Lead AI GRC- Cybersecurity- CFU
Responsibilities
Lead Software Engineer - GenAI for Cybersecurity Red Team.
AI security risk advisory, cybersecurity governance, and responsible AI oversight for enterprise adoption.
Employment Type: - Full-Time
Experience: - 8+ years in cybersecurity, risk, governance, security advisory, or Information officer-related roles & AI
Primary Focus: - Business security advisory, AI use-case risk assessment, responsible AI governance, stakeholder management.
Lead AI GRC Cybersecurity – AI acts as the primary cybersecurity partner for business stakeholders adopting Artificial Intelligence.
The role ensures that AI use cases, AI agents are assessed, challenged, and governed in line with internal security standards, regulatory expectations, risk appetite, and responsible AI principles.
This is a senior governance and advisory role, distinct from hands-on AI engineering. The successful candidate will bridge business, technology, cybersecurity, compliance, risk, and leadership teams to support secure and business-aligned AI adoption.
Key ResponsibilitiesSecurity Advisory & Risk Management
· Identify, assess, and challenge cybersecurity risks associated with AI use cases, AI agents, and AI-enabled services.
· Provide risk-based security guidance throughout the project lifecycle from ideation to production deployment.
· Support security risk assessments, remediation planning, and acceptance decisions.
AI Governance & Responsible AI
· Review AI initiatives for alignment with internal security standards, governance frameworks, and responsible AI principles.
· Assess risks related to data protection, model security, privacy, third-party AI providers, AI agents, and business process impact.
· Ensure AI-related initiatives comply with applicable regulatory obligations, enterprise security policies, and risk management expectations.
· Provide independent challenge where AI use cases create elevated security, privacy, operational, or misuse risks.
Oversight, Reporting & Challenge
· Monitor AI-related security risks, remediation actions, control gaps, and residual risk positions.
· Report security posture, key risks, and mitigation progress to leadership and relevant governance bodies.
· Support audits, regulatory reviews, risk committees, and internal assessments where required.
· Track adherence to security requirements and challenge exceptions or deviations from expected controls.
Profile required
Skill Area
Market-standard Expectations
Information Security
Strong understanding of information security principles, control frameworks, cyber risk management, security architecture, and enterprise security governance.
Risk & Governance
Experience conducting security reviews, risk assessments, control validation, remediation tracking, and risk reporting.
AI Risk
Good understanding of AI, GenAI, AI agents, model security, data protection, privacy, third-party risk, prompt injection, misuse, and responsible AI considerations.
Business Advisory
Ability to translate cybersecurity concerns into business-relevant risk language and pragmatic mitigation options.
Stakeholder Management
Strong influencing, communication, and senior stakeholder engagement skills across business, technology, risk, compliance, and cybersecurity teams.
Regulatory Awareness
Understanding of security, privacy, compliance, and governance expectations applicable to AI.
Operating Model
Ability to operate effectively in complex, matrixed, and fast-evolving environments while balancing security, and operational constraints.
Preferred Qualifications· Previous experience as a Information Officer, Information Security Officer, Cyber Risk Manager, Security Governance Lead, or Security Architect.
· Knowledge of offensive security concepts, attacker behavior, threat actor methodologies, and adversarial AI risks.
· Experience supporting AI governance, responsible AI, cloud security, data protection or risk programs.
· Certifications such as CISSP, CISM, CRISC, ISO 27001, AZ-500, or equivalent practical experience.
· Experience in regulated enterprise environments, including banking, financial services, technology, or critical infrastructure.
Ideal Candidate Profile· Senior cybersecurity advisor who can challenge AI initiatives constructively without blocking innovation unnecessarily.
· Comfortable working with ambiguity, emerging risk areas, and fast-moving AI delivery teams.
· Able to communicate clearly with executives while maintaining sufficient technical understanding to assess real security risk.
· Strong collaborator who can balance business priorities, security controls, governance expectations, and operational realities.
Why join us
We are committed to creating a diverse environment and are proud to be an equal opportunity employer. All qualified applicants receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.
Business insight
At Société Générale, we are convinced that people are drivers of change, and that the world of tomorrow will be shaped by all their initiatives, from the smallest to the most ambitious. Whether you’re joining us for a period of months, years or your entire career, together we can have a positive impact on the future. Creating, daring, innovating, and taking action are part of our DNA. If you too want to be directly involved, grow in a stimulating and caring environment, feel useful on a daily basis and develop or strengthen your expertise, you will feel right at home with us!
Still hesitating?
You should know that our employees can dedicate several days per year to solidarity actions during their working hours, including sponsoring people struggling with their orientation or professional integration, participating in the financial education of young apprentices, and sharing their skills with charities. There are many ways to get involved.
We are committed to support accelerating our Group’s ESG strategy by implementing ESG principles in all our activities and policies. They are translated in our business activity (ESG assessment, reporting, project management or IT activities), our work environment and in our responsible practices for environment protection.