Full-Time

Lead AI Risk Engineer

Technology, Risk Engineering

College Board

College Board

Compensation Overview

$168k - $183k/yr

Remote in USA

Remote

Periodic travel to College Board offices is required 3–5 times per year.

Category
Cybersecurity (2)
,
Required Skills
LLM
Microsoft Azure
Agile
Threat modeling
AWS
Requirements
  • The candidate must have 8+ years of experience in security engineering, application security, cloud security, or security architecture, including technical leadership of work crossing team and service boundaries.
  • The candidate must have deep, practical expertise in at least two relevant areas, such as cloud security architecture, identity and access management, application security, vendor or third-party risk, or AI/GenAI application security.
  • The candidate must have experience designing identity and access controls for service accounts, API credentials, or machine identities, and applying least-privilege principles in automated systems.
  • The candidate must have experience running or contributing to risk-based security reviews of technology implementations, including assessing architecture, data flows, and misuse scenarios.
  • The candidate must have a track record of turning ambiguous, emerging risk domains into documented standards, repeatable processes, and adoptable guidance.
  • The candidate must be able to work through others by mentoring engineers, deliberately sharing knowledge, and increasing team capability.
  • The candidate must be able to build relationships with product, platform, legal, procurement, and governance partners and present risk tradeoffs to technical and non-technical audiences.
  • The candidate must be comfortable operating while standards, tooling, and regulatory expectations are evolving, including FERPA, student data privacy obligations, and emerging AI governance frameworks.
  • The candidate must be able to travel 3–5 times per year to College Board offices.
  • The candidate must be authorized to work in the United States for any employer.
  • The candidate must communicate clearly and concisely in written and verbal settings.
  • The candidate must be willing to learn and apply new digital tools independently and proactively.
Responsibilities
  • Lead risk-based security reviews of technology implementations across cloud architecture, application security, vendor and third-party integrations, identity and access, and emerging technologies such as generative AI and agentic AI systems.
  • Assess architectures, data flows, data classification handling, and misuse scenarios during security reviews.
  • Evolve the risk review practice into a documented, repeatable methodology with risk tiering, reusable templates, decision records, and findings tracking.
  • Define and maintain secure-by-default standards, patterns, and reference guidance that reduce review friction and enable delivery teams to meet expectations on the first pass.
  • Work across team and service boundaries to translate risk and governance requirements into practical implementation steps that fit Agile delivery and anticipate risks before they become launch blockers.
  • Assess and document ownership, credential scope, and control requirements for systems involving automated or autonomous behavior, including AI agents, service accounts, and machine identities.
  • Serve as a primary security and risk partner to organization-level teams and governance bodies, including GenAI Studio, the GenAI Governance Committee, platform, procurement, and legal stakeholders.
  • Establish recurring consultation touchpoints and pre-procurement engagement.
  • Embed risk requirements into tool onboarding, procurement, and vendor contract processes, including data handling, retention and no-train terms, telemetry expectations, and identity and access provisions.
  • Identify emerging or higher-uncertainty risk areas, including agentic AI, non-human identities, and new integration patterns, and bring them into the standard review process.
  • Define risk acceptance criteria, control requirements, and escalation thresholds; ratify them through appropriate governance bodies and apply them consistently across use cases entering production.
  • Mentor engineers on risk review practices through paired reviews, documentation, and teaching, ensuring knowledge is shared and no capability depends on a single person.
  • Contribute to the strategic direction of the risk engineering program by synthesizing findings from real implementations into roadmap priorities and producing leadership reporting on risk posture and program outcomes.
Desired Qualifications
  • Exposure to AI, generative AI, or agentic systems is a plus but is not required.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A