Director, AI Security & Governance
About Digital Asset & The Canton Network
Digital Asset builds the technologies that are reshaping the foundations of financial markets. Our mission is to create the world’s most trusted, privacy-enabled, and interoperable digital infrastructure for global finance. At the heart of this mission is the Canton Network - the blockchain purpose-built for institutional finance. Uniquely combining privacy, compliance, and scalability, Canton enables real-time, secure settlement across multiple asset classes. Governed by the Canton Foundation with participation from leading financial institutions, it is the proven link between the promise of blockchain and the power of global finance.
Founded in 2014 and headquartered in New York City, with offices in London, Zurich, Budapest, Hong Kong, and Sydney— we are on a mission to transform finance— and that transformation is now playing out rapidly on the Canton Network. If you’re interested in playing a crucial role at the intersection of traditional and crypto-capital markets and want to help bring the next trillion dollars of finance on-chain, join us.
About The Role
Digital Asset is building the infrastructure that underpins institutional finance on distributed ledger technology. AI is becoming central to how we operate, how we build, and how we serve clients, and that adoption is accelerating. This role exists to make sure it happens well. The Director of AI Security & Governance will be the company’s first dedicated owner of AI risk responsible for how AI systems are designed, secured, governed, and accounted for across the organization. You will work at the intersection of technology, risk, and regulation, translating business intent into governed architecture and producing the reporting and documentation that holds up under regulatory and investor scrutiny. You will sit within the security organization, reporting to the CISO, and operate as a key interface to the Head of Enterprise Risk & Internal Audit, Finance, People, and business leadership. This is a build role. The function does not exist yet, and you will define it.
Responsibilities
- AI architecture and intake
- Serve as the first point of contact for business and product teams seeking to deploy AI - translate use cases into technical designs that meet security, privacy, and regulatory requirements
- Evaluate and recommend AI vendors, models, and platforms; own the framework for approving new AI system deployments
- Define and maintain the company’s AI architecture standards, including data classification requirements for AI inputs and outputs
- Security and controls
- Partner with Business Units to threat-model AI systems prior to production deployment
- Partner with IT Security team to manage the access control and API key governance framework for all AI services
- Lead AI-specific incident response, including triage, containment, and post-incident documentation
- Model risk and regulatory compliance
- Own the company’s risk management documentation for AI systems
- Maintain an inventory of AI models and tools in production, including purpose, data inputs, decision scope, and validation status
- Serve as the primary point of contact for regulatory inquiries related to AI; prepare examination-ready materials
- Cost management and reporting
- Instrument AI infrastructure for per-team and per-product cost attribution; own the chargeback and reporting framework in partnership with IT Security, Engineering and Finance
- Establish and maintain spend thresholds and approval processes for new AI API procurement
- Produce a monthly AI cost and risk report for the AI Advisory Council, covering spend, open risks, incidents, and model inventory status
- Workforce AI readiness
- Partner with People function to define AI competency expectations by function and level, ensuring role profiles reflect the skills required to work alongside AI systems responsibly
- Advise on AI literacy standards for new hire assessments and onboarding
- Serve as the subject matter expert when People updates job architectures or leveling frameworks to incorporate AI-related capabilities
Requirements
- 7+ years in information security, technology risk, or a related discipline, with direct experience in financial services or another regulated industry
- Demonstrable understanding of how large language models and AI systems work, including the security risks specific to AI
- Ability to translate technical AI risk into language that resonates with legal, compliance, finance, and executive audiences
- Experience with cloud AI platforms (AWS, Azure, or GCP) and API-based AI service integrations
- Strong written communication. This role produces documentation that will be reviewed by regulators, auditors, and investors
- Comfort operating without a fully defined playbook; this is a build role and requires independent judgment
Skills
- Helpful But Not Required
- Experience with blockchain infrastructure or distributed ledger technology
- Familiarity with DORA, FCA AI guidance, or other international AI regulatory frameworks
- Prior experience standing up a governance function from scratch
Pay
The range below may vary if based outside the New York tri-state area (New York, New Jersey, and Connecticut). Base salaries are determined during our interview process, during which we assess the candidate's experience, skills, and capabilities against internal peers and the scope and responsibilities of the position.
US Pay Transparency $270,000 - $290,000 USD
At Digital Asset, we are committed to compensation structures that reward impact consistently across our global teams.
Benefits
We offer a comprehensive benefits package designed to support the well-being of our team members. Health and insurance benefits vary by region to ensure local relevance and compliance, and may include medical, dental, and vision coverage.