Role: Senior/Lead AI Governance Engineer
Location: Remote or (Buffalo, NY or Wilmington, DE (the first 2 – 4 weeks onsite, then remote US))
Responsibilities:
· Standards & Controls Engineering
· Draft and iterate the AI standards library under the Lead''s direction: model onboarding and approval, oversight tiers, logging/retention, agentic guardrails, data-classification handling, and acceptable use.
· Engineer each control as a testable requirement: definition, enforcement point, owner, evidence artifact, and validation method.
· Build and maintain obligation-to-control-to-evidence mappings against regulatory guidance and internal policy.
· Contribute to policy-as-code and controls-automation approaches with the platform team where controls can be enforced or checked mechanically.
· Evidence & Assessment Production
· Produce evidence artifacts, control attestations, and assessment documentation for deviations, exceptions, and governance reviews.
· Validate platform-generated evidence (audit logs, entitlement records, quota enforcement) against control requirements; document gaps and drive fixes.
· Support deviation and exception lifecycle management: drafting, compensating-control documentation, tracking, and closure evidence.
· Assemble components of examiner-readiness and audit-response packages.
· Governance Operations Support
· Support AI Control Group, working group, and committee operations with prepared materials, assessments, and documented decisions.
· Maintain the AI use case and agent registry data quality in partnership with intake and platform onboarding.
· Document governance processes, runbooks, and templates in repositories for FTE handover.
· Transfer working knowledge to FTEs throughout the engagement.
Mandatory Skills Description:
· Minimum of 5 years'' experience in technology governance, IT risk/controls, security governance engineering, or compliance engineering in a technology environment.
· Demonstrated experience writing technical standards, control frameworks, or control documentation that maps to regulatory or policy obligations.
· Working technical knowledge of cloud platforms and modern application patterns: APIs and gateways, identity/RBAC, logging and monitoring, environment separation.
· Familiarity with AI/GenAI systems sufficient to write accurate, enforceable requirements for model access, oversight, and logging.
· Strong technical writing and documentation discipline; able to produce artifacts that survive audit and second-line challenge.
· Experience with GRC processes: exceptions, findings, evidence collection, and remediation tracking.
Nice-to-Have Skills Description:
· Financial services or other highly regulated industry experience; familiarity with model risk management concepts.
· Experience with policy-as-code, compliance automation, or controls testing automation.
· Familiarity with NIST AI RMF, SR 11-7/SR 26-2 lineage, or comparable AI governance frameworks.
· Azure experience (APIM, Entra ID, Azure Monitor, Key Vault)