AI Governance & Controls Lead

Luxoft

Buffalo (NY)

On-site

USD 140,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Luxoft in Buffalo, NY seeks an AI Governance & Controls Lead to operationalize the bank's governance framework, authoring AI standards, controls, and evidence that the platform enforces policy mechanically.

This hands-on role partners with Risk, Compliance, Cybersecurity, and Enterprise Architecture to translate regulatory obligations into implementable requirements and to produce examiner-ready documentation.

Qualifications

  • Bachelor's degree and a minimum of 5 years' experience in technology risk, IT governance, information security governance, or technology compliance within a regulated environment, or in lieu of a degree, a combined minimum of 9 years' education and/or relevant work experience.
  • Demonstrated experience authoring technology standards, controls, or policies and mapping them to regulatory obligations.
  • Working technical fluency with modern AI systems: LLM-based applications, API gateways, model access patterns, RBAC/entitlements, logging and monitoring architectures.

Responsibilities

  • Author, maintain, and version the bank's AI standards library and map obligations to controls.
  • Operate policy exception and deviation processes and define compensating controls.
  • Partner with platform team to enforce governance mechanically at enterprise gateway and produce native evidence.

Skills

Technology risk
IT governance
information security governance
policy authoring
auditing
stakeholder management

Education

Bachelor's degree

Tools

GRC tooling
Azure Monitor
API gateways
Entra ID

Job description

Project description

The AI Governance & Controls Lead is the senior individual contributor responsible for operationalizing client's AI governance framework: authoring and maintaining AI standards and controls, executing the policy exception and deviation processes, and producing the examiner-ready evidence that demonstrates our controls are enforced mechanically rather than attested annually. This role partners closely with Technology Risk Management, Model Risk Management, Compliance, Cybersecurity, Enterprise Architecture, and the enterprise AI platform team to ensure every AI use case at the bank operates within a defensible, testable control framework.This is a hands-on, technically fluent governance role. The Lead works directly with platform-enforced controls (gateway policies, entitlements, quotas, audit logging), translates regulatory obligations (e.g., SR 26-2, NYDFS guidance) into implementable standards, and validates that evidence generated by the platform satisfies second-line and examiner expectations. The role serves as a key contributor to policy refresh cycles, regulatory response efforts, and the continuous-monitoring design that replaces point-in-time annual review

Responsibilities
  • Standards, Controls & Policy ExecutionAuthor, maintain, and version the bank's AI standards library: model selection and approval, human oversight tiers, prompt/response logging and retention, agentic guardrails, and acceptable-use requirements.Build and maintain the obligation-to-control-to-evidence mapping against applicable regulatory guidance (SR 26-2, NYDFS, and evolving supervisory expectations).Operate the AI policy exception and TRM deviation processes: draft time-bound deviation requests, define compensating controls, track expiries and remediation paths to closure.Support annual policy refresh cycles and translate policy principles into testable, enforceable requirements in partnership with policy owners.Platform-Enforced Governance & EvidencePartner with the AI platform team to ensure governance requirements are enforced mechanically at the enterprise AI gateway (entitlements, model allowlists, quotas, audit logging) and that enforcement produces native evidence.Define evidence requirements and validate audit artifacts as queryable, export-ready, and sufficient for internal audit, second-line review, and examiner requests.Design and operate continuous-monitoring practices: monitoring boundaries, event-based review triggers, and evidence expectations for AI systems that change frequently.Maintain the AI use case and agent registry as the system of record, integrated with platform onboarding and entitlement workflows.Provide governance ownership of the AI use-case intake framework in partnership with the AI Use Case Intake & Value Lead.Risk Partnership & Regulatory ReadinessServe as the primary working-level interface to Technology Risk Management, Model Risk Management, Compliance, and Internal Audit for AI governance matters.Assemble examiner-readiness packages: control mappings, evidence samples from the live platform, and documented rationale for the standards the bank has defined.Monitor the regulatory and industry landscape (agency guidance, FSB/trade-group developments) and assess impact to standards and controls.Support AI Control Group and AI Ethics Working Group activities with documented assessments and control recommendations.
SKILLS
Must have
  • Bachelor's degree and a minimum of 5 years' experience in technology risk, IT governance, information security governance, or technology compliance within a regulated environment, or in lieu of a degree, a combined minimum of 9 years' education and/or relevant work experience.Demonstrated experience authoring technology standards, controls, or policies and mapping them to regulatory obligations.Working technical fluency with modern AI systems: LLM-based applications, API gateways, model access patterns, RBAC/entitlements, logging and monitoring architectures.Experience preparing for or responding to internal audit, second-line review, or regulatory examination.Strong analytical writing: able to produce standards, deviation requests, and evidence narratives that survive challenge.Strong communication and stakeholder management skills across risk, technology, and business partners
Nice to have
  • Experience with AI/ML governance frameworks (NIST AI RMF, model risk management guidance, SR 11-7/SR 26-2 lineage).
  • Familiarity with Azure services relevant to AI workloads (API Management, Entra ID, Key Vault, Azure Monitor) and with policy-as-code or controls-automation concepts.
  • Financial services or other highly regulated industry experience.
  • Experience with GRC tooling and evidence management.
  • Experience supporting AI, data, or technology committees and governance forums
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Governance & Controls Lead
AI Governance & Controls Lead

Luxoft • Wilmington (DE)

On-site
USD 140,000 - 190,000
AI Governance Engineer
AI Governance Engineer

Luxoft • United States

Hybrid
USD 140,000 - 170,000
AI Governance Engineer
AI Governance Engineer

Luxoft • Buffalo (NY)

Hybrid
USD 140,000 - 190,000
AI Governance Engineer
AI Governance Engineer

Luxoft • Wilmington (DE)

Hybrid
USD 140,000 - 190,000
AI Governance Engineer – Standards & Controls
AI Governance Engineer – Standards & Controls

Glint Tech Solutions • Buffalo (NY)

Hybrid
USD 120,000 - 165,000
AI Governance Architect
AI Governance Architect

Arcitix Technologies • United States

Hybrid
USD 150,000 - 200,000
AI Governance Specialist
AI Governance Specialist

Jobtailor • Connecticut

On-site
USD 90,000 - 150,000
Financial Analyst/Project Planning & Controls
Financial Analyst/Project Planning & Controls

CUBRC • Buffalo (NY)

Hybrid
USD 140,000 - 190,000
Principal, AI Governance
Principal, AI Governance

Request Technology, LLC • Chicago (IL)

On-site
USD 120,000 - 160,000
Sr Director of Software Engineering - AI Governance
Sr Director of Software Engineering - AI Governance

JPMorgan Chase & Co. • New York (NY)

On-site
USD 220,000 - 360,000