Director, Artificial Intelligence Security & Safeguards
Finance of AmericaAbout Us
Finance of America helps homeowners 55+ access the equity they’ve built while staying in full control of their home and their financial future. Through a range of reverse mortgage solutions, we help customers shape the retirement they’ve earned while continuing to evolve how we serve and work together.
Joining Finance of America now means stepping into a period of momentum and growth, with teams actively shaping what comes next and opportunities to make an impact and grow your career.
To learn more about us, visit www.financeofamerica.com
Purpose of Role
Responsible for Finance of America’s program for securing the artificial intelligence the company builds, buys, and embeds in customer-facing and back-office processes. Establishes the controls, governance, and monitoring that allow the company to adopt AI at speed without creating unacceptable risk to borrower data, model integrity, or regulatory standing. Performs the technical work of the program, including AI red teaming, model and application security testing, and guardrail and control validation.
Key Responsibilities and Expectations
- Owns the strategy, roadmap, and execution of the company’s AI Security and Safeguards program, including control design, tooling selection, and measurement of program maturity.
- Performs the technical work of the program personally, including AI red teaming and adversarial testing, security testing of models and AI-enabled applications, guardrail and control validation, detection engineering, and configuration and tuning of AI security tooling.
- Serves as the enterprise subject matter expert on AI security, and is expected to hire, develop, and lead a small team as program demand and approved headcount allow.
- Maintains a current inventory of AI systems in use across the enterprise, including first-party applications, embedded vendor capabilities, and employee-adopted tools, and owns the discovery process that keeps it complete in collaboration with the Technology Risk Management team.
- Designs and operates safeguards against AI-specific threats, including prompt injection, model and data poisoning, unauthorized model access, over-privileged agentic tooling, insecure agent-to-tool integration protocols such as the Model Context Protocol (MCP), and loss of sensitive or nonpublic personal information through AI channels.
- Integrates AI-specific security requirements into enterprise governance processes, including procurement, third-party risk management, change control, and the software development lifecycle.
- Personally conducts security reviews of proposed AI use cases, evaluating data handling, model behavior, system integration, and output reliability, and issues clear approve, conditional, or decline recommendations with documented rationale.
- Partners with Legal, Compliance, Technology Risk, Enterprise Risk, and model risk functions to ensure AI use meets regulatory, fair lending, and consumer protection obligations, with particular attention to the company’s predominantly senior customer population.
- Partners with the Security Operations Center and Emerging Technology teams to build detection, investigation, and response capability for AI-related events, including AI-specific response playbooks and escalation criteria.
- Establishes and reports measurable indicators of AI risk posture and control effectiveness to the Chief Information Security Officer, technology leadership, and risk committee and board audiences, as requested.
- Authors and maintains information security policies, standards, and guidelines related to AI, and supports evidence production for internal audit, external audit, and regulatory examination.
- Tracks the evolving AI threat landscape, regulatory expectations, and control frameworks, and translates them into actionable requirements for the enterprise.
- Acts as a strategic advisor and credible critical reviewer for AI initiatives, ensuring that business innovation is balanced with technical feasibility, compliance, and stated risk appetite.
- Performs other duties as assigned.
Reports To
- Chief Information Security Officer
Direct Reports
- None initially; expected to build and lead a small team as the program matures.
Qualifications - Experience/Skills/Competencies
- Minimum of 8 years of experience in information security, risk management, security operations, or information technology, including at least 3 years focused on AI or machine learning security, data security, security engineering, or emerging technology risk.
- Demonstrated experience building or scaling a security program from an early stage, with a track record of progressing from hands-on delivery to team leadership.
- Experience securing AI systems in production, including large language model applications, retrieval pipelines, agentic workflows, and third-party AI services.
- Working knowledge of U.S. laws and regulations relevant to financial services technology and cybersecurity, including the Gramm-Leach-Bliley Act Safeguards Rule, New York Department of Financial Services cybersecurity requirements, and state privacy and breach notification regimes.
- Familiarity with AI governance frameworks and standards, such as the NIST AI Risk Management Framework, NIST Cybersecurity Framework 2.0, ISO/IEC 42001, Google Secure AI Framework (SAIF), and the OWASP Top 10 for Large Language Model Applications.
- Skilled in conducting risk assessments of AI systems, including model lifecycle security, data provenance, and third-party AI service evaluations.
- Demonstrated hands-on experience with AI security monitoring, red teaming, and adversarial testing of models and AI-enabled applications, evidenced by work the candidate performed directly rather than oversaw.
- Proficiency with standard security technologies and investigative methods for security or compliance incidents.
- Disciplined curiosity and analytical skepticism in evaluating emerging AI technologies and vendor claims.
- Ability to produce audit-ready and examination-ready documentation of controls, decisions, exceptions, and residual risk.
- Strong analytical and project management skills with the ability to lead complex, cross-functional initiatives.
- Self-driven and capable of managing priorities independently while maintaining clear communication and alignment.
- Excellent written and verbal communication skills; able to convey complex topics to diverse audiences, including executives, auditors, and examiners.
- Comfortable working in evolving environments, bringing structure and clarity to new or ambiguous domains.
- Builds effective partnerships through transparency, collaboration, and trust.
- Maintains current technical depth and is willing to remain a practicing engineer and tester.
- Background in lending, mortgage, or financial services preferred; familiarity with consumer protection and vulnerable-customer considerations is a plus.
Qualifications - Education - Required
- Bachelor's Degree
Qualifications - Education - Field(s)/Profession(s)
- Computer Science, Information Security, Data Science, or related field.
Compensation
The base salary range for this position is ($150,000 - $205,000) inclusive of all geographical differences in the labor market. The base salary for the position will be determined based on factors such as the candidate’s work location, skills, education, and experience. In addition to those factors, we believe in the importance of pay equity and consider the internal equity of our current team members in determining any final offer. We offer a competitive benefits package including health, dental, vision, life insurance, paid time-off benefits, flexible spending account, 401(k) with employer match, and ESPP.
Additional Information
The application deadline for the job opportunity is 11/9/2026.
The above statements are intended to describe the general nature and level of work being performed by people assigned to this classification. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified.
Finance of America is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, sex (including pregnancy), sexual orientation, religion, creed, age, national origin, physical or mental disability, gender identity and/or expression, marital status, veteran status or other characteristics protected by law.