Senior Risk Manager – Digital Strategy & Enterprise Automation (Commercial Bank)
CitizensAbout the role
As a Senior Risk Manager in the First Line of Defense, you will play a pivotal role in managing risks across digital banking platforms and emerging technologies—including AI and intelligent automation. You’ll serve as a trusted advisor to business partners, helping to ensure innovation is delivered safely, to scale, and in alignment with regulatory expectations.
You’ll lead complex risk assessments, assess control frameworks, and monitor the effectiveness of controls across AI and automation initiatives. This role also supports governance processes, change management, and pilot oversight, while driving continuous improvement through automation and AI-enabled risk solutions.
You’ll also partner with relevant groups such as; Sourcing, Privacy, Legal, InfoSec, and Third Party Risk Management (TPRM) to assess third‑party vendor risks, ensuring contracts, SLAs, and control obligations provide sufficient coverage for AI, GenAI, Agentic AI, and automation risks—including data handling, model governance, operational resilience, and regulatory compliance requirements.
Your key responsibilities will include:
Lead risk identification, assessment, and mitigation for digital platforms and emerging technologies (AI, GenAI, Agentic AI & automation).
Develop and maintain control frameworks for AI and automation use cases.
Partner with business and tech teams to ensure operational and technical resiliency.
Oversee risk governance activities: change control, control testing, and RCSAs.
Provide regulatory guidance (e.g., OCC, FRB, GLBA, NIST) across digital initiatives.
Collaborate with Second and Third Lines of Defense to maintain transparency and alignment.
Support pilot programs and new product launches by assessing risk exposure and recommending mitigations.
Serve as a subject matter expert on AI governance, ethical use, and risk mitigation.
Key Skills and Qualifications:
- Strong Knowledge of Risk Management Principles: A solid understanding of various risk types (e.g., operational, financial, compliance, reputational) and risk management methodologies, including COSO and OCC Heightened Standards.
- Technology and Cybersecurity Risk Management: Focus on identifying and mitigating risks associated with the adoption and integration of AI, GenAI, Agentic AI, and automation technologies within digital banking platforms. Collaborate with technical teams to ensure the security, stability, and operational resilience of AI-enabled systems, including core banking infrastructure and intelligent payment applications. Evaluate emerging technology risks such as model drift, adversarial AI threats, and data integrity vulnerabilities. Maintain awareness of evolving cybersecurity threats and regulatory expectations, and implement proactive controls and monitoring strategies to safeguard against technology-driven disruptions and ensure compliance with frameworks such as SR 11-7, FFIEC, and NIST
- Third Party Risk Management: Ensure that all third-party providers involved in the development, deployment, or support of AI, GenAI, Agentic AI, and automation solutions are identified and integrated into the Bank’s Third-Party Risk Management (TPRM) program. Confirm that due diligence activities both onboarding and through ongoing monitoring—are conducted in accordance with policy requirements, with a specific focus on evaluating contact language, model governance, data handling practices, algorithmic transparency, and compliance with regulatory expectations such as SR 11-7, NIST AI RMF, and FFIEC guidance.
- Risk Assessment Skills: The ability to manage and execute risk assessments on new business initiatives and implement new and / or revised controls to applicable product and service risk inventories. Experience in establishing risk and control inventories and executing an annual and or ad hoc targeted risk and control self-assessment on a product and service inventory.
- AI, GenAI, and Automation Solutions: Foundational knowledge of AI, Generative AI (GenAI), Agentic AI, and automation solutions within enterprise environments, including their application in streamlining operations, enhancing decision-making, and enabling intelligent workflows. This includes an understanding of embedded AI use cases across various business functions and how the risk landscape evolves with the adoption of AI-driven architectures and automated process flows.
- Data & Privacy Risk Oversight: Knowledge of data management, data protection, and privacy requirements—including GDPR, CCPA, and GLBA—and their implications on AI and automation architectures. Skilled in assessing data quality, lineage, classification, access controls, and the handling of s
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s