AI Security Risk & GRC Lead

jeffersonhealth

Pennsylvania

On-site

USD 150,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Jefferson Health seeks a Manager, Technology, AI, and Security Risk to lead the organization's Security Risk Assessment portfolio with hands-on technical and security architecture focus. You will review architectures, designs, and controls of internal applications, AI-enabled apps, APIs, cloud environments, and external connections to drive risk decisions.

You will own GRC components of the portfolio, including control framework management, regulatory assessments (HIPAA, NIST, PCI), external

Responsibilities

  • Lead security architecture reviews across internally developed applications, AI systems and agents, APIs, and cloud environments, assessing design, data flows, trust boundaries, and control coverage both before and after deployment.
  • Perform and oversee threat modeling and secure design reviews for custom-built and AI-enabled applications throughout the development lifecycle, identifying design-level weaknesses and driving fixes into engineering work.
  • Define the technical assessment approach for AI and machine learning systems, covering model and data governance, prompt and agent security, guardrails, output validation, and misuse scenarios.
  • Evaluate and validate security controls at the application, integration, and infrastructure layers, including authentication, authorization, encryption, logging, segmentation, and secrets management.
  • Own the Security Risk Assessment portfolio end to end, ensuring a consistent and technically rigorous methodology, prioritization, and reporting across control framework management, enterprise and regulatory assessments, external and third-party risk, cyber risk, issues management, and cloud posture.
  • Lead cloud security posture management, including configuration and hardening review, identity and access design, and asset and attack-surface visibility.
  • Assess third-party, medical device, and B2B integration risk with real attention to the technical interfaces, data exchange, and connectivity involved, not just questionnaire responses.
  • Maintain the cyber risk register and apply quantitative analysis to technical findings, translating architecture and control gaps into decision-ready risk.
  • Drive remediation of findings from architecture reviews, assessments, audits and testing through to validated technical closure.
  • Ensure applications and platforms meet information security policies, standards, and applicable regulatory frameworks (e.g., HIPAA, NIST, PCI), and inform updates to technical and secure-design standards as technology and threats evolve.
  • Partner with engineering, cloud, data, and AI teams to embed security into how systems operate.
  • Advance AI enablement across the team, applying AI-assisted automation to assessment, architecture review, and reporting workflows to strengthen efficiency gains and scale the portfolio's output.

Skills

Security architecture
Threat modeling
AI risk
Cloud security
Regulatory compliance
HIPAA compliance
NIST/PCI standards

Job description

Jefferson Health seeks a Manager, Technology, AI, and Security Risk to lead the organization's Security Risk Assessment portfolio with hands-on technical and security architecture focus. You will review architectures, designs, and controls of internal applications, AI-enabled apps, APIs, cloud environments, and external connections to drive risk decisions.

You will own GRC components of the portfolio, including control framework management, regulatory assessments (HIPAA, NIST, PCI), external

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technical AI Risk & Security Leader
Technical AI Risk & Security Leader

Jefferson Health • Washington, Northern (KY)

Hybrid
USD 120,000 - 165,000
AI Risk & Security Leader
AI Risk & Security Leader

Thomas Jefferson University • Orlando (FL)

On-site
USD 120,000 - 160,000
Medical insurance
Tuition assistance
Retirement plans
+1
GRC Analyst: Information Security & Risk
GRC Analyst: Information Security & Risk

Jefferson Health • Washington, Northern (KY)

Hybrid
USD 90,000 - 120,000
Medical Insurance
Tuition Assistance
GRC Analyst: Risk, Compliance & Resilience
GRC Analyst: Risk, Compliance & Resilience

jeffersonhealth • Pennsylvania

On-site
USD 90,000 - 120,000
Senior GRC Analyst: Security & Risk Leader
Senior GRC Analyst: Security & Risk Leader

Jefferson Health • Washington, Northern (KY)

Hybrid
USD 100,000 - 150,000
Senior GRC Analyst: Risk, Compliance & Resilience
Senior GRC Analyst: Risk, Compliance & Resilience

jeffersonhealth • Pennsylvania

On-site
USD 120,000 - 150,000
AI Enterprise Product Leader: Strategy to Delivery
AI Enterprise Product Leader: Strategy to Delivery

jeffersonhealth • Pennsylvania

On-site
USD 130,000 - 180,000
Senior AI Software Engineer Cloud & Security
Senior AI Software Engineer Cloud & Security

Jefferson Health • Fort Washington

On-site
USD 130,000 - 180,000
Medical insurance
Dental
Vision
+3
Technology and AI Risk, Manager
Technology and AI Risk, Manager

jeffersonhealth • Pennsylvania

On-site
USD 150,000 - 210,000
IAM Engineer: Identity, Access & Governance Expert
IAM Engineer: Identity, Access & Governance Expert

Jefferson Health • Washington, Northern (KY)

Hybrid
USD 110,000 - 140,000
Medical insurance
Dental insurance
Vision coverage
+2