SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
AlphaSense is seeking a Data Engineer to build the data layer that governs AI risk across the enterprise. This is an analytics engineering role focused on creating defensible, auditable data foundations for AI governance, compliance, and board-level reporting.
You will own the governance data model, transformation pipelines, data quality, lineage, and metrics that answer critical questions from the CISO, AI Governance Council, external auditors, and the board. Your work will support ISO 42001 certification, EU AI Act readiness, and cyber risk quantification for investment prioritization.
Key responsibilities include:
- Design and maintain the analytical data model for AI governance (systems, agents, owners, risk classifications, assessments, findings, control results, incidents, vendors, usage)
- Build transformation pipelines with tests, version control, and CI/CD
- Implement automated data quality checks, freshness monitoring, and end-to-end lineage tracing
- Own reconciliation between the AI System Registry and Product Security's bill-of-materials records, including identity resolution, ownership attribution, and conflict resolution
- Design metrics and KPIs for registry coverage, risk distribution, assessment throughput, control effectiveness, and remediation velocity
- Build analytics on control monitoring results (coverage, failure rates, drift detection, time-to-remediation)
- Create executive, council, and board reporting with visual and narrative clarity
- Structure risk and incident data for financial risk quantification
- Support audit and compliance evidence for ISO 42001, EU AI Act, and internal assessments
- Partner with Enterprise Data and Analytics on platform, semantic definitions, and BI standards
You will work alongside an AI Security Analyst and AI Security Automation Engineer, reporting to the Director. The Automation Engineer owns external system integrations and raw data delivery; you own everything downstream: modeling, transformation, quality, lineage, metrics, and reporting.
Requirements:
- 4+ years in analytics engineering, data engineering, or BI engineering, with experience supporting security, risk, compliance, or audit functions
- Strong SQL (window functions, complex joins, query performance reasoning)
- Working Python (pandas or equivalent) for transformation, reconciliation, and analysis
- Data modeling and pipeline design (ETL/ELT, dimensional modeling, incremental processing, warehousing)
- Hands-on BI and visualization (Tableau, Power BI, Looker, or similar)
- Cloud data platform experience (Snowflake, BigQuery, Redshift, Databricks, or similar)
- Version control and CI/CD for analytics (Git, dbt, GitHub Actions, or equivalent)
- Comfort with imperfect, incomplete, multi-source data and judgment about when to reconcile, flag, or refuse to report
- Strong written and visual communication
Required depth (both required):
- Demonstrated experience building metrics consumed by demanding audiences (external auditors, regulators, executives, boards) and defending those numbers under scrutiny
- Demonstrated experience reconciling entities across conflicting systems of record with incomplete or contradictory data, including identity resolution, ownership attribution, and handling disagreements between authoritative sources
Strongly preferred:
- Experience building metrics or dashboards for security operations, GRC, vendor risk, or audit programs
- API-based data ingestion from security and identity tooling (SIEM, CASB, IAM, EDR, cloud audit logs)
- Data quality and observability tooling, lineage or catalog implementation
- Exposure to AI governance frameworks (ISO 42001, NIST AI RMF, EU AI Act) or security frameworks (NIST CSF, SOC 2) through audit evidence work
- Familiarity with cyber risk quantification methodologies (FAIR) or board-level risk reporting
- Exposure to AI asset inventory, AIBOM concepts, agent registries, or non-human identity data
- Experience supporting IPO readiness, SOX, or investor due diligence
Critical requirement: This role aggregates sensitive security findings, incidents, and risk exposure across the enterprise. Discretion, careful handling of sensitive data, and understanding that data access is a reporting obligation are non-negotiable.