Sr. Enterprise Risk Operations Specialist

Reflection

New York (NY)

On-site

USD 120,000 - 170,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Stock options
Health insurance
Meals provided in office
23 weeks paid parental leave (US)
Unlimited vacation / PTO
Visa sponsorship

Job summary

Reflection is seeking a Sr. Enterprise Risk Operations Specialist to join Enterprise Risk & Trust. You will translate governance into operational reality, validating adherence and driving remediation across commercial risk, third-party risk, controls, and risk issue management.

You will partner with product, engineering, legal, and compliance teams to ensure risk obligations are evidenced and addressed, with high visibility and impact across the organization.

Qualifications

  • 7+ years of progressive experience in risk operations, compliance, or related discipline.
  • Hands-on practitioner with scalable risk program experience.
  • Experience delivering risk assessments, certifications, or security questionnaires.
  • Knowledge of AI system risk evaluation and safety testing.

Responsibilities

  • Drive end-to-end lifecycle for risk assessments supporting deals pipeline.
  • Partner with sales, legal, and product to tailor risk artifacts.
  • Develop library of risk artifacts and evidence packages.
  • Serve as risk SME in customer conversations and RFPs involving risk, compliance, and AI safety topics.
  • Conduct third-party risk assessments and vendor monitoring.
  • Define vendor risk tiering and onboarding criteria.

Skills

Operational discipline
Analytical skills
Cross-functional collaboration
Communication skills
AI risk knowledge

Tools

GRC platforms

Job description

Our Mission

Reflection is a research lab making intelligence open and accessible for everyone to use, customize, and build on. We build open models that let anyone control their intelligence and help shape the future of AI. Our mission: make intelligence open and accessible to all.

Role Overview

The Sr. Enterprise Risk Operations Specialist position is a senior role within Enterprise Risk & Trust, reporting to the Head of Enterprise Risk & Trust. This is the hands-on expert who translates the organization’s risk governance frameworks and policies into operational reality — personally operating the machinery that validates adherence, surfaces issues, and drives resolution. The result is a continuously evidenced, audit-ready risk posture that can be confidently represented to customers, regulators, and leadership.

Spanning commercial risk support, third-party risk management, controls assurance, and risk issue management, this role serves as an operational center of gravity for the Enterprise Risk & Trust function — coordinating across product, engineering, legal, and compliance teams to ensure risk obligations are not just understood, but actively evidenced and remediated where gaps exist.

This is a high-visibility, high-impact individual-contributor role that operates across all business functions. Success requires the ability to translate complex risk concepts into verifiable risk management, influence without direct authority, and build trusted relationships internally and externally.

What You'll Do
Commercial Risk & Go-to-Market Support
  • Drive the end-to-end lifecycle for risk assessments and certifications supporting the deals pipeline and go-to-market efforts, ensuring risk reviews are completed with the speed and rigor the business requires.

  • Partner closely with sales, legal, and product teams to scope and deliver risk assessments tailored to customer requirements, industry verticals, and deal-specific obligations.

  • Develop and maintain a library of reusable risk assessment artifacts, certifications, and evidence packages that accelerate commercial cycles without compromising quality.

  • Serve as a risk subject-matter expert in customer-facing conversations, due diligence requests, and RFP responses involving risk, compliance, and AI safety topics.

Third-Party & Vendor Risk Management
  • Conduct upfront due-diligence assessments, ongoing risk monitoring, and on-demand risk reviews of third parties and vendors supporting organizational operations.

  • Design and operate a scalable third-party risk management program that reflects the organization’s risk appetite, vendor criticality tiers, and evolving regulatory expectations.

  • Define and maintain clear criteria for vendor risk tiering, onboarding requirements, and ongoing monitoring cadences — ensuring continuous visibility into the risk profile of the extended enterprise.

  • Coordinate with procurement, legal, and technology teams to ensure vendor risk findings are reflected in contracting, remediation timelines, and relationship management decisions.

Controls Assurance & Obligation Validation
  • Validate and evidence the design and operational efficacy of policies, standards, controls, and guardrails related to risk management — translating governance intent into demonstrable operational outcomes.

  • Design and execute controls testing programs that provide reliable, audit-quality evidence of control effectiveness across the organization’s obligation landscape.

  • Develop and maintain structured assurance documentation that enables confident representation of risk posture to regulators, auditors, and enterprise customers.

  • Identify and elevate control design or operational gaps, working cross-functionally to drive timely and durable remediation.

Risk Issue Management & Remediation
  • Operate the organization’s risk issue management lifecycle, including maintenance of the risk issue inventory, escalation protocols, remediation prioritization frameworks, and exception management.

  • Define and apply clear standards for issue documentation, severity classification, ownership assignment, and remediation timelines — ensuring accountability and visibility at all levels.

  • Drive prioritization of remediation efforts in alignment with the organization’s risk appetite, ensuring that the most consequential exposures receive appropriate urgency and resources.

  • Manage the exception management process, including evaluation, approval, compensating control requirements, and time-bound tracking of all active exceptions.

  • Provide regular reporting to leadership on open issues, remediation velocity, exception inventory, and systemic risk trends, enabling informed decisions on risk tolerance and resource allocation.

What We're Looking For
Experience & Background
  • 7+ years of progressive experience in risk operations, compliance, internal audit, information security, or a closely related discipline, with a demonstrated track record as a hands-on practitioner and builder of operational risk programs.

  • Demonstrated track record of building and operating scalable risk operational programs: controls assurance, third-party risk management, issue management, or incident response.

