Published Date
6 days ago
Work Arrangement
Hybrid • New York, NY or Remote, USA
Open Positions
30 openings
Experience Level
Senior
About the opportunity
Lead enterprise GRC and AI risk programs, translating emerging AI, cybersecurity, privacy, and regulatory risks into scalable governance strategies and measurable controls.
What you will do
- check_circle Own and mature enterprise GRC and AI governance programs covering cybersecurity, technology risk, privacy, regulatory compliance, and responsible AI.
- check_circle Lead risk assessments and control evaluations across AI systems, cloud platforms, applications, vendors, and critical business processes.
- check_circle Design and maintain governance frameworks, control libraries, risk registers, policies, standards, and executive-level risk reporting aligned with NIST AI RMF, NIST CSF, ISO 27001, SOC 2, and applicable regulations.
- check_circle Establish AI risk management processes covering model governance, data protection, security, explainability, human oversight, third-party AI dependencies, and ongoing monitoring.
- check_circle Lead audit and regulatory readiness activities, including evidence management, control testing, remediation tracking, and coordination with internal and external auditors.
- check_circle Partner with engineering, security, legal, privacy, and product leadership to translate complex technical and regulatory risks into actionable business decisions.
- check_circle Drive automation and AI-assisted GRC capabilities to improve continuous control monitoring, risk analysis, compliance reporting, and governance workflows.
What we are looking for
- arrow_circle_right 8+ years of experience in GRC, cybersecurity risk, technology risk, compliance, audit, or a closely related field, with significant enterprise-level ownership.
- arrow_circle_right Deep expertise in GRC and security frameworks including NIST CSF, NIST AI RMF, ISO 27001, SOC 2, and enterprise risk management practices.
- arrow_circle_right Proven experience designing or leading AI governance, AI risk management, responsible AI, or emerging technology risk programs.
- arrow_circle_right Strong understanding of cloud security, data privacy, third-party risk, security controls, regulatory requirements, and technology audit processes.
- arrow_circle_right Demonstrated ability to influence senior executives and cross-functional stakeholders and communicate complex risk topics in clear business terms.
- arrow_circle_right Experience with GRC platforms, risk automation, continuous compliance, or AI-enabled compliance workflows is strongly preferred.
Skills & Tech Stack
Why candidate applications stand out
Verified Technical Credentials
Applications include direct proof-of-work repositories and instructor verification endorsements.
Fast-Track Hiring Visibility
Direct internal referral channels through enterprise partners bypass automated resume discard filters.