Technology and AI Risk, Manager

jeffersonhealth

Pennsylvania

On-site

USD 150,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Jefferson Health seeks a Manager, Technology, AI, and Security Risk to lead the organization's Security Risk Assessment portfolio with hands-on technical and security architecture focus. You will review architectures, designs, and controls of internal applications, AI-enabled apps, APIs, cloud environments, and external connections to drive risk decisions.

You will own GRC components of the portfolio, including control framework management, regulatory assessments (HIPAA, NIST, PCI), external

Responsibilities

  • Lead security architecture reviews across internally developed applications, AI systems and agents, APIs, and cloud environments, assessing design, data flows, trust boundaries, and control coverage both before and after deployment.
  • Perform and oversee threat modeling and secure design reviews for custom-built and AI-enabled applications throughout the development lifecycle, identifying design-level weaknesses and driving fixes into engineering work.
  • Define the technical assessment approach for AI and machine learning systems, covering model and data governance, prompt and agent security, guardrails, output validation, and misuse scenarios.
  • Evaluate and validate security controls at the application, integration, and infrastructure layers, including authentication, authorization, encryption, logging, segmentation, and secrets management.
  • Own the Security Risk Assessment portfolio end to end, ensuring a consistent and technically rigorous methodology, prioritization, and reporting across control framework management, enterprise and regulatory assessments, external and third-party risk, cyber risk, issues management, and cloud posture.
  • Lead cloud security posture management, including configuration and hardening review, identity and access design, and asset and attack-surface visibility.
  • Assess third-party, medical device, and B2B integration risk with real attention to the technical interfaces, data exchange, and connectivity involved, not just questionnaire responses.
  • Maintain the cyber risk register and apply quantitative analysis to technical findings, translating architecture and control gaps into decision-ready risk.
  • Drive remediation of findings from architecture reviews, assessments, audits and testing through to validated technical closure.
  • Ensure applications and platforms meet information security policies, standards, and applicable regulatory frameworks (e.g., HIPAA, NIST, PCI), and inform updates to technical and secure-design standards as technology and threats evolve.
  • Partner with engineering, cloud, data, and AI teams to embed security into how systems operate.
  • Advance AI enablement across the team, applying AI-assisted automation to assessment, architecture review, and reporting workflows to strengthen efficiency gains and scale the portfolio's output.

Skills

Security architecture
Threat modeling
AI risk
Cloud security
Regulatory compliance
HIPAA compliance
NIST/PCI standards

Job description

Number of Positions In Requisition 1

Job Details

The Manager, Technology, AI, and Security Risk leads the organization's Security Risk Assessment portfolio with a hands‑on technical and security architecture focus. The role is accountable for reviewing the architecture, design, and controls of internally developed applications, AI‑enabled applications and agents, APIs and integrations, cloud environments, and external connections, and for turning those technical findings into clear, prioritized risk decisions. Alongside this technical work, the manager owns the broader Governance, Risk, and Compliance (GRC) components of the portfolio, including control framework management, enterprise and regulatory assessments, external and third‑party risk, cyber risk management, issues management, and cloud security and posture management, as well as the GRC platform and its AI‑enablement capabilities. The position exists to ensure that as the organization expands its internal development and adoption of AI, it designs, builds, and operates those systems securely and in line with applicable legal and regulatory requirements.

Job Description
Summary

The Manager, Technology, AI, and Security Risk leads the organization's Security Risk Assessment portfolio with a hands‑on technical and security architecture focus. The role is accountable for reviewing the architecture, design, and controls of internally developed applications, AI‑enabled applications and agents, APIs and integrations, cloud environments, and external connections, and for turning those technical findings into clear, prioritized risk decisions. Alongside this technical work, the manager owns the broader Governance, Risk, and Compliance (GRC) components of the portfolio, including control framework management, enterprise and regulatory assessments, external and third‑party risk, cyber risk management, issues management, and cloud security and posture management, as well as the GRC platform and its AI‑enablement capabilities. The position exists to ensure that as the organization expands its internal development and adoption of AI, it designs, builds, and operates those systems securely and in line with applicable legal and regulatory requirements.

