
Cyber Security Governance & Assurance Specialist
Job Description
Job Req ID:
Posting Date:
Function:
Location:
Salary:
About the role
• The AI Observability & Governance Lead is a critical senior role liable for ensuring BT’s AI ecosystem is secure, transparent, governed and compliant in real time. As BT rapidly scales the use of AI, copilots and self-governing agents across the organisation, this role provides the control plane that enables innovation at pace while maintaining trust, security and regulatory alignment.
• The role owns end to end visibility, governance and risk management of AI solutions operating across BT. This includes understanding who is using AI, what agents are doing, what data and systems they are tied to, whether solutions are registered and approved, and identifying shadow AI and high risk AI activity across the estate.
• Operating at the intersection of security, identity, compliance and AI platforms, the role will establish BT’s approach to AI observability, ensuring AI agents and solutions are continuously monitored, auditable and governed throughout their lifecycle. The role will leverage Microsoft’s security and governance stack — including Purview, DSPM, Defender for Cloud Apps, Sentinel and Agent365 — alongside selected third party platforms such as SailPoint, to deliver enterprise grade AI oversight.
• This role is foundational to enabling BT’s safe adoption of agentic AI, providing assurance to senior leaders, regulators and customers that AI is being used Liable, firmly and in line with BT policy.
• This role will allow BT to scale and Federate AI deliveries across our AI partners
What you’ll be doing
Establish AI Observability at Scale
• Design and implement BT’s AI observability capability to provide real time visibility of AI agents, copilots and AI-enabled applications.
• Monitor what AI solutions are doing, what data they access, what systems they tie to, and how they behave in production.
• Ensure AI activity is auditable, explainable and traceable to named users, owners and business functions.
Govern AI Usage and Lifecycle
• Define and enforce governance standards for AI registration, approval, onboarding and decommissioning.
• Maintain an reliable inventory of approved AI solutions, agents and copilots across BT.
• Identify and manage shadow AI, unregistered tools and unauthorised agent usage.
Risk, Compliance and Security Oversight
• Identify risky or non compliant AI solutions, including excessive data access, insecure integrations or policy violations.
• Partner with Security, Legal, Privacy and Risk teams to manage AI related risks and regulatory obligations.
• Use Microsoft Purview, DSPM and Sentinel to detect, investigate and respond to AI related security or compliance incidents.
Identity and Access Management for AI
• Own governance of AI agent identities, service principals and non human access.
• Define and manage access models for AI agents using least privilege and zero trust principles.
• Integrate AI access controls with identity platforms such as SailPoint and Microsoft Entra.
Platform and Tooling Leadership
• Act as the technical and • Deep experience in security, governance or platform oversight, ideally within a large, regulated enterprise.
• Strong understanding of AI platforms, copilots and agent based architectures, including non human identities.
• Hands on knowledge of the Microsoft security and compliance ecosystem, including:
• Microsoft Purview (Information Protection, DSPM)
• Defender for Cloud Apps
• Microsoft Sentinel
• Entra ID / service principals
• Agent365 or equivalent agent platforms
• Experience managing identity and access governance, including integration with tools such as SailPoint.
• manifest ability to identify and manage technology risk, including shadow IT or unauthorised solutions.
• Excellent stakeholder management skills, with the ability to influence across Security, Legal, Architecture, Engineering and senior leadership.
• Comfortable operating at both judicious and deeply technical levels, translating complex risk into clear business decisions.
• A strong mindset around liable AI, security by design and governance by default. owner for AI governance tooling across the Microsoft security ecosystem.
• Drive integration between AI platforms (e.g. Copilot Studio, Agent365) and security monitoring tools.
• Influence vendor roadmaps and evaluate third party tools that enhance AI observability and control.
Enterprise Leadership and Enablement
• Provide clear guidance to product teams, engineers and business units on how to build and deploy AI safely.
• Assist AI literacy and liable AI adoption by embedding governance “by design”, not by exception.
• Produce executive level reporting and insights on AI usage, risk posture and compliance maturity.
