
Associate Director of Cybersecurity, Physical Security, and AI Governance
ECG Management Consultants · Atlanta, GA
- Hybrid
- Full-time
- $175,000 / year
- Atlanta, GA
Job highlights
- Lead enterprise cybersecurity and AI governance strategy.
- Define policies, standards, and risk assessments.
- Collaborate with cross-functional leadership teams.
- Advise executives on investment and reporting.
- Ensure incident preparedness and oversight.
About the role
Associate Director of Cybersecurity, Physical Security, and Artificial Intelligence (AI) Governance
ECG Management Consultants is seeking an Associate Director of Cybersecurity, Physical Security, and Artificial Intelligence (AI) Governance to join our team. With over 50 years of experience, ECG is a leading healthcare consulting firm dedicated to improving patient outcomes through innovative solutions. This role is strategic and governance-focused, responsible for shaping our long-term approach to security and responsible AI use.
About ECG
ECG is a national consulting firm redefining healthcare. We offer a wide range of services to providers, payers, and investors, focusing on practical, tailored solutions. We foster a collaborative, inclusive, and supportive work environment.
Your Opportunity with ECG
Reporting to the IT director, the Associate Director will define and advance the organization’s approach to cybersecurity, physical security, data governance, and responsible AI use. This strategic role involves establishing vision, policy, and risk evaluation, partnering with various departments to support execution.
Your Responsibilities May Include
Enterprise Security, Data, and AI Governance Strategy
- Define and maintain a multiyear enterprise strategy for cybersecurity, physical security, data analytics governance, and AI/automation risk.
- Ensure security, data, and AI considerations are integrated into IT architecture, cloud platforms, analytics initiatives, and application delivery.
- Advise IT leadership on risks, opportunities, and investments related to emerging technologies.
- Translate technical, physical, and AI risks into business impacts for executive decision-making.
AI and Data Governance
- Establish and maintain the organization’s AI governance framework, including acceptable AI use, data privacy, security, and ethical guardrails.
- Partner with data and analytics teams to define standards for data classification, protection, and platform security.
- Act as the escalation point for AI-related risks, misuse, or policy exceptions.
- Balance security needs with business objectives to ensure safe practices without hindering business goals.
Governance, Policy, and Risk Management
- Own enterprise governance for cybersecurity, physical security, data protection, and AI use within ECG.
- Develop and maintain policies, standards, and control objectives.
- Lead enterprise risk assessments across cyber, physical, data, and AI domains.
- Align governance practices with recognized frameworks such as NIST, ISO, and applicable privacy or AI standards.
Cross‑Functional Leadership and Collaboration
- Provide strategic oversight into cybersecurity, physical security, and data governance functions.
- Partner closely with IT infrastructure, applications, architecture, data and analytics, HR, legal, and compliance teams.
- Act as the security, data, and AI-governance authority in IT leadership forums.
- Promote a culture of responsible innovation that balances progress with trust and control.
Investment, Metrics, and Executive Reporting
- Advise IT leadership on security, analytics, and AI investment priorities.
- Define and track KPIs and KRIs for security posture, data governance maturity, and AI risk.
- Deliver executive-ready reports on trends, risks, and program effectiveness.
Incident Preparedness and Oversight
- Define enterprise-level strategies for cyber incidents, physical security events, data breaches, and AI misuse scenarios.
- Ensure leadership readiness for high-impact incidents.
- Lead post-incident strategic reviews focused on systemic improvement and governance maturity.
Collaboration with Legal and Compliance
- Partner with compliance teams to ensure AI and data governance align with regulatory, contractual, privacy, and ethical obligations.
- Co-develop policies addressing AI use, intellectual property, confidentiality, and third-party risk.
- Support coordinated responses to AI-related incidents, audits, or regulatory inquiries.
Qualifications
Required Qualifications
- Bachelor’s degree in information security, computer science, data management, or a related field (or equivalent experience).
- Typically, 7+ years of experience in cybersecurity, risk management, enterprise IT, data governance, or related leadership roles.
- Demonstrated experience leading enterprise-level security strategy and governance.
- Strong understanding of cybersecurity and physical security principles, data analytics platforms and data protection, and AI/generative AI risk, governance, and ethical considerations.