Job Duties
  • Lead security architecture reviews across internally developed applications, AI systems and agents, APIs, and cloud environments, assessing design, data flows, trust boundaries, and control coverage both before and after deployment.
  • Perform and oversee threat modeling and secure design reviews for custom‑built and AI‑enabled applications throughout the development lifecycle, identifying design‑level weaknesses and driving fixes into engineering work.
  • Define the technical assessment approach for AI and machine learning systems, covering model and data governance, prompt and agent security, guardrails, output validation, and misuse scenarios.
  • Evaluate and validate security controls at the application, integration, and infrastructure layers, including authentication, authorization, encryption, logging, segmentation, and secrets management.
  • Own the Security Risk Assessment portfolio end to end, ensuring a consistent and technically rigorous methodology, prioritization, and reporting across control framework management, enterprise and regulatory assessments, external and third‑party risk, cyber risk, issues management, and cloud posture.
  • Lead cloud security posture management, including configuration and hardening review, identity and access design, and asset and attack‑surface visibility.
  • Assess third‑party, medical device, and B2B integration risk with real attention to the technical interfaces, data exchange, and connectivity involved, not just questionnaire responses.
  • Maintain the cyber risk register and apply quantitative analysis to technical findings, translating architecture and control gaps into decision‑ready risk.
  • Drive remediation of findings from architecture reviews, assessments, audits and testing through to validated technical closure.
  • Ensure applications and platforms meet information security policies, standards, and applicable regulatory frameworks (e.g., HIPAA, NIST, PCI), and inform updates to technical and secure‑design standards as technology and threats evolve.
  • Partner with engineering, cloud, data, and AI teams to embed security into how systems . . .
  • Advance AI enablement across the team, applying AI‑assisted automation to assessment, architecture review, and reporting workflows to strengthen efficiency gains and scale the portfolio's output.
ORGANIZATIONAL IMPACT

Establishes and works to implement key elements of tactical and operational plans with measurable contribution towards the achievement of results of the job area or completion of a project. Makes significant decisions on what their team of responsibility focuses on or executes as directed. Focus is on short‑term operational plans (e.g.,

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Tech Risk & Controls Lead
AI Tech Risk & Controls Lead

JPMorgan Chase & Co. • Palo Alto (CA)

On-site
USD 180,000 - 240,000
Director – AI Security Product Manager
Director – AI Security Product Manager

Jobtailor • Town of Florida (NY)

On-site
USD 140,000 - 200,000
Program Manager, Security Risk Program
Program Manager, Security Risk Program

Meta • Menlo Park (CA)

On-site
USD 190,000 - 260,000
AI Solutions Engineer
AI Solutions Engineer

Socket.dev • Atlanta (GA)

On-site
USD 120,000 - 190,000
VP – AI Security and Data Protection Governance and Controls
VP – AI Security and Data Protection Governance and Controls

Jobtailor • United States

On-site
USD 180,000 - 280,000
Info Security Architect – AI
Info Security Architect – AI

Jobtailor • Webster (MA)

On-site
USD 140,000 - 190,000
IT - AI Platform Manager
IT - AI Platform Manager

Standard Motor Products • Lewisville (TX)

On-site
USD 180,000 - 240,000
Sr Data Architect - AI Controls, Governance & Capabilities
Sr Data Architect - AI Controls, Governance & Capabilities

Bank of America • Charlotte (NC)

On-site
USD 150,000 - 210,000
Technical AI Risk & Security Leader
Technical AI Risk & Security Leader

Jefferson Health • Washington, Northern (KY)

Hybrid
USD 120,000 - 165,000
Manager of Technology, Security & AI
Manager of Technology, Security & AI

Amplify HR Management • Northbrook (IL)

Hybrid
USD 130,000 - 150,000