Jobs and Careers
DT

AI Cyber Risk and Credible Challenge Associate Director

DTCC
United Statesfull_timeVerifiedPosted 19 Aug 2026

About the role

Are you ready to make an impact at DTCC?  

Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets.  We're committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact.  We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.

Pay and Benefits:

  • Competitive compensation, including base pay and annual incentive
  • Comprehensive health and life insurance and well-being benefits, based on location
  • Pension / Retirement benefits 
  • Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
  • DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee). 

The Impact You will have in this role:

In this role, you will play a key part in executing the Credible Challenge assessment program within the Cyber Security Risk Office (CSRO), with a specialized focus on AI risk oversight across the AI lifecycle. Your work will directly contribute to strengthening DTCC’s cyber risk governance by independently assessing First Line functions and evaluating the design and effectiveness of controls.
You will work closely with CSRO leadership, assessment leads, and First Line stakeholders to perform structured assessments, analyze evidence, identify risks and control gaps, and support clear, defensible assessment conclusions.

Your Primary Responsibilities:

  • Lead and execute Credible Challenge assessments of First Line AI risk practices across the AI lifecycle, including planning, scoping, fieldwork, and documentation
  • Perform walkthroughs, interviews, and evidence reviews to assess the design and operating effectiveness of controls governing AI use cases (including GenAI, agentic workflows, and embedded AI)
  • Evaluate alignment of First Line AI practices to the AI Policy, AI Governance Procedure, AI Acceptable Usage Policy, and applicable frameworks (NIST AI RMF, CRI Profile, EU AI Act)
  • Represent CSRO on the AI Working Groups, conducting independent AI use case reviews and applying the AI risk tiering framework to scale challenge intensity to data exposure, automation, and business impact
  • Identify, assess, and communicate material AI risks, control gaps, and thematic issues across cyber, model, data, privacy, and third-party risk domains
  • Engage with senior CSRO and First Line stakeholders to discuss assessment results and remediation of AI control deficiencies
  • Contribute to continuous improvement of the Credible Challenge methodology, standards, and templates as applied to the AI domain
  • Support AI policy awareness and acceptable-usage training, and assist with regulatory and audit responses on AI (e.g., Reg SCI, FRBNY/SEC inquiries)
  • Lead and contribute to special projects including program enhancements, resource coordination, and senior management presentations
  • Develop, communicate and ensure adherence to department risk policies, procedures and best practices
  • Stay abreast of industry and market events that impact cyber risk management processes
  • Foster an environment of regulatory awareness and ensure regulatory compliance
  • Conduct periodic assessments and surveys to gauge DTCC's AI risk and acceptable usage awareness level and recommend adjustments to the program

**NOTE:  The Primary Responsibilities of this role are not limited to the details above. **

Qualifications:

  • Minimum of 8 years of related experience in cyber security, cyber operations, cyber risk, IT audit, or technology risk.
  • Cyber security risk background with working knowledge of AI/GenAI risk domains (prompt injection, model drift, hallucination, data leakage, shadow AI)
  • Bachelor's degree preferred or equivalent experience
  • Professional certifications such as CISSP, CISA, CRISC or equivalent are a plus
  • Knowledge of frameworks and regulations, including Cyber Risk Institute (CRI), National Institute of Standards and Technology (NIST) Cybers

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

DTCC

View company profile →