Share this job
Security and Compliance Lead
New York City, New York, United States
Apply for this job

AIVC is an AI consulting and investment firm built on four connected engines. We Transform enterprises through consulting, Build companies in our studio, Buy and own operating businesses, and Accelerate all of it through a shared platform and intelligence layer that compounds across every engagement. We operate in regulated environments: healthcare with HIPAA exposure, private markets where portfolio data is client property and boundaries are absolute. One of our five discipline standards is written for this seat: security is the floor. If it is not secure, it does not ship.

Today the firm's security, compliance, and governance surfaces ride informally on engineering leads. SOC 2, and HIPAA where required, gates the enterprise and portfolio deployments we are built to win, and no one owns getting us certified and keeping us there. That is this job.

Role Overview

You will author AIVC's security and compliance program end to end: the control framework, the evidence pipeline, the audit cadence, and the policies the whole firm operates under. You will harden our infrastructure and CI/CD, design the governance controls for AI systems that handle sensitive data, and build the Governance Console access-control layer as a reusable primitive that every platform deployment and consulting engagement inherits.

One boundary, clear from the first conversation. You author the program and its policies. A separate IT Manager, reporting through a different line, executes day-to-day identity, device, and access-review operations under the policies you write. You still need genuine hands-on depth there, because nobody can write enforceable policy for an estate they have never operated, and you remain its escalation path and auditor. You are not the help desk.

You lead by building. There is no security team to manage on day one: your leverage is the program you author, the controls you personally implement, and the reusable governance layer you leave behind. A fractional start converting to full-time is possible for the right operator.

  What You'll Own (Outcomes)

  • SOC 2 attained and maintained, HIPAA readiness where required. Twelve months in, AIVC holds the certification with a maintained control framework, evidence pipeline, and audit cadence.
  • Hardened infrastructure and CI/CD. Secure-by-default cloud infrastructure and pipelines: secrets management, least-privilege access, and audit logging across the stack.
  • The Governance Console access-control layer. The compliance, audit-trail, and access-control tooling that platform deployments and consulting engagements rely on, a reusable primitive rather than per-project bespoke work.
  • The policy layer for identity, device, and access operations. Joiner-mover-leaver policy, access-review cadence, device baseline, and SaaS security standards: written by you, executed by the IT Manager, provable to an auditor.
  • LLM governance controls. Enforceable policies and tooling for sensitive data in AI systems: PII handling in prompts and traces, retention and residency, model-access rules, and audit trails for agentic actions.

  What You'll Do (Responsibilities)

  •  Scope the SOC 2 control framework against our actual stack, run the gap assessment, and sequence remediation by what gates certification.
  • Design and implement controls at the data and infrastructure layer, with evidence generated as a side effect of enforcement, not as a quarterly screenshot scramble.
  • Run the external audit end to end: assessor selection, fieldwork, pushback, findings, and the continuous monitoring that follows.
  • Author the identity, device, access-review, and SaaS security policies the IT Manager operates, and audit that execution against them.
  • Threat-model our AI systems and ship the governance controls that make them deployable in regulated client environments.
  • Front external security reviews with client security, risk, and compliance teams when engagements require it.

  What We're Looking For (Required)

  •  DevOps and IT hybrid range. You have personally owned cloud infrastructure and CI/CD and an IT-admin estate (identity/SSO, device management, access provisioning, SaaS administration), and you can narrate both halves with build-level specifics rather than oversight language.
  • Compliance-program operations, end to end. You have run a SOC 2 or HIPAA program through control design, evidence collection, audit readiness, and continuous monitoring, and the program kept running after the certificate.
  • Security engineering fundamentals. Access controls enforced at the data and infrastructure layer rather than the UI, plus secrets management, network isolation, logging and audit trails, and incident response you personally designed and implemented.
  • LLM and AI governance literacy. You reason concretely about model and data access policies, PII in prompts and traces, guardrails, retention and residency, and audit trails for agentic actions, and you are honest about where your depth ends.
  • Sensitive-data stewardship. You are credible with regulated data, you have fronted external security reviews yourself, and you hold the boundary that client data stays with the client.
  • Reusable-primitive codification. You have turned repeated security or compliance work into control libraries, tooling, or platform layers that other people used without you.

  Helpful If You Have (Preferred)

  • Healthcare or private-markets experience, where BAA-grade and portfolio-data obligations are lived rather than studied.
  • Compliance-automation tooling experience: evidence collection as code, continuous controls monitoring.
  • Exposure to AI governance frameworks such as NIST AI RMF or EU AI Act readiness work.
  • Time as the first dedicated security hire at a firm without a large security apparatus.


Apply for this job
Powered by