Principal – AI Technology Risk
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: New York City with a hybrid work model; positions in Scottsdale, San Francisco, Chicago, and New York are also hybrid. Applicants must already be eligible to work in the United States for any employer. Visa sponsorship is not available.
Base pay: $221,000–$276,000 per year in New York or San Francisco; $184,000–$230,000 per year in Phoenix, Chicago, or Washington, DC. Additional discretionary incentive plan and benefits are available.
Company
provides payment and financial-services technology, including Zelle and Paze, while supporting transaction security for financial institutions, consumers, and businesses.
What you will do
- Lead second-line oversight, independent challenge, and governance of AI technology risk across the organization.
- Oversee AI risk assessments, governance decisions, risk classification, escalations, and regulatory alignment for customer-facing and internal AI use cases.
- Review LLM usage, AI infrastructure, emerging technologies, and proposed adoption from security and risk perspectives.
- Develop and maintain AI technology policies, governance operating models, reporting standards, and KPI/KRI frameworks.
- Manage security posture initiatives, control design and implementation, remediation tracking, and evidence review through closure.
- Advise and collaborate with cross-functional stakeholders to strengthen risk ownership, controls, and security posture.
Requirements
- 15+ years of progressive information technology or information security experience, including firewalls, IDS, vulnerability management, antivirus, DLP, two-factor authentication, and VPN technologies.
- Experience working in regulated environments and at least 3 years in security governance, regulatory controls, privacy, risk assessment, and risk management.
- Experience with AI compute technologies such as Bedrock and understanding of AI systems governance and technology risk.
- Advanced knowledge of network security, application security, secure architecture, operating-system security, hardening, cloud security, and security controls.
- Ability to apply ISO, PCI, and NIST/FISMA standards, with experience developing and tracking information-security KPIs and KRIs.
- Bachelor’s degree in computer science, information technology, cybersecurity, or a related field; background and drug screening required.
Nice to have
- Expertise in ISO 27002, PCI DSS, NIST 800-53A, SIG, FFIEC, SOC 2 Type II, GLBA, FCRA, NYDFS, or data privacy.
- Certification such as CISA, CISM, CISSP, CCSP, CRISC, GSNA, or CGIH.
- Project or process management experience.
Culture & Benefits
- Hybrid office environment with primarily sedentary computer-based work.
- Medical, dental, and vision coverage, plus HSA and FSA options.
- 401(k) plan with a 100% company safe-harbor match on the first 6% deferred.
- Flexible time off for exempt employees, paid holidays, and a paid volunteer day.
- 12 weeks of paid parental leave and family-planning support.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →