Director, Data & AI Risk Management

Haag, a Salas O'Brien Company,
$215,000 - $245,000Remote

About The Position

The Data and AI Risk Management Director will lead Salas O'Brien's approach to responsible data and AI use. This role will develop practical governance standards, guide review of AI use cases, maintain visibility into tools and models in use, and help teams move quickly while meeting regulatory, client, and security expectations. The goal of this role is to help the firm adopt data and AI tools responsibly, with governance that is clear, practical, and easy for employees to follow. You will build controls that work in practice, assign clear ownership, and create the documentation needed for client, audit, and regulatory review. This is a hands-on build-and-run role. You will help mature the firm's data and AI governance program, improve the inventory of tools and use cases, and prepare the organization for expanding regulatory and controlled-data obligations as Salas O'Brien continues to grow.

Requirements

  • You have helped build or significantly mature a governance program, and you understand the difference between a written control and one that works in practice.
  • You are technical enough to review a model card, an architecture diagram, and a data flow without needing them translated.
  • You can write policy that a working engineer will follow, and a one-page explanation that a project manager will read.
  • You can navigate senior stakeholder conversations with sound judgment, clear recommendations, and a bias toward finding a responsible path forward when one is available.
  • You maintain clear records because strong documentation supports good decisions, efficient reviews, and audit readiness.
  • Twelve or more years in risk management, governance, compliance, audit, or a closely related discipline, with substantial focus on data, analytics, or artificial intelligence.
  • Demonstrated experience developing and implementing policies, standards, and procedures that meet legal, audit, regulatory, or client expectations.
  • Working command of model risk management practice, including inventory, validation, monitoring, and documentation expectations.
  • Experience mapping regulatory and contractual obligations to operating controls under frameworks such as NIST, ISO, or an equivalent, and maintaining the traceability.
  • Experience running a governance committee, including agenda control, quorum management, decision records, and escalation.
  • Experience with evidence and audit readiness, including sampling, control testing, and remediation tracking.
  • Familiarity with AI-specific risk domains, including data leakage, prompt injection, model drift, intellectual property exposure, and third-party model terms.
  • Bachelor's degree in relevant discipline, or equivalent experience.
  • Strong written communication skills, with the ability to write both a standard and its plain-language summary.

Nice To Haves

  • Professional certification such as CIPP, CISA, CRISC, CISM, or an equivalent.
  • Legal or regulatory training, including experience working directly with outside counsel on AI and data terms.
  • Experience with data governance tooling and catalog-based policy enforcement, including Unity Catalog or a comparable capability.
  • Experience supporting governance integration during acquisitions, including assessing inherited tools, practices, controls, and risk areas.

Responsibilities

  • Develop, maintain, and improve data and AI policies, standards, procedures, and implementation guidance so they remain practical, current, and aligned with evolving technology and regulatory requirements.
  • Lead the Data and AI Risk Management Committee by setting agendas, guiding policy and risk decisions, documenting outcomes, and escalating key matters to senior leadership when needed.
  • Help define and apply the firm's risk expectations for frontier models, data privacy, and security so teams understand what is acceptable, what requires review, and when additional safeguards are needed.
  • Manage AI use-case intake against clear service levels by assessing requests, approving or conditioning use where appropriate, declining requests when needed, and explaining decisions in plain language.
  • Maintain a complete inventory of models, agents, and AI-enabled tools in use, including those acquired through vendors and through acquisitions.
  • Ensure each control has a clear owner, defined evidence, and a review cadence, and confirm that evidence is available before it is needed for client, audit, or regulatory review.
  • Maintain a practical view of key regulatory, contractual, and client requirements, and help translate them into controls the business can understand and use.
  • Review third-party AI tools and vendors before adoption, maintain the approved tool list, and keep it visible to employees who need a fast answer.
  • Manage exceptions using clear criteria, defined timelines, documented decisions, and follow-through to resolution.
  • Partner with communications, training, and other stakeholders to translate policy requirements into plain-language guidance, training, and resources employees can use.

Benefits

  • Medical, dental, and vision insurance
  • 401(k) with company match
  • Paid time off and company holidays
  • Wellness programs and employee assistance resources
  • Professional development support
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service