Toronto, ON, CA
Position Title: Lead, AI Security Governance & Operations
Come Build Your Career at Aecon!
Aecon delivers some of the most complex and impactful infrastructure projects — from transformative transportation networks to critical energy, industrial and nuclear programs. The projects we build connect communities and power future generations. With deep roots in North America and a strong footprint internationally, Aecon brings global expertise and proudly serves public and private sector clients through its Construction and Concessions segment.
Safety Always is not only our #1 core value – it is the standard that anchors our culture. We believe the most ambitious projects deserve the most committed people. At Aecon, you won’t just build your career — you’ll help build what matters to enable future generations to thrive.
At Aecon, you can count on:
- Safety Always. Our number one core value. The safety of our people, projects, partners, and stakeholders is our priority focus – today and always.
- Integrity. We lead by example, with humility and courage.
- Accountability. We’re passionate about delivering on our commitments.
- Inclusion. We provide opportunities where people feel valued, supported, and empowered to contribute fully.
We deliver infrastructure with purpose, and our people are at the heart of everything we do. Aecon employees are incredibly proud to build some of the most impactful infrastructure of this generation – we call it Aecon Proud.
At Aecon we:
- Ensure you and your family receive the services and benefits needed to support your mental, emotional, and physical well-being.
- Are intentional when it comes to investing in your development. We help you build your career and advance your skills through our Aecon University, tuition reimbursement, and Leadership Programs.
- Are committed to creating work environments focused on mutual respect, teamwork, collaboration, and new ideas, through meaningful initiatives, training, partnerships with Veteran groups, our Aecon Women in Trades and diversity programs, as well as our Employee Resource Groups (ERGs), to ensure we are building with top talent and harnessing our collective strengths within every aspect of our culture.
- Operate responsibly by managing risk, safety, and environmental considerations across all our projects and surrounding communities.
Our success is built on the passion, expertise, and dedication of our people. Together, we embrace strong execution, innovation, and continuous improvement — values that come to life through the unique talents and collaborative spirit of every team member. If you’re inspired to make a difference through future-building projects, join our best-in-class team.
What is the Opportunity?
The AI Security Governance & Operations Lead will drive the secure design, governance, and day-to-day protection of artificial intelligence (AI) and machine learning (ML) capabilities across the organization. This role blends Security Operations (SecOps) and Governance, Risk & Compliance (GRC) to ensure AI solutions - including generative AI, predictive analytics, and automation - are secure, compliant, monitored, and continuously improved. The ideal candidate bridges security architecture, operational security tooling, and practical delivery in asset-intensive environments (e.g., construction, engineering, and project delivery).
What You'll Do Here:
AI Security Architecture & Guardrails
- Design and own end-to-end security patterns for AI/ML platforms across data ingestion, model development, training, deployment, and monitoring.
- Define and enforce secure-by-design controls for AI (identity and access, segmentation, encryption, secrets management, secure APIs, and inference protection).
- Establish controls for generative AI including prompt protection, data leakage prevention, misuse prevention, and output risk management.
Hands-on Security Tooling & Configuration (AI-Specific)
- Implement and tune security controls in enterprise security tools that govern AI usage (e.g., data loss prevention, sensitivity labeling, access policies, conditional access, and tenant/app configuration).
- Configure and validate logging, telemetry, and audit coverage for AI services, AI endpoints, and AI-enabled applications; ensure logs are usable for detection and investigations.
- Create, test, and refine detection rules and alerting for AI-specific threats (e.g., prompt injection attempts, anomalous access, data exfiltration patterns, and unsafe plugin/connector usage).
- Assess AI-specific tools and features as they are introduced (e.g., security posture capabilities, AI governance features) and configure security components as required to meet standards.
- Partner with platform teams to harden AI environments (RBAC, network restrictions, private endpoints where applicable, key management, and secure CI/CD for model/application deployments).
- Perform hands-on validation (tabletop + technical) of control effectiveness—spot checks, configuration reviews, and evidence capture for audits.
Risk, Governance & Compliance (GRC)
- Identify and manage AI-specific security risks such as data poisoning, model inversion, prompt injection, IP leakage, and unauthorized model retraining.
- Develop AI security standards, reference architectures, and guardrails aligned with enterprise frameworks (e.g., NIST, ISO 27001, Zero Trust) and ensure they are operationalized.
- Support privacy, data protection, and regulatory/contractual obligations by defining AI control requirements, mapping controls to policies, and maintaining evidence.
- Lead third-party AI risk activities with Legal, Privacy, and Risk teams (intake requirements, security assessments, and ongoing monitoring expectations).
Security Operations (SecOps) for AI
- Act as the escalation point for AI-related security events—triage, coordinate investigation, and support containment and remediation in collaboration with SecOps.
- Operationalize incident response playbooks for AI services and AI-enabled applications, including communications, evidence handling, and post-incident reviews.
- Track and report AI security posture metrics (e.g., policy coverage, high-risk exceptions, recurring alert types) and drive remediation plans with owners.
Construction & Engineering Context (Preferred)
- Apply AI security controls to construction and engineering use cases such as BIM/digital twins, predictive scheduling/cost modeling, safety analytics, computer vision for site monitoring, and AI-enabled asset lifecycle tools.
- Understand and mitigate risks related to project data, design IP, site telemetry, and operational technology (OT) interfaces.
Collaboration & Enablement
- Work closely with Architecture, AI, and Enterprise Technology to balance security, innovation, and delivery speed.
- Provide security input for AI vendor selection, architecture reviews, and proofs of concept, including required controls and go-live criteria.
- Enable responsible adoption through practical guidance, patterns, and runbooks that teams can implement (not just policy statements).
- Advise leaders on AI risk posture and trade-offs in clear, business-relevant terms.
What You Bring to the Team:
- 8+ years of experience in security architecture, cloud security, security engineering, or security operations.
- Experience securing AI/ML, data analytics, or automation platforms in production environments.
- Working knowledge of identity and access management, encryption/key management, logging/monitoring, and security incident response.
- Hands-on experience configuring and operating security controls in enterprise security tools (policy configuration, monitoring, detection, and evidence capture).
- Ability to translate technical risk into clear recommendations and actionable remediation plans.
Preferred Qualifications
- Experience in construction, engineering, infrastructure, industrial, or other asset-intensive sectors.
- Familiarity with BIM, digital twins, project management systems, or OT/ICS environments.
- Experience with AI governance frameworks, responsible AI, model risk management, and third-party risk assessment.
- Certifications such as CISSP, CCSP, SABSA, cloud security certifications, and/or AI-related coursework/certifications.
Reason for vacancy: New
The expected salary range for this role is $120,000 - $125,000 per year
Individual pay is determined based on several factors, including work location, education, experience, unique skills and job conditions. Other considerations may includecertifications, specialized training, and the complexity or scope of the role.
Aecon fosters belonging within and across our organization. We are committed to providing equal employment opportunities and considering all applicants without regard to race, color, religion, sex, national origin, age, disability, or any other characteristic protected by applicable local laws.