Lead Risk Engineer

College BoardRemote - Virginia, VA
$168,000 - $183,000Remote

About The Position

College Board’s Enterprise Security Engineering (ESE) team is responsible for implementing and managing cutting-edge security solutions and tools to protect the confidentiality, integrity, and availability of data and endpoints across physical and cloud environments. This role will provide technical leadership for how College Board identifies, reviews, and manages risk across its technology systems, which span cloud infrastructure, vendor and API integrations, identity and access for automated systems, and AI and agentic capabilities. The Lead Risk Engineer will build and lead a consistent, repeatable practice for assessing risk across all technology systems. The role involves working within an existing security engineering team and across the Technology division to run risk reviews, define controls and identity practices for automated and machine-driven access, and partner with stakeholders to integrate security early in decision-making. This individual will shape standards, patterns, and practices, and mentor other engineers. The role requires operating across team and service boundaries, spanning risk domains like cloud and vendor risk, identity and access for automated systems, and emerging technologies such as agentic AI. The Lead Risk Engineer will contribute to the strategic direction of the risk engineering program, identify risks and opportunities influencing roadmap decisions, and remain hands-on in reviews, threat modeling, and control design. The impact will be measured in repeatable and evidenced reviews, owned and documented risk, and early stakeholder engagement with security due to practical and predictable processes.

Requirements

  • 8+ years in security engineering, application security, cloud security, or security architecture, including demonstrated technical leadership of work that crosses team and service boundaries.
  • Deep, practical expertise in at least two relevant technical areas — for example: cloud security architecture, identity and access management (including non-human/service identities), application security, vendor/third-party risk, or AI/GenAI application security.
  • Experience designing identity and access controls for service accounts, API credentials, or machine identities, and applying least-privilege principles in automated systems.
  • Experience running or contributing to risk-based security reviews of technology implementations, including assessing architecture, data flows, and misuse scenarios; exposure to AI/GenAI or agentic systems is a plus but not required.
  • A track record of turning ambiguous, emerging risk domains into documented standards, repeatable processes, and adoptable guidance.
  • Demonstrated ability to work through others: mentoring engineers, sharing knowledge deliberately, and lifting the capability of a team rather than concentrating expertise.
  • Strong stakeholder skills — building relationships with product, platform, legal, procurement, and governance partners, and presenting risk tradeoffs to technical and non-technical audiences.
  • Comfort operating where standards, tooling, and regulatory expectations are still evolving (e.g., FERPA and student data privacy obligations, and emerging AI governance frameworks).
  • Ability to travel 3–5 times per year to College Board offices.
  • Authorization to work in the United States for any employer
  • A passion for expanding educational and career opportunities and mission-driven work
  • Curiosity and enthusiasm for emerging technologies, with a willingness to experiment with and adopt new AI-driven solutions and a comfort learning and applying new digital tools independently and proactively
  • Clear and concise communication skills, written and verbal
  • A learner's mindset and a commitment to growth: welcoming diverse perspectives, giving and receiving timely, respectful feedback, and continuously improving through iterative learning and user input
  • A drive for impact and excellence: solving complex problems, making data-informed decisions, prioritizing what matters most, and continuously improving through learning, user input, and external benchmarking
  • A collaborative and empathetic approach: working across differences, fostering trust, and contributing to a culture of shared success

Nice To Haves

  • Exposure to AI/GenAI or agentic systems is a plus but not required.

Responsibilities

  • Lead operational risk reviews and delivery enablement (45%)
  • Lead risk-based security reviews of technology implementations across domains — including cloud architecture, application security, vendor/third-party integrations, identity and access, and emerging technologies such as GenAI and agentic AI systems — assessing architectures, data flows, data classification handling, and misuse scenarios.
  • Evolve the risk review practice into a documented, repeatable methodology with risk tiering, reusable templates, decision records, and findings tracking.
  • Define and maintain secure-by-default standards, patterns, and reference guidance that reduce review friction and enable delivery teams to meet expectations on the first pass.
  • Cross team and service boundaries to unblock delivery — translating risk and governance requirements into practical implementation steps that fit Agile delivery, and anticipating risks before they become launch blockers.
  • Where systems involve automated or autonomous behavior (e.g., AI agents, service accounts, machine identities), assess and document ownership, credential scope, and control requirements as part of the standard review.
  • Drive cross-organizational risk alignment (30%)
  • Serve as a primary security/risk partner to organization-level teams and governance bodies — including teams driving responsible AI use, such as GenAI Studio and the GenAI Governance Committee, as well as platform, procurement, and legal stakeholders — establishing recurring consultation touchpoints and pre-procurement engagement.
  • Embed risk requirements into tool onboarding, procurement, and vendor contract processes (e.g., data handling, retention and no-train terms, telemetry expectations, identity and access provisions).
  • Identify emerging or higher-uncertainty risk areas early — including agentic AI, non-human identities, and new integration patterns — and bring them into the standard review process rather than handling them ad hoc.
  • Build program maturity and grow the team (25%)
  • Define risk acceptance criteria, control requirements, and escalation thresholds; ratify them through appropriate governance bodies and apply them consistently across use cases entering production.
  • Mentor engineers on risk review practices through paired reviews, documentation, and teaching; ensure knowledge is shared and no capability depends on a single person.
  • Contribute to defining the strategic direction of the risk engineering program — synthesizing findings from real implementations into roadmap priorities, and producing leadership reporting on risk posture and program outcomes.

Benefits

  • Meaningful career
  • Supportive team
  • Comprehensive package designed to help you thrive
  • Fair and competitive compensation
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service