecture reviews of how AI products align to the firm's Microsoft platform, partnering with the data team on data governance for AI workloads, and supporting the legal and risk teams to ensure the firm's AI-related contractual and policy language is accurate and defensible. The AI Security Manager may manage a team of security engineers or serve as a hands-on technical thought leader for the practice; in either case, this person owns an area of the practice and is responsible for its health. The role balances leadership and execution to deliver secure, governed, responsible AI adoption aligned with Zero Trust principles, the firm's “TRUST” framework, NIST AI RMF, and OST priorities. A typical day as a AI Security Manager might include the following: Leads the firm's AI security practice, translating AI security strategy into standards, controls, and delivery outcomes across initiatives. Serves as a technical authority on the Microsoft 365 E7 security stack as the firm's primary AI security control plane, including Entra ID, Defender, Purview, Sentinel, Agent 365, and Intune, and extends these controls to govern third-party AI platforms (Anthropic, OpenAI, Google) through federation, compliance API integration, and conditional access enforcement. Conducts enterprise architecture reviews of AI products, agents, IDE extensions, and M365 add-ins, assessing how each aligns to the firm's Microsoft environment, identity model, data boundaries, and reference architecture before approval. Applies the EA Decision Scoring Matrix and security risk assessment criteria to approve or deny AI tool and platform requests, and supports Application Portfolio Management intake for AI and agentic applications. Partners with the data team on data governance for AI workloads, including data classification, sensitivity labeling, retention, Purview DLP policy, semantic and grounding data boundaries, and access control for AI-consumed data sources. Supports the legal and risk teams by reviewing and informing AI-related legal, contractual, and policy language, including vendor terms, data retention and training commitments, client-facing AI disclosures, and acceptable use policy, ensuring statements about the firm's AI controls are technically accurate. Defines and enforces security policies for autonomous agents, ensuring every digital worker operates within governed, auditable boundaries. Performs AI threat modeling and risk assessment across identity, endpoint, network, data, application, and AI-specific vectors, including prompt injection, data poisoning, model exfiltration, and agent drift. Monitors and governs MCP server connections, OAuth consent flows, and cross-platform agent communications, ensuring external integrations are allow-listed and observable through Defender for Cloud Apps and Agent 365. Integrates third-party AI compliance APIs into the firm's centralized SIEM, supporting unified detection, alerting, and incident correlation across all AI platforms. Supports design and governance of isolated development environments for installed AI coding tools, including identity isolation, network segmentation, conditional access, endpoint registration, and user-level activity monitoring. Partners with the EB Security Team, enterprise architecture, and digital delivery teams to embed AI security into every layer of the firm's composable architecture. Translates security requirements into actionable work items within agile delivery teams using Scrum practices, including backlog grooming, sprint planning, and retrospectives. Participates in the AI / Security Governance Council and presents AI security recommendations to technology leadership, translating technical risk into business language. Provides leadership, coaching, and mentorship to security and engineering associates, building team capability and succession. Monitors the evolving AI threat landscape, evaluates emerging security technologies, and drives continuous improvement in AI security practices, tooling, and delivery processes. Resolves complex technical and delivery issues while managing trade-offs and competing priorities, promoting a culture of collaboration, accountability, and high performance. Who You Are You have a bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field required. You have 5 - 8+ years of progressive experience in enterprise security architecture, engineering, or operations. You have 3+ years of hands-on experience with Microsoft security technologies (Entra ID, Defender, Purview, Sentinel, DLP). You have demonstrated experience securing AI, machine learning, or automation workloads in an enterprise environment. You have experience conducting architecture or security reviews of third-party products for fit within a Microsoft-centered enterprise environment. You have experience partnering with data governance, legal, or risk functions on policy, contractual, or compliance matters. You have a familiarity with multi-vendor AI platform security models, including Anthropic Claude Enterprise, OpenAI ChatGPT Enterprise, and Google Gemini Enterprise, specifically their compliance APIs, data retention policies, and SSO/SCIM integration capabilities. You have proven experience mentoring, coaching, and developing technical talent, or serving as a technical thought leader in a domain. You have experience delivering enterprise-level technology solutions in Agile or iterative environments preferred. Preferred certifications: CISSP, CISM, Microsoft SC-100/SC-200/SC-300, or equivalent. Preferred experience in professional services, financial services, or regulated industries preferred. You have deep knowledge of Microsoft 365 E7 security architecture, including Entra ID, Defender, Purview, Sentinel, Agent 365, DLP, and Intune. You have expertise in Zero Trust security principles and their application across identity, network, data, and workload boundaries. You have an understanding of AI-specific security risks, including prompt injection, data poisoning, model exfiltration, and agent drift. You have working knowledge of enterprise architecture review practices and the ability to assess how a product aligns to the firm's Microsoft platform, identity model, and reference architecture. You have knowledge of data governance practices for AI workloads, data classification, sensitivity labeling, retention, DLP, and access control for AI-consumed data sources. You are able to interpret AI vendor terms and translate technical control realities into accurate legal, contractual, and policy language in partnership with legal and risk. You have knowledge of third-party AI platform security architectures, including data retention policies, compliance API schemas, and workspace isolation models across Anthropic, OpenAI, and Google. You have knowledge of AI vendor licensing models (Enterprise vs. Team vs. API tiers) and their impact on security control availability, including SSO, SCIM, ZDR, audit logging, RBAC granularity, and spend governance. You have an understanding of installed AI IDE and agentic tool security risks, including host-level filesystem access, credential exposure, code exfiltration, and autonomous processes running on managed workstations. You have working knowledge of Scrum and agile delivery practices, including backlog management, sprint execution, and cross-functional collaboration. You have knowledge of regulatory and compliance frameworks relevant to professional services, including NIST AI RMF, SOC, and data privacy regulations. You have strong stakeholder management and communication skills, with the ability to present complex security concepts to executive and non-technical audiences. You have analytical skills to evaluate threat intelligence, assess risk, and recommend proportionate controls. You have sound judgment and problem-solving, with a commitment to quality, governance, security, responsible AI, and alignment with enterprise architecture and OST priorities. Must be authorized to work in the United States now or in the future without visa sponsorship. Making an Impact Together People join Eide Bailly for the opportunities and stay because of the culture. At Eide Bailly, we've built a collaborative workplace based on integrity, authenticity, and support for one another. You'll find opportunities for education and career growth, a team dedicated to your success, and benefits that put your family's needs first. Hear what our employees have to say about working at Eide Bailly. Compensation $150,000-$185,000. Our compensation philosophy emphasizes competitive and equitable pay. Eide Bailly complies with all local/state regulations regarding displaying ranges. Final compensation decisions are dependent upon factors such as geography, experience, education, skills, and internal equity. Benefits Beyond base compensation, Eide Bailly provides benefits such as: generous paid time off, comprehensive medical, dental, and vision insurance, 401(k) profit sharing, life and disability insurance, lifestyle spending account, certification incentives, education assistance, and a referral program. Next Steps We'll be in touch! If you look like the right fit for our position, one of our recruiters will be reaching out to schedule a phone interview with you to learn more about your career interests and goals. In the meantime, we encourage you to learn more about us on Facebook, Instagram, LinkedIn or our About Us page. Eide Bailly is proud to be an affirmative action/equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, veteran status, or any other status protected under local, state or federal laws. #LI-KH1 #LI-Remote
This job posting was last updated on 9/23/2026