Technology and AI Risk, Manager

Jefferson Health Plans1100 Virginia Drive, PA
Onsite

About The Position

The Manager, Technology, AI, and Security Risk leads the organization's Security Risk Assessment portfolio with a hands-on technical and security architecture focus. The role is accountable for reviewing the architecture, design, and controls of internally developed applications, AI-enabled applications and agents, APIs and integrations, cloud environments, and external connections, and for turning those technical findings into clear, prioritized risk decisions. Alongside this technical work, the manager owns the broader Governance, Risk, and Compliance (GRC) components of the portfolio, including control framework management, enterprise and regulatory assessments, external and third-party risk, cyber risk management, issues management, and cloud security and posture management, as well as the GRC platform and its AI-enablement capabilities. The position exists to ensure that as the organization expands its internal development and adoption of AI, it designs, builds, and operates those systems securely and in line with applicable legal and regulatory requirements.

Requirements

  • Bachelor’s Degree in science, technology, engineering, or math discipline
  • 7 years related work experience

Responsibilities

  • Lead security architecture reviews across internally developed applications, AI systems and agents, APIs, and cloud environments, assessing design, data flows, trust boundaries, and control coverage both before and after deployment.
  • Perform and oversee threat modeling and secure design reviews for custom-built and AI-enabled applications throughout the development lifecycle, identifying design-level weaknesses and driving fixes into engineering work.
  • Define the technical assessment approach for AI and machine learning systems, covering model and data governance, prompt and agent security, guardrails, output validation, and misuse scenarios.
  • Evaluate and validate security controls at the application, integration, and infrastructure layers, including authentication, authorization, encryption, logging, segmentation, and secrets management.
  • Own the Security Risk Assessment portfolio end to end, ensuring a consistent and technically rigorous methodology, prioritization, and reporting across control framework management, enterprise and regulatory assessments, external and third-party risk, cyber risk, issues management, and cloud posture.
  • Lead cloud security posture management, including configuration and hardening review, identity and access design, and asset and attack-surface visibility.
  • Assess third-party, medical device, and B2B integration risk with real attention to the technical interfaces, data exchange, and connectivity involved, not just questionnaire responses.
  • Maintain the cyber risk register and apply quantitative analysis to technical findings, translating architecture and control gaps into decision-ready risk.
  • Drive remediation of findings from architecture reviews, assessments, audits, and testing through to validated technical closure.
  • Ensure applications and platforms meet information security policies, standards, and applicable regulatory frameworks (e.g., HIPAA, NIST, PCI), and inform updates to technical and secure-design standards as technology and threats evolve.
  • Partner with engineering, cloud, data, and AI teams to embed security into how systems are designed, built, and run, advancing internal development and AI enablement securely.
  • Advance AI enablement across the team, applying AI-assisted automation to assessment, architecture review, and reporting workflows to strengthen efficiency gains and scale the portfolio's output.

Benefits

  • medical (including prescription)
  • supplemental insurance
  • dental
  • vision
  • life and AD&D insurance
  • short- and long-term disability
  • flexible spending accounts
  • retirement plans
  • tuition assistance
  • voluntary benefits
  • tuition discounts at Thomas Jefferson University after one year of full time service or two years of part time service
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service