×
Register Here to Apply for Jobs or Post Jobs. X

AI Governance & Controls Lead

Job in Buffalo, Erie County, New York, 14266, USA
Listing for: Luxoft
Full Time position
Listed on 2026-08-14
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity
Job Description & How to Apply Below
Project description

The AI Governance & Controls Lead is the senior individual contributor responsible for operationalizing client's AI governance framework: authoring and maintaining AI standards and controls, executing the policy exception and deviation processes, and producing the examiner-ready evidence that demonstrates our controls are enforced mechanically rather than attested annually. This role partners closely with Technology Risk Management, Model Risk Management, Compliance, Cybersecurity, Enterprise Architecture, and the enterprise AI platform team to ensure every AI use case at the bank operates within a defensible, testable control framework.

This is a hands-on, technically fluent governance role. The Lead works directly with platform-enforced controls (gateway policies, entitlements, quotas, audit logging), translates regulatory obligations (e.g., SR 26-2, NYDFS guidance) into implementable standards, and validates that evidence generated by the platform satisfies second-line and examiner expectations. The role serves as a key contributor to policy refresh cycles, regulatory response efforts, and the continuous-monitoring design that replaces point-in-time annual review

Responsibilities

Standards, Controls & Policy Execution

Author, maintain, and version the bank's AI standards library: model selection and approval, human oversight tiers, prompt/response logging and retention, agentic guardrails, and acceptable-use requirements.

Build and maintain the obligation-to-control-to-evidence mapping against applicable regulatory guidance (SR 26-2, NYDFS, and evolving supervisory expectations).

Operate the AI policy exception and TRM deviation processes: draft time-bound deviation requests, define compensating controls, track expiries and remediation paths to closure.

Support annual policy refresh cycles and translate policy principles into testable, enforceable requirements in partnership with policy owners.

Platform-Enforced Governance & Evidence

Partner with the AI platform team to ensure governance requirements are enforced mechanically at the enterprise AI gateway (entitlements, model allow lists, quotas, audit logging) and that enforcement produces native evidence.

Define evidence requirements and validate audit artifacts as queryable, export-ready, and sufficient for internal audit, second-line review, and examiner requests.

Design and operate continuous-monitoring practices: monitoring boundaries, event-based review triggers, and evidence expectations for AI systems that change frequently.

Maintain the AI use case and agent registry as the system of record, integrated with platform onboarding and entitlement workflows.

Provide governance ownership of the AI use-case intake framework in partnership with the AI Use Case Intake & Value Lead.

Risk Partnership & Regulatory Readiness

Serve as the primary working-level interface to Technology Risk Management, Model Risk Management, Compliance, and Internal Audit for AI governance matters.

Assemble examiner-readiness packages: control mappings, evidence samples from the live platform, and documented rationale for the standards the bank has defined.

Monitor the regulatory and industry landscape (agency guidance, FSB/trade-group developments) and assess impact to standards and controls.

Support AI Control Group and AI Ethics Working Group activities with documented assessments and control recommendations.

Skills

Must have

Bachelor's degree and a minimum of 5 years' experience in technology risk, IT governance, information security governance, or technology compliance within a regulated environment, or in lieu of a degree, a combined minimum of 9 years' education and/or relevant work experience.

Demonstrated experience authoring technology standards, controls, or policies and mapping them to regulatory obligations.

Working technical fluency with modern AI systems: LLM-based applications, API gateways, model access patterns, RBAC/entitlements, logging and monitoring architectures.

Experience preparing for or responding to internal audit, second-line review, or regulatory examination.

Strong analytical writing: able to produce standards, deviation requests, and evidence narratives that survive challenge.

Strong communication and stakeholder management skills across risk, technology, and business partners

Nice to have

Experience with AI/ML governance frameworks (NIST AI RMF, model risk management guidance, SR 11-7/SR 26-2 lineage).

Familiarity with Azure services relevant to AI workloads (API Management, Entra , Key Vault, Azure Monitor) and with policy-as-code or controls-automation concepts.

Financial services or other highly regulated industry experience.

Experience with GRC tooling and evidence management.

Experience supporting AI, data, or technology committees and governance forums

Other

Languages

English: C1 Advanced

Seniority

Lead
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary