> Markdown version of [/jobs/ext/3127360-principal-ai-governance-security-engineer](https://www.wearedevelopers.com/jobs/ext/3127360-principal-ai-governance-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal AI Governance & Security Engineer - **Company:** Toyota Motor North America - **Location:** United States - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Audit Trail, Cyber Security, Continuous Integration, Data Governance, Identity and Access Management, Key Management, Security Information and Event Management, Software Engineering, Management of Software Versions, Policy as Code, Large Language Models, Model Validation, AI Platforms, Deployment Automation, Machine Learning Operations, Devsecops - **Published:** September 28, 2026 - **Apply:** https://www.dice.com/job-detail/d2ce6fed-b776-41c4-bbe0-46a8cb21a252 ## About the Role Toyota Financial Services' AI & ML Platforms team is looking for a passionate and highly motivated Principal AI Governance & Security Engineer. This is a hands-on, principal-level role that sits at the intersection of AI governance, AI security, and forward deployed engineering. You will help build the enterprise control plane that lets Toyota deploy AI and agentic systems safely, compliantly, and at scale - turning governance and security requirements into working, production-grade controls rather than documents., * 12+ years of software engineering experience and demonstrated experience with AI/ML/Data Governance and associated information-security of AI/ML * Designing and implementing enterprise AI or data governance frameworks and operational governance processes in production * Translating security, risk, privacy, and compliance requirements into executable controls, measurable tests, and working software * Deep understanding of AI/model risk and responsible-AI principles, with working knowledge of SR 11-7, NIST AI RMF, the EU AI Act, and ISO/IEC 42001 * Practical AI security depth - threat modeling, guardrails, identity and access management, secrets, and least-privilege design * Governing and securing GenAI, RAG, and agentic systems - model/agent registries, MCP or comparable tool-mediation patterns, and evaluation frameworks * Strong software, data-engineering, or automation skills, with production experience on a major cloud (AWS preferred) and modern CI/CD * Strong communication - able to explain technical AI risk and control gaps to both engineers and senior executives Added bonus if you have * Direct experience governing or securing enterprise AI/GenAI programs in financial services or another regulated industry * Hands-on experience with AWS AI services (Bedrock, AgentCore, Bedrock Guardrails), policy-as-code (e.g., Cedar), and LLM/agent evaluation and guardrail frameworks (LLM-as-judge, trajectory evaluation, NeMo Guardrails, Llama Guard) * Relevant certifications - CISSP, CCSP, CRISC, CISA, a Certified AI Security/Governance credential, or a model-risk certification ## Description Reporting to the Director of AI & ML Platforms and partnering closely with the AI Governance team, Cybersecurity, Model Risk, Legal, Privacy, and the business, you will own the technical foundation for how AI use cases and agents move from idea to production. A typical week spans three kinds of work: shaping the governance framework and lifecycle controls (roughly half your time), hardening the security posture of our AI and agentic platforms (about a quarter), and embedding directly with use-case teams to design, build, and ship the controls they need to launch (about a quarter). The ideal candidate combines deep governance and information-security judgment with a strong software engineering background, and is equally comfortable authoring a control standard, threat-modeling an agent, and writing the code that enforces both. What you'll be doing In this role you'll help shape the foundation for Toyota Financial Services' next generation of governed AI and agentic capabilities, where success means AI systems that are demonstrably safe, auditable, compliant, and useful in production. You'll balance governance rigor against engineering velocity so teams can innovate within guardrails instead of around them. AI Governance (?50%) * Design, author, and maintain the enterprise AI governance framework - standards, policies, and procedures across the full lifecycle of AI use cases and models, from intake through production monitoring and retirement * Operationalize lifecycle gates: intake, risk classification, control design, approval workflows, monitoring, and remediation * Define risk tiers and controls proportional to use-case risk, extending model risk management to AI/ML and GenAI in line with SR 11-7, NIST AI RMF, the EU AI Act, and ISO/IEC 42001 * Own the Agent Registry and AI inventory as the authoritative source of truth - registration, versioning, and prevention of shadow-AI deployments * Translate governance policy into repeatable, testable engineering controls, partnering with the AI Governance team to move controls from observation to staged enforcement AI Security (?25%) * Perform AI-specific threat modeling and risk assessments - prompt injection, data poisoning, adversarial attacks, model theft, and data exfiltration - and design mitigations across the data, model, application, and infrastructure layers * Design guardrail, isolation, and least-privilege controls for agents - sandboxed execution, non-human identity, secrets management, and mediated tool access through the MCP registry * Build AI-specific incident response playbooks, drive red-team exercises, and embed security into the AI/ML lifecycle (DevSecOps for AI) with audit logging into enterprise SIEM Forward Deployed Engineering (?25%) * Embed with use-case, product, and platform teams to design and ship the executable controls they need to launch AI and agentic solutions within governed boundaries * Build reusable, production-grade capabilities hands-on: guardrail services, evaluation pipelines, agent/MCP registrations, and human-in-the-loop approval flows - using AWS, Bedrock/AgentCore, Cedar policies, and Lambda/Step Functions * Lead design reviews, set engineering standards, and mentor engineers across the governance and security control stack ## Related Videos - [GenAI Security: Navigating the Unseen Iceberg](https://www.wearedevelopers.com/videos/1744-genai-security-navigating-the-unseen-iceberg) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [This App Reached 10,000 Users in One Week. Here's How.](https://www.wearedevelopers.com/videos/100329-this-app-reached-10-000-users-in-one-week-here-s-how) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [From AI Assistance to Agentic Systems: Scaling Sovereign AI in Banking](https://www.wearedevelopers.com/videos/100070-from-ai-assistance-to-agentic-systems-scaling-sovereign-ai-in-banking) ## Related Articles - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [MLOps And AI Driven Development](https://www.wearedevelopers.com/magazine/82-mlops-and-ai-driven-development) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production)