Senior Manager, AI Corporate Engineering
Job description
About the role
Vanta is seeking a Senior Manager, AI Corporate Engineering to lead the infrastructure layer that underpins the company's AI-first operating model. In this role, you will own the end-to-end strategy and execution for the internal AI and developer platform that keeps Vanta's operations secure, efficient, and scalable. You will define the boundaries of Corporate Engineering, distinguishing between direct ownership and enabled services, while ensuring that departmental AI initiatives remain coordinated and aligned with company-wide standards. This position is critical for translating the rapid adoption of AI tools into a governed, cost-effective, and reliable environment. You will lead a team of senior engineers and program managers, setting direction and fostering a culture where data drives decisions and healthy pushback is encouraged. Success in this role will be measured by the platform's ability to accelerate safe AI adoption while controlling risk, cost, and duplication across the organization. You will be the primary architect of the "golden path" that makes secure and compliant AI usage the easiest path for every team at Vanta.
Key facts
What you'll do
- Lead, coach, and grow a senior team spanning platform engineering and technical program management, providing clear direction and fostering a culture of accountability and data-driven feedback.
- Own the AI access layer end to end, including identity and authentication for AI tools, connector and integration allowlisting, tiered permissions by function, and guardrails that make adoption safe by default.
- Drive AI cost engineering by building attribution down to the team and individual level, right-sizing model selection to actual need, and making agent and automation spend traceable and transparent.
- Partner with Finance to set budget thresholds and alerting, ensuring that AI expenditure is predictable, justified, and aligned with business value.
- Own the MCP layer for internal tools end to end, overseeing commissioning, decommissioning, governance, and conducting downstream impact assessments before any migration ships.
- Define and own the paved path for internal applications, including a golden-path deployment pattern, sensible defaults with private-by-default settings, and lifecycle and decommissioning policies.
- Build the enablement layer that turns adoption into impact through a skills and agent registry, an evaluation framework for internal AI usage, and hands-on technical guidance on sanctioned tools.
- Write and hold the charter for Corporate Engineering, clearly defining ownership boundaries, enabling functions, and the process for how work enters the team.
- Convene a cross-functional forum with Engineering, GRC, Security, Data, Finance, and People to coordinate departmental AI efforts and prevent duplication of work.
- Partner across key organizations such as Engineering, GRC, Security, Data, Finance, and People, influencing through collaboration rather than direct authority.
- Stand up an internal AI or developer platform function from scratch, writing the initial roadmap, intake processes, and governance model without inheriting a mature system.
- Hold scope by landing a bounded first version of a complex initiative and declining additional work without it being perceived as abdication of responsibility.
- Ensure fluency in AI cost engineering, including token economics, usage attribution, model right-sizing, and the distinction between hard limits and useful guardrails.
- Foster an enablement-first mindset where the default question is how to make something safe for self-service, always explaining declines and offering alternative paths to visibility.
- Apply hands-on technical depth across LLM platform tooling, agent and MCP architecture, identity and OAuth, CI/CD, and infrastructure as code to review designs and assess risk.
- Build for a non-engineer audience, ensuring that internal tools and platforms are accessible and secure for product and operations teams who are not developers.
- Maintain data governance fluency in a regulated environment, understanding what types of data should never enter a prompt, repository, or third-party tool.
Requirements
- Experience standing up an internal AI or developer platform function rather than inheriting a mature one, having written the charter, defined intake, and built the roadmap from a blank page.
- The ability to hold scope, taking a commitment that was made without proper scoping or resourcing, delivering a bounded first version, and declining the rest without it being viewed as a failure.
- Fluency in AI cost engineering, including usage attribution, model right-sizing, token economics, agent cost traceability, and the difference between a hard limit and a useful guardrail.
- An enablement-first instinct, with a default approach of making things safe to self-serve and always explaining why access is declined while offering alternative paths to the same outcome.
- Hands-on technical depth across LLM platform tooling, agent and MCP architecture, identity and OAuth, CI/CD, and infrastructure as code, enough to review a design honestly and distinguish real risk from reported progress.
- Comfort building for an audience that is no longer limited to engineers, recognizing that many internal tool creators are not developers and the platform must serve them without lowering the security bar.
- Data governance fluency in a regulated environment, knowing what should never enter a prompt, a repository, or a third-party tool.
- The capacity to influence cross-functional stakeholders who sit in Engineering, GRC, Security, Data, Finance, and People, coordinating work without direct authority.
Practical notes
This is a full-time remote position based in the United States. There are no requirements for travel, visa sponsorship is not mentioned, and the posting does not specify an application deadline.