This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Director, Risk based in the United States.
This senior leadership role will lead and mature technology risk management while establishing strong governance for emerging technologies.
A core focus will be developing and overseeing AI, machine learning, and generative AI governance across the organization.
You’ll guide risk identification, assessment, mitigation, monitoring, reporting, and escalation while helping teams operate within defined risk appetite.
The role combines strategic risk leadership with practical execution, translating regulatory and control expectations into actionable policies and processes.
You’ll collaborate with risk owners and cross-functional teams across technology, security, privacy, compliance, and business functions.
Your expertise will help strengthen the overall control environment while enabling responsible innovation in a highly regulated financial-services setting.
This is a fully remote opportunity reporting directly to the Chief Compliance Officer.
Accountabilities
- Lead and continuously mature the enterprise and technology risk management program, covering risk identification, assessment, mitigation, acceptance, monitoring, reporting, and escalation.
- Provide strategic direction for risk frameworks, methodologies, metrics, assessments, governance practices, and executive reporting.
- Apply recognized risk and control frameworks and standards, including ISO, COSO, NIST, COBIT, and relevant financial-services requirements.
- Identify and monitor key technology and operational risks against the organization’s approved risk appetite and support IT risk assessments, including threat identification and analysis.
- Develop and maintain IT risk and control assessments, documenting and evaluating risks and controls and partnering with risk owners to assess control design and effectiveness.
- Analyze risk ratings and control decisions, including remediation, mitigation, acceptance, and avoidance, while reviewing monitoring and testing results.
- Report on the adequacy and effectiveness of the risk and control environment and escalate material issues appropriately.
- Promote organization-wide risk awareness, accountability, ownership, and disciplined follow-through.
- Lead the governance lifecycle for AI, machine learning, and generative AI use cases, including intake, risk classification, assessment, controls, monitoring, issue management, and reporting.
- Evolve AI governance policies, standards, review criteria, documentation, and control requirements to address emerging risks and regulatory expectations.
- Evaluate AI-related risks involving data, privacy, information security, system behavior, third-party providers, regulatory obligations, and customer impact.
- Translate AI governance principles and regulatory expectations into practical requirements for products, platforms, technology, processes, and business operations.
- Serve as a subject matter expert and lead reviewer for enterprise, technology, information security, privacy, emerging-technology, and AI-related risks.
- Support the Chief Compliance Officer and broader compliance organization, as needed, with business continuity and disaster recovery governance, regulatory management, compliance advisory matters, incidents, and related cross-functional initiatives.
- Facilitate risk and control discussions, challenge assumptions constructively, clarify accountability, and drive timely decisions and remediation.
- Prepare concise, defensible risk materials and recommendations for executive, board, audit, client, and regulatory audiences.
- Use GRC and risk management platforms to support effective governance, assessment, documentation, monitoring, and reporting.
- Bachelor’s degree required; master’s degree preferred, or an equivalent combination of education and professional experience.
- 15+ years of progressive experience in risk management, internal audit, compliance, IT audit, security risk, or related control functions.
- At least 5 years of experience leading risk, control, compliance, governance, or related programs.
- 10+ years of experience within banking, financial services, FinTech, or another regulated technology environment.
- Demonstrated experience developing, implementing, or overseeing AI governance, AI risk management, or responsible AI practices.
- Strong technical fluency in artificial intelligence, machine learning, and generative AI, with the ability to understand and evaluate emerging technology risks.
- Strong working knowledge of risk and control frameworks and regulatory requirements, including NIST, SCF, ISO, COSO, COBIT, FFIEC, FDIC, NCUA, CFPB, OCC, GLBA, SOC, PCI DSS, and related financial-services standards.
- Knowledge of IT security and privacy risk principles, technology controls, and emerging technology risk.
- Demonstrated ability to translate regulatory, privacy, security, risk, and control requirements into practical business, product, technology, platform, and process requirements.
- Experience managing risk assessments, control evaluations, mitigation plans, remediation activities, risk acceptance, monitoring, and executive reporting.
- Experience using GRC or comparable risk management platforms, including AuditBoard/Optro or similar tools.
- One or more relevant professional certifications is preferred, such as CRCM, CIA, CPA, CISA, CRMA, CRISC, CISSP, CISM, CBCP, CGRC, IAPP AIGP, or an equivalent AI governance/responsible-AI credential.
- Strong strategic judgment and independence, combined with a pragmatic approach to balancing risk management with business objectives.
- Excellent facilitation, stakeholder management, communication, and influencing skills.
- Strong written and verbal communication skills, including the ability to produce concise materials for senior leadership, boards, auditors, clients, and regulators.
- Strong analytical skills, sound decision-making, persistence, and the ability to drive accountability across cross-functional teams.
- Must be authorized to work full-time in the United States; employment sponsorship is not available.
- Fully remote work opportunity within the United States.
- Competitive annual salary range of $151,000-$189,000.
- Unlimited paid time off.
- 401(k) retirement plan with employer matching.
- Comprehensive employee benefits package.
- Diverse and inclusive workplace environment.
- Opportunities for professional development and continuous learning.
- Exposure to emerging technology, AI governance, financial-services risk, and enterprise-level governance initiatives.
- Opportunity to influence risk strategy and responsible technology adoption at a growing technology organization.

