
Risk Lead, IT Risk Management
Posted 23 hours ago

Posted 23 hours ago
This is a fully remote position, open to applicants in California, +1 more state.
β’ Take charge of the IT Risk Management standards and methodologies, encompassing risk sensing, aggregation, prioritization, risk appetite, taxonomy, thresholds, and standardized methods.
β’ Spearhead the AI-driven risk intelligence model and articulate how sub-agents prioritize exposure based on business impact.
β’ Deliver real-time insights for leadership across AI and IT signals.
β’ Establish the assurance model for critical service outcomes, including failure tolerances, resilience, control effectiveness, and safeguards throughout the AI lifecycle.
β’ Test disaster-recovery capabilities through evidence-based evaluations of objectives, dependencies, and recovery protocols.
β’ Manage the closed-loop model through designated owners, action tracking, risk acceptance and escalation pathways, and validation of risk mitigation efforts.
β’ Integrate incidents, testing outcomes, and lessons learned back into standards and design frameworks.
β’ Offer technical thought leadership in AI-driven risk management.
β’ Collaborate with Software Engineering and leaders across AI + IT, STO, Finance, Security, Compliance, and Resiliency.
β’ Establish guardrails, assess agent behavior, facilitate automation and telemetry, and maintain domain ownership regarding risk decisions and remediation actions.
β’ Over 12 years of experience in IT risk, GRC, audit, control assurance, or management of technology risk programs.
β’ Proven experience in creating a unified risk framework, taxonomy or scoring method, enterprise risk register, and a consistent executive review schedule.
β’ Experience collaborating with executive team members and domain owners to delineate RACI, escalation processes, risk acceptance, and decision-making rights.
β’ Familiarity with at least two of the following areas: SOX or control assurance, vulnerability management, lifecycle management, business continuity or disaster recovery, application resiliency, CMMC, or GRC or audit.
β’ Bachelorβs degree or equivalent experience in Information Systems, Risk Management, Computer Science, Business, or a related discipline (preferred).
β’ Proven experience employing AI, agentic workflows, automation, or advanced analytics in technology risk, security, resilience, control assurance, or operations.
β’ Experience with establishing guardrails and facilitating human-in-the-loop reviews.
β’ Demonstrated experience leading evidence-based resilience, control effectiveness, or AI lifecycle testing initiatives.
β’ Ability to unify fragmented risk or compliance programs into a cohesive operating model.
β’ Proven experience in building closed-loop risk management with designated owners, action tracking, verified completion, and measures for risk reduction.
β’ Strong ability to promote open communication, balanced discussions, and consensus on decisions that enhance business performance.
β’ Medical, dental, and vision insurance.
β’ 401(k) plan with a matching contribution from Cisco.
β’ Paid parental leave.
β’ Coverage for short- and long-term disability.
β’ Basic life insurance.
β’ Potential for Cisco restricted stock unit grants.
β’ 10 paid holidays each full calendar year.
β’ 1 floating holiday for non-exempt employees.
β’ Paid employee birthday.
β’ Paid year-end holiday shutdown.
β’ 4 paid personal wellness days.
β’ 16 days of paid vacation annually for non-exempt employees.
β’ Flexible vacation time off program for exempt employees.
β’ 80 hours of sick time off provided upon hire and each January 1st thereafter.
β’ Up to 80 hours of unused sick time may be carried forward.
β’ Additional paid time off for critical or emergency family situations.
β’ Optional 10 paid volunteer days per full calendar year.
β’ Annual bonuses for non-sales roles, subject to Cisco policies.
Duck Creek Technologies
Trucordia
Trucordia
Farm Credit Services of America
Get handpicked remote jobs straight to your inbox weekly.