- Proven ability to communicate complex risk topics to executive audiences.
Preferred Qualifications
- Advanced degree (MBA, MS, or equivalent).
- Relevant certifications (CISSP, CISM, CRISC, CPP, CDGM, or AI-governance credentials).
- Experience supporting cloud-based, analytics-driven, and AI-enabled enterprise environments.
- Experience presenting to executive leadership or governance committees.
- Experience with Microsoft environments (Azure, Fabric).
- Experience with security products (Defender, Sentinel, Purview, Entra, Azure WAF, Brivo badging system).
Job Locations
Remote. Travel as needed (approximately 10%).
Schedule
Full time/exempt.
What You Can Expect Of Us
ECG offers an attractive compensation package, challenging work, and an entrepreneurial environment. Benefits include medical, dental, and vision coverage; a 401(k) matching program; unlimited PTO; and other wellness programs. The estimated base salary range is $150,000 – $175,000 annually, plus eligibility for annual incentive compensation.
Apply Now
Submit your resume via our career site at https://careers.ecgmc.com.
Key skills/competency
- Cybersecurity Strategy
- Physical Security Management
- AI Governance
- Data Governance
- Risk Management
- Policy Development
- Enterprise Security
- IT Leadership
- Executive Communication
- Compliance
Skills & topics
- Cybersecurity
- Physical Security
- AI Governance
- Data Governance
- Risk Management
- Information Security
- IT Leadership
- Healthcare Consulting
- Strategy
- Compliance
How to get hired
- Tailor your resume: Highlight your 7+ years in cybersecurity, risk, data governance, and AI leadership, emphasizing enterprise strategy and executive communication skills.
- Showcase relevant experience: Detail your experience with security frameworks (NIST, ISO), AI governance, and data protection, aligning with ECG's focus on healthcare consulting.
- Prepare for strategic questions: Be ready to discuss your approach to defining long-term security vision, evaluating risk, and translating technical concepts for executive audiences.
- Demonstrate collaborative spirit: Highlight your ability to partner with IT, legal, compliance, and business leaders to drive execution and foster a culture of responsible innovation.
- Research ECG's values: Understand ECG's commitment to healthcare, client success, and their culture of collaboration, integrity, and innovation.
Technical preparation
Behavioral questions
Frequently asked questions
- What is the primary focus of the Associate Director of Cybersecurity, Physical Security, and AI Governance role at ECG?
- The primary focus of this Associate Director role at ECG Management Consultants is on defining and advancing the organization's long-term strategy for cybersecurity, physical security, data governance, and responsible AI use. This is a heavily strategic and governance-focused position.
- What are the key qualifications for the Associate Director of Cybersecurity, Physical Security, and AI Governance position at ECG?
- Required qualifications include a Bachelor's degree in a related field (or equivalent experience), typically 7+ years of experience in cybersecurity, risk management, or data governance leadership, demonstrated experience in enterprise security strategy, and the ability to communicate complex risk topics to executives. A strong understanding of cybersecurity, physical security, data protection, and AI governance is essential.
- Does this Associate Director role at ECG involve hands-on technical work or is it more strategic?
- This role is described as heavily strategic and governance-focused. While a strong understanding of technical principles is required, your responsibilities will center on establishing vision, policy, and guardrails, evaluating risk, and providing executive-level insight, rather than direct hands-on implementation.
- What is the expected salary range for the Associate Director of Cybersecurity, Physical Security, and AI Governance at ECG?
- The estimated base salary range for this position at ECG Management Consultants is $150,000 to $175,000 annually. This role is also eligible for an annual incentive compensation program.
- Is the Associate Director of Cybersecurity, Physical Security, and AI Governance role at ECG remote?
- Yes, the Associate Director of Cybersecurity, Physical Security, and AI Governance role at ECG Management Consultants is a remote position. There may be travel required as needed, estimated at approximately 10%.
- What kind of experience is preferred for the Associate Director of Cybersecurity, Physical Security, and AI Governance at ECG?
- Preferred qualifications include an advanced degree, relevant certifications like CISSP or CISM, experience with cloud-based and AI-enabled environments, experience presenting to executives, and familiarity with Microsoft Azure environments and specific security products such as Defender, Sentinel, and Purview.