À propos de ce poste AI Platform & Security Engineer chez Beghouconsulting
Beghou is standing up an AI-native operating model: enterprise Claude and ChatGPT, a growing library of internal skills and tools, an MCP server ecosystem, an internal AI Lab site, and firm-wide cost and governance obligations. Every one of these has an AI-specific platform, security, and configuration layer underneath it – managed policy files, connector and MCP governance, security reviews, token controls, admin and access management, deployment infrastructure.
This role owns that layer. It exists so the platform runs as managed infrastructure with a clear standard and owner as Beghou’s AI footprint scales.
This is a distinct profile from the AI builders on the team. Builders ship skills and automations. This person secures, configures, governs, and deploys the platform those skills run on.
What you will own
This is the current scope. It will evolve as the technology and our adoption change.
Managed configuration and policy
-
Author and maintain managed settings for Claude, ChatGPT, and Codex across the fleet, and keep them current as the tools change
-
Enforce org policy through configuration: connector governance, deny-lists, permitted capabilities, model and feature controls
-
Coordinate rollout of configuration changes with IT and endpoint management so they land consistently on every user’s setup
MCP and integration governance
-
Stand up and secure the MCP server ecosystem: evaluate and operate supply-chain controls, decide hosting and data-residency, maintain the approved MCP catalog
-
Review MCP and agent permissions on a set cadence; approve or reject new server requests against a security bar
-
Decide where MCP servers are hosted and run (client-provided versus Beghou-hosted) and own the hosting posture
Security reviews and GRC partnership
-
Run security reviews for new AI tools, agents, and MCPs, and produce the artifacts GRC needs to approve or approve-with-conditions
-
Maintain the approved AI tool and agent catalog and the conditions attached to each
-
Support HIPAA/GxP and audit posture for AI tooling, and act as the technical counterpart to GRC
Cost and token governance (technical side)
-
Implement usage and token visibility, per-user attribution, budgets, soft caps, and alerting that back the firm’s cost-management framework
-
Build or operate the dashboards and controls that turn governance policy into enforced reality
Access and admin
-
Own the admin consoles for the AI platforms: seat and entitlement provisioning, analytics and API access, SSO and identity coordination with IT
-
Resolve the recurring access and admin requests across the AI toolset
Deployment and infrastructure for AI tools
-
Package and deploy internal skills and tools, and operate the AI Lab site and its hosting infrastructure
-
Set up the CI/CD and environments internal AI tooling needs to ship reliably
What makes someone great at this
-
Security-minded by default. You think about data exposure, permissions, and audit posture before shipping, and you can hold a defensible line with a vendor or a reviewer.
-
Hands-on platform and DevOps depth. You are comfortable with cloud (Azure), identity and SSO, endpoint or configuration management, and policy-as-code. You configure and deploy; you don’t just advise.
-
You move fast without breaking compliance. You find the path that satisfies GRC and still ships this quarter, rather than stalling on either side.
-
You partner across boundaries. This work touches AI Innovation, IT, Cloud, and GRC, and you keep threads moving to closure across all of them.
-
You own ambiguity. Much of this is greenfield at Beghou, and you define the standard where none exists yet.
Background that fits well
-
4–8 years in platform engineering, security engineering, DevOps, cloud infrastructure, or IT engineering
-
Hands-on with cloud (Azure preferred), identity and SSO, and configuration or endpoint management
-
Experience running or supporting security reviews, audit, or compliance tooling (HIPAA/GxP exposure a plus)
-
Familiarity with LLM tooling, agents, or MCP is a strong plus, and the ability to learn it fast is a requirement
-
Comfortable being the technical face to a governance and risk function and to external vendors