VP, Generative AI Risk Oversight
Synchrony · West Chester, OH · 2 days ago
FinanceFull-time
Essential Responsibilities
- Engage the Information Technology organization in reviewing and assessing AI risk management practices and controls for AI/GenAI/Agentic AI solutions, ensuring risks are understood, measured, and managed in alignment with business objectives and risk appetite.
- Risk assessment and control design: Perform or oversee AI risk assessments (use case, model, vendor, and process), documenting inherent/residual risk, control effectiveness, and remediation plans.
- GenAI and LLM risk controls: Recommend guardrails for prompt/response safety, content moderation, jailbreak/prompt injection defenses, RAG data hygiene, retrieval security, and output verification.
- Agentic AI controls: Establish policies and technical controls for tool access, authorization, least privilege, action confirmation, rate limiting, sandboxing, memory management, and Human-in-the-Loop approval for high-impact actions.
- Model risk management: Partner with Model Validation/Analytics teams to define validation expectations (performance, robustness, bias/fairness, explainability, drift) and ensure independent review where required.
- Security and privacy alignment: Coordinate with Security and Privacy teams on data classification, access control, encryption, secrets management, secure SDLC, privacy-by-design for AI solutions.
- Regulatory and policy alignment: Maintain alignment with relevant standards and regulations (as applicable) and ensure internal AI policies and procedures are current and auditable.
- Third-party and vendor risk: Conduct due diligence on AI vendors (foundation models, platforms, data providers) including security posture, data usage terms, IP considerations, and model transparency/documentation.
- Incident response and issue management: Oversee triage, containment, communications, and lessons learned.
- Monitoring and KRIs: Define and track AI risk metrics (e.g., safety events, policy violations, drift, override rates, hallucination indicators, agent action errors) and report insights to governance forums.
- Training and enablement: Deliver risk guidance and training to product and engineering teams; promote responsible AI practices and documentation discipline.
- Audit readiness: Ensure evidence collection, control testing support, and documentation standards to satisfy internal audit, regulators, and customer due diligence inquiries.
- Perform formal assessments of technology risks using common processes within Risk Management, including Targeted Reviews, Concurrent Reviews and Continuous Monitoring.
- Monitor risks being accepted by the business and provide an independent assessment of the risk-taking activities.
- Attend and represent 2LOD at multiple Technology Strategic planning sessions including but not limited to: Responsible AI Working Group.
- Manage risks and issues within the Synchrony’s enterprise governance application (eGRC).
- Perform other duties and/or special projects as assigned.
- Support 2nd Line of Defense processes such as the Enterprise Risk Assessment (ERA) and Risk and Control Self-Assessment (RCSA) processes.
Qualifications/Requirements
- Bachelor’s degree in Risk Management, Information Systems, Computer Science, Data Science, Engineering, Mathematics/Statistics, Cybersecurity, or a related field (or equivalent practical experience).
- 6+ years in technology risk, model risk management, information security risk, compliance, operational risk, or assurance roles in a regulated bank or financial institution.
- 1+ years supporting AI/ML or data-driven systems (or demonstrably equivalent exposure) in a regulated bank or financial institution.
- Working knowledge of supervised/unsupervised learning, evaluation metrics, overfitting, data leakage, bias/fairness concepts, drift, and monitoring.
- Familiarity with AI agents that plan and use tools (APIs), including risks introduced by autonomy (goal misalignment, unsafe actions, cascading failures) and control patterns (scoped tools, approvals, sandboxing).
- Demonstrated experience creating risk assessments, control frameworks, KRIs/KPIs, and remediation plans; ability to articulate risk in business terms and quantify impact/likelihood where possible.
- Strong capability to produce clear governance documentation (policies, standards, procedures, risk assessments, controls) and present to senior stakeholders.
- Evidence of ongoing learning in AI risk, security, privacy, and compliance (courses, workshops, internal enablement, or certifications).
- Ability and flexibility to travel for business as required.