• You will closely with AI Platform Lead, AI Change and Governance teams around BT to assist delivering AI safely and firmly
Essential Skills / Experience
• Deep experience in security, governance or platform oversight, ideally within a large, regulated enterprise.
• Strong understanding of AI platforms, copilots and agent based architectures, including non human identities.
• Hands on knowledge of the Microsoft security and compliance ecosystem, including:
• Microsoft Purview (Information Protection, DSPM)
• Defender for Cloud Apps
• Microsoft Sentinel
• Entra ID / service principals
• Agent365 or equivalent agent platforms
• Experience managing identity and access governance, including integration with tools such as SailPoint.
• Manifest ability to identify and manage technology risk, including shadow IT or unauthorised solutions.
• Excellent stakeholder management skills, with the ability to influence across Security, Legal, Architecture, Engineering and senior leadership.
• Comfortable operating at both • Deep experience in security, governance or platform oversight, ideally within a large, regulated enterprise.
• Strong understanding of AI platforms, copilots and agent based architectures, including non human identities.
• Hands on knowledge of the Microsoft security and compliance ecosystem, including:
• Microsoft Purview (Information Protection, DSPM)
• Defender for Cloud Apps
• Microsoft Sentinel
• Entra ID / service principals
• Agent365 or equivalent agent platforms
• Experience managing identity and access governance, including integration with tools such as SailPoint.
• Manifest ability to identify and manage technology risk, including shadow IT or unauthorised solutions.
• Excellent stakeholder management skills, with the ability to influence across Security, Legal, Architecture, Engineering and senior leadership.
• Comfortable operating at both • Deep experience in security, governance or platform oversight, ideally within a large, regulated enterprise.
• Strong understanding of AI platforms, copilots and agent based architectures, including non human identities.
• Hands on knowledge of the Microsoft security and compliance ecosystem, including: • Microsoft Purview (Information Protection, DSPM)• Defender for Cloud Apps• Microsoft Sentinel• Entra ID / service principals• Agent365 or equivalent agent platforms• Experience managing identity and access governance, including integration with tools such as SailPoint. • Manifest ability to identify and manage technology risk, including shadow IT or unauthorised solutions. • Excellent stakeholder management skills, with the ability to influence across Security, Legal, Architecture, Engineering and senior leadership. • Comfortable operating at both judicious and deeply technical levels, translating complex risk into clear business decisionsand deeply technical levels, translating complex risk into clear business decisions. • A strong mindset around liable AI, security by design and governance by default.
BT Group is the UK’s leading communications group and the holding company behind some of the country’s most recognised brands – including BT, EE, Openreach and Plusnet. Our purpose is as simple as it is ambitious: we connect for good. Our customers include consumers, small, medium and large businesses, public sector organisations and other communications providers.
BT Group’s role is about setting direction, unlocking value and creating the conditions for our brands and businesses to thrive.
Having come through the most capital-intensive phase of our fibre investment, our focus now is on what comes next – simplifying how we operate, using technology and AI to work smarter, and organising ourselves to serve customers better and grow sustainably. Group teams shape strategy, policy, brand, capital allocation and transformation, helping the whole organisation perform at its best.
We have a singular culture that unites all our people: we are customer-first challengers, who are committed, clear and connected. These behaviours unite us as one team to deliver for our colleagues, our customers, our stakeholders and the country. Joining BT Group means working at the heart of a business that matters to the UK, with the opportunity to shape decisions, influence outcomes and help set the future course of one of the country’s most important companies.
Company benefits
Working at BT Group
Company employees:
Gender diversity (m:f):
Hiring in countries
Hungary
India
Ireland
United Kingdom
Office Locations
Other jobs you might like
AI Assurance Advisor Ref. 3747
£74,624 per annum
Location: Central London
AI Security Architect Ref. 3746
£74,624 per annum
Location: London
Senior Identity & Access GRC Engineer
Bucuresti, Bucuresti, Romania
#1 MOST LOVED - ENTERPRISE COMPANIES

