About this role
The Principal Governance Analyst - Application Security leads governance, policy, and control oversight for cloud, container, orchestration, and AI/ML security across the Bank. This advanced role provides authoritative guidance on security controls, documentation quality, regulatory alignment, and structured governance processes. It ensures defensible, consistent, and scalable practices for modern technology platforms.
Day-to-day involves leading the governance framework by aligning risks, controls, and processes with regulatory expectations and audit requirements. Produce clear, complete documentation for audit-ready materials. Drive development, simplification, and consolidation of policies and standards across cloud, containerization, virtualization, orchestration, and AI/ML platforms.
Partner closely with engineering, architecture, risk, compliance, and audit stakeholders. Act as authoritative reviewer for third-party governance responses and execute structured review cycles with engineering leaders. Represent Information Security in Bank-wide working groups, surfacing platform-level risks early.
Improve governance workflows for scale, consistency, growth, and resiliency while supporting engineer-friendly execution. No supervisory responsibilities, focusing on influencing decision makers and facilitating structured working sessions. Advance secure-by-design principles in a regulated banking environment.
Requirements
- Strong understanding of cloud security (e.g., AWS), container security, and container orchestration (Kubernetes preferred)
- Working knowledge of AI/ML security risks, model lifecycle considerations, and emerging regulatory expectations
- Experience translating technical designs, risks, and controls into documentation suitable for auditors, regulators, and senior leadership
- Experience writing or maintaining policies, standards, or control documentation in a regulated environment
- Ability to challenge respectfully, influence decision makers, and take a clear position when ambiguity exists
- Demonstrated ability to partner effectively with senior engineers and architects without needing to be the deepest SME
- Strong understanding of audit processes and what mature controls and evidence look like
- Excellent communication skills, with the ability to simplify complex technical topics for diverse audiences
Responsibilities
- Lead the governance framework for cloud, container, orchestration, and AI security ensuring alignment with regulatory expectations, audit requirements, and internal control frameworks
- Drive the development, simplification, and consolidation of policies and standards across cloud, containerization, virtualization, orchestration, and AI/ML platforms
- Act as the authoritative reviewer for third-party governance responses, assessing non-conforming items and partnering with SMEs
- Execute structured governance review cycles with engineering leaders for security tooling, guardrails, and platform standards
- Represent Information Security in Bank-wide and cross-functional working groups providing strong views on secure-by-design principles
- Improve governance workflows for scale and consistency supporting growth, resiliency, and engineer-friendly execution
Similar roles

DevSecOps Engineer
1w1 week agoWade Trim
Detroit, US · Full-time · $130,000 – $170,000

Cybersecurity Architect III
1w1 week agoJPMorgan Chase & Co.
Hyderābād, IN · Full-time · INR 4,000,000 – INR 8,000,000

Application Security Lead
1w1 week agoHightouch
Remote · Full-time · $220,000 – $300,000

OT Cybersecurity Engineer
1w1 week agoVantage Data Centers
GB · Full-time · £70,000 – £100,000
