Description
The AI Risk and AI Risk Governance Manager is a Second Line of Defense individual contributor role within Risk Management responsible for providing independent oversight, challenge, and risk governance support for enterprise-wide artificial intelligence activities, with emphasis on generative AI, agentic AI, and AI-enabled applications. This role will report to the AI Risk and Digital Assets Risk Director and help ensure AI use across the enterprise is governed in alignment with risk appetite, internal policy, regulatory expectations, and responsible AI principles. This role partners closely with first-line business, technology, data, model risk, compliance, privacy, information security, audit, and other risk stakeholders to provide credible challenge over AI risk identification, assessment, monitoring, control design, and governance processes. The role will also support development and oversight of risk governance expectations specific to AI agents and agentic AI systems, including autonomy, tool use, human oversight, escalation, testing, monitoring, change management, and incident response considerations. Key Responsibilities
- Provide independent Second Line of Defense oversight and credible challenge of enterprise AI governance activities, including AI risk identification, risk assessment, control expectations, monitoring, reporting, issue management, and escalation.
- Assess whether first-line AI governance, control, testing, validation, and monitoring practices are appropriately designed and operating in alignment with enterprise risk appetite, AI policy, risk management standards, and applicable regulatory expectations.
- Support risk governance program expectations for AI agents and agentic AI systems, including requirements related to autonomy, delegated decision-making, tool and API access, task boundaries, auditability, and kill-switch or deactivation protocols.
- Establish and maintain oversight expectations for material changes to AI systems, including changes to models, data sources, prompts, tools, permissions, integrations, autonomy, and intended use, and challenge whether reassessment, retesting, approval, restriction, or deactivation is required.
- Evaluate risks associated with generative AI and agentic AI use cases, including inaccurate or misleading outputs, inappropriate system actions, prompt injection, data leakage, privacy concerns, bias, explainability, security vulnerabilities, third-party dependencies, operational resiliency, and model or system drift.
- Provide oversight and challenge of AI use case intake, classification, approval, monitoring, inventory, and material change processes to ensure appropriate governance coverage across the AI lifecycle and visibility into aggregate enterprise exposure, common dependencies, and concentration risk.
- Review AI risk assessment and ongoing monitoring outputs and challenge whether risks, controls, testing evidence, residual risk conclusions, limitations, compensating controls, risk acceptances, and continued-use decisions are sufficiently documented and supported.
- Partner with Model Risk Management, Technology Risk, Operational Risk, Compliance, Privacy, Information Security, Legal, Internal Audit, and business risk teams to ensure AI governance expectations are consistently interpreted and applied across the enterprise.
- Monitor emerging AI and agentic AI risks, industry practices, regulatory developments, and internal control themes; translate relevant developments into actionable oversight considerations.
- Support governance reporting for senior management and risk committees by developing concise insights on the enterprise AI risk posture, alignment with risk appetite, material exposures, concentration and dependency risks, control themes, open issues, and areas requiring escalation.
- Support audit, regulatory exam, and issue response activities related to AI governance, including evidence review, management responses, remediation oversight, and validation of completed actions.
Basic Qualifications
- Bachelors degree
- 7 or more years of AI, Model and Technology experience applying risk management concepts to AI or technology-enabled processes, including risk identification, control evaluation, monitoring, issue management, and governance reporting.
Preferred Qualifications
- Experience applying risk management concepts to AI or technology-enabled processes, including risk identification, control evaluation, monitoring, issue management, and governance reporting.
- Demonstrated ability to provide independent oversight and challenge while building effective partnerships with business, technology, data, risk, compliance, and control stakeholders.
- Working knowledge of AI governance frameworks and responsible AI practices, including controls related to transparency, explainability, human oversight, accountability, privacy, fairness, security, resiliency, and third-party risk.
- Understanding of agentic AI risk considerations, including autonomous task execution, tool use, orchestration, delegation chains, memory, permissions, boundary setting, runtime monitoring, and intervention or shutdown procedures.
- Familiarity with NIST AI Risk Management Framework, generative AI risk management practices, model risk management principles, operational risk frameworks, technology risk controls, or similar governance standards.
- Experience reviewing AI or automation use cases for risk tiering, documentation completeness, control adequacy, testing evidence, monitoring plans, and residual risk conclusions.
- Ability to synthesize complex AI, technology, risk, and regulatory topics into clear written materials, governance reporting, and executive-ready issues or recommendations.
- Strong analytical, communication, and influencing skills, with the ability to challenge constructively and drive risk-informed outcomes without direct ownership of first-line execution.
- Professional certification or advanced training in AI governance, model risk, technology risk, information security, privacy, audit, compliance, or risk management.
Exempt Status: (Yes = not eligible for overtime pay) (No = eligible for overtime pay)
YesWorkplace Type:
OfficeOur Approach to Office Workplace Type
Certain positions outside our branch network may be eligible for a flexible work arrangement. We’re combining the best of both worlds: in-office and work from home. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. Remote roles will also have the opportunity to come together in our offices for moments that matter. Specific work arrangements will be provided by the hiring team.
Huntington is an Equal Opportunity Employer.
Tobacco-Free Hiring Practice: Visit Huntington's Career Web Site for more details.
Note to Agency Recruiters: Huntington Bank will not pay a fee for any placement resulting from the receipt of an unsolicited resume. All unsolicited resumes sent to any Huntington Bank colleagues, directly or indirectly, will be considered Huntington Bank property. Recruiting agencies must have a valid, written and fully executed Master Service Agreement and Statement of Work for consideration.