  • Hands-on experience with commercial risk support functions, including the delivery of risk assessments, certifications, or security questionnaires in a go-to-market or enterprise sales context.

  • Prior experience in technology risk operations — with working knowledge of AI system risk evaluation, safety testing methodologies, and the operational lifecycle of AI models.

  • Experience operating in regulated environments and interacting directly with auditors, regulators, or enterprise customers on risk, compliance, or security topics.

Skills & Capabilities
  • Exceptional operational discipline — proven ability to design, document, and run repeatable, audit-quality risk management processes at scale.

  • Strong analytical and investigative skills, with the ability to triage complex risk issues, synthesize large volumes of evidence, and distinguish signal from noise.

  • Demonstrated ability to manage and report on multi-workstream operational programs, balancing competing priorities, tight timelines, and cross-functional dependencies.

  • Excellent written and verbal communication skills, including the ability to document risk findings clearly and represent the organization’s risk posture credibly in customer-facing and regulatory settings.

  • Proficiency in risk management tools and GRC platforms; familiarity with evidence management, controls testing workflows, and incident tracking systems.

Mindset & Approach
  • An operational risk practitioner who takes pride in building evidence-based, audit-ready risk programs — and understands that credibility is earned through the quality and consistency of execution, not just the elegance of frameworks.

  • Deeply collaborative and cross-functionally astute, with the ability to engage engineering, legal, product, and compliance stakeholders as a trusted partner rather than a compliance gatekeeper.

  • Calm and structured under pressure, with the judgment to triage and respond to fast-moving risk events — from safety incidents to regulatory inquiries — without sacrificing rigor.

  • Genuinely curious about AI and technology risk, and motivated to develop and maintain meaningful operational expertise in a domain that is evolving rapidly.

  • A builder at heart — energized by creating programs and processes where structure is still emerging, and committed to leaving operational infrastructure better than they found it.

What We Offer:

We believe that to make intelligence open and accessible to all, you need to start at the foundation. Joining Reflection means building from the ground up as part of a talent-dense team. You will help define our future as a company, and help define the future of open foundational models.

We want you to do the most impactful work of your career with the confidence that you and the people you care about most are supported.

  • Top-tier compensation: Salary and equity structured to recognize and retain our talent globally.

  • Stock options: Everyone who joins and contributes to Reflection's success gets to share in the upside through stock options.

  • Health & wellness: Comprehensive medical, dental, vision, and life, with an annual wellness allowance.

  • Meals: Lunch and dinner are provided in the office daily.

  • Life & family: 22 weeks paid parental leave for all new birthing and non-birthing parents, including adoptive and surrogate journeys.

  • Vacation days: Unlimited paid time off in the U.S. and 30 days in the U.K.

  • Sponsorship support: We sponsor visas to help exceptional talent join our team and support long-term immigration pathways where applicable.

  • Team building: We have regular off-sites, happy hours, and team celebrations.

Export Control Notice: This position may require access to technology or source code subject to the U.S. Export Administration Regulations. Any offer of employment for this role may be conditioned on the Company's ability to provide the candidate with access to such technology or source code in compliance with applicable U.S. export control laws, which may require the Company to seek government authorization.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Enterprise Risk Operations Specialist
Sr. Enterprise Risk Operations Specialist

Socket.dev • New York (NY)

On-site
USD 150,000 - 210,000
Top-tier compensation
Stock options
Health insurance
+5
Sr. Enterprise Risk Operations Specialist
Sr. Enterprise Risk Operations Specialist

Precision Labs • Northern (KY), New York (NY)

Hybrid
USD 160,000 - 210,000
Top-tier compensation
Stock options
Health & wellness
+3
Sr. Enterprise Risk Governance Specialist
Sr. Enterprise Risk Governance Specialist

Precision Labs • Northern (KY), New York (NY)

Hybrid
USD 120,000 - 180,000
Top-tier compensation
Stock options
Health & wellness
+5
Sr. Enterprise Risk Governance Specialist
Sr. Enterprise Risk Governance Specialist

Reflection • New York (NY)

On-site
USD 180,000 - 260,000
Top-tier compensation
Stock options
Health & wellness
+2
Sr. Enterprise Risk Governance Specialist
Sr. Enterprise Risk Governance Specialist

Socket.dev • New York (NY)

On-site
USD 150,000 - 210,000
MTS Lead, Product Security
MTS Lead, Product Security

Socket.dev • New York (NY)

On-site
USD 180,000 - 260,000
Stock options
Health & wellness benefits
Paid parental leave
Manager of Technology & Security Engineering
Manager of Technology & Security Engineering

Reflection AI • New York (NY)

On-site
USD 250,000 - 350,000
Top-tier compensation
Stock options
Comprehensive health benefits
+4
Sovereign Deal Lead
Sovereign Deal Lead

Reflection • San Francisco (CA)

On-site
USD 250,000 - 500,000
Top-tier compensation
Stock options
Health, dental, vision
+5
Member of Technical Staff - Research Software Engineer - Safety Evaluations Infrastructure
Member of Technical Staff - Research Software Engineer - Safety Evaluations Infrastructure

B Capital • San Francisco (CA)

On-site
USD 180,000 - 240,000
Top-tier compensation
Stock options
Health & wellness
+4
Sovereign Deal Lead
Sovereign Deal Lead

Reflection • New York (NY)

On-site
USD 350,000 - 600,000
Top-tier compensation
Stock options
Health & wellness
+5