Job Description
Overview
Looking for a professional with experience in Information Security, GRC, risk management, compliance, AI governance, and related areas.
Key Success Factors• Creates organized, consistent, and audit-ready documentation without requiring heavy rework.• Keeps AI intake requests moving by identifying gaps, tracking follow-ups, and communicating status clearly.• Builds trusted working relationships with technical and non-technical stakeholders.• Learns quickly, asks thoughtful questions, and applies governance guidance consistently.• Balances curiosity about AI with a practical focus on security, privacy, compliance, and business risk.
Responsibilities
Responsibilities
- Lead the AI intake process by managing, reviewing, and approving submitted requests for completeness, documenting business use cases, identifying missing information, and helping route requests to the appropriate stakeholders.
- Conduct comprehensive AI-related risk assessments for enterprise tools, third-party platforms, embedded AI features, and internally proposed AI use cases.
- Oversee and manage AI governance records, including intake trackers, risk registers, control mappings, exception logs, decision records, and supporting evidence.
- Drive the development, maintenance, and strategic evolution of of AI governance policies, standards, procedures, and user guidance aligned to frameworks such as NIST AI RMF, NIST CSF, ISO 27001, and other applicable requirements.
- Lead coordination across IT, Legal, Privacy, Procurement, Compliance, Information Security, and business teams to collect information needed for AI risk reviews and approval decisions.
- Independently evaluate and assess third-party AI-enabled products from a security, privacy, data handling, compliance, and vendor risk perspective.
- Lead control gap analysis, remediation tracking, and documentation of compensating controls for AI-related risks and exceptions.
- Lead readiness response activities by collecting evidence, drafting control responses, and maintaining audit-ready documentation.
- Monitor developing AI governance expectations, regulatory themes, and internal control needs, and summarize potential implications for Information Security leadership and stakeholders.
- Lead AI security awareness and responsible use communications by helping draft training content, FAQs, knowledge articles, and internal guidance materials.
- Drive broader GRC activities and strategic initiatives, including policy lifecycle support, security questionnaires, third-party risk reviews, compliance reporting, and Information Security Management System support.
AI Intake and Governance Support
- Lead new AI intake submissions and help confirm scope, data classification, user population, integration method, vendor ownership, and intended business outcome.
- Document intake decisions, review status, required follow-up actions, and evidence in a consistent and traceable manner.
- Manage and maintain an AI tool and use case inventory, including ownership, approval status, risk notes, and control considerations.
- Direct intake workflow reporting by preparing status summaries, aging views, action item lists, and stakeholder follow-ups.
Audit, Customer Response, and Documentation
- Lead the preparation and organization of evidence for internal and external audits, customer security questionnaires, and compliance reviews.
- Author clear, consistent, strategic, and audit-ready responses that explain Information Security and AI governance controls in business language.
- Maintain version-controlled documentation for policies, standards, procedures, risk decisions, meeting notes, and control evidence.
Ensure documentation is complete, current, traceable, and aligned to approved processes.
Qualifications
Qualifications Required Minimum
- Bachelor’s degree in Cybersecurity, Information Systems, Information Technology, Computer Science, Business, Risk Management, or a related field, or equivalent practical experience.
- 5+ years of experience in Information Security, GRC, IT audit, risk management, compliance, privacy, technology operations, or a related internship, co-op
- Advanced understanding and demonstrated expertise of information security concepts, common control frameworks, and risk management practices.
- Proven track record in AI governance, responsible AI, data protection, third-party risk, and emerging technology risk management.
- Demonstrated ability to write compelling technical, organize details, maintain trackers, and translate technical or compliance information into understandable business language.
- Expert-level collaboration and stakeholder management skills, and comfort working with cross-functional stakeholders.
- Exceptional attention to detail and strategic thinking with strong follow-through, and ability to manage multiple work items in a structured way.
- Working knowledge of Microsoft 365 productivity tools such as Word, Excel, PowerPoint, Teams, SharePoint, and Outlook.
Preferred
- Exposure to frameworks or standards such as NIST CSF, NIST AI RMF, ISO 27001, ISO 42001, SOC 2, CMMC, or related governance frameworks.
- Experience with GRC tools, ticketing systems, workflow trackers, Vanta, SharePoint lists, Microsoft Forms, Smartsheet, Jira, ServiceNow, or similar platforms.
- Familiarity with third-party risk management, security questionnaires, vendor assessments, or data classification concepts.
- Advanced understanding and demonstrated expertise of cloud services, identity and access management, SaaS applications, APIs, and enterprise integrations.
- One or more relevant certifications such as CGRC, CISM, CISA, CRISC, or equivalent senior-level certification; or AI governance related training.
- Experience drafting knowledge articles, process documentation, training material, or executive-ready status summaries.
Company Description
Waters Corporation (NYSE:WAT) is a global leader in life sciences and diagnostics, dedicated to accelerating the benefits of pioneering science through analytical technologies, informatics, and service. With a focus on regulated, high-volume testing environments, our innovative portfolio harnesses deep scientific expertise across chemistry, physics, and biology. We collaborate with customers around the world to advance the release of effective, high-quality medicines, ensure the safety of food and water, and drive better patient outcomes by detecting diseases earlier, managing routine infections, and combating antibiotic resistance. Through a shared culture of relentless innovation, our passionate team of ~16,000 colleagues turn scientific challenges into breakthroughs that improve lives worldwide.
Diversity and inclusion are fundamental to our core values at Waters Corporation. It benefits our employees, our products, our customers and our community. Waters complies with all applicable federal, state, and local laws. Qualified applicants are considered without regard to sex, race, color, ancestry, national origin, citizenship status, religion, age, marital status (including civil unions), military service, veteran status, pregnancy (including childbirth and related medical conditions), genetic information, sexual orientation, gender identity, legally recognized disability, domestic violence victim status, or any other characteristic protected by law. Waters is proud to be an equal opportunity workplace and is an affirmative action employer. All hiring decisions are based solely on qualifications, merit, and business needs at the time.