Risk Lead, IT Risk Management

Cisco•San Jose, NC
•Remote

About The Position

The application window is expected to close on: 10/15/2026. The role is listed as remote and can be performed from anywhere in the US. NOTE: Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received. Meet the Team: Commerce Engineering Productivity & Platforms (CEP&P) is a fast paced, multifaceted engineering organization that adapts quickly to changing business and technology needs. We are launching IT Risk Management (ITRM) to support all of Cisco AI + IT with real-time risk insight, resilience testing, and closed-loop remediation. CEP&P brings together shared-service functions that enable teams across Cisco. You’ll work with some of Cisco’s most cutting-edge engineers and technical leaders as we invent how AI-native delivery changes the way we build, operate, and manage risk. Your Impact: You will lead ITRM as an expert practitioner at the leading edge of AI-enabled risk management. You will define the standard and methodology, use AI and agentic tools to turn fragmented signals into risk intelligence, and build the assurance model that tests resilience, control effectiveness, and AI safeguards. You will guide where AI can safely detect, prioritize, act, test, and verify; challenge disaster-recovery capability with evidence rather than accepting plans at face value; and ensure the organization confirms that remediation held. This role combines deep risk expertise with hands-on proficiency in AI, agents, automation, telemetry, and the systems that make closed-loop remediation possible.

Requirements

  • 12+ years of experience in IT risk, GRC, audit, control assurance, or technology risk program management.
  • Experience establishing a common risk framework, taxonomy or scoring method, enterprise risk register, and recurring executive review cadence.
  • Experience partnering with executive team members and domain owners to define RACI, escalation paths, risk acceptance, and decision rights.
  • Experience working across at least two of the following domains: SOX or control assurance, vulnerability management, lifecycle management, business continuity or disaster recovery, application resiliency, CMMC, or GRC or audit.

Nice To Haves

  • Bachelor’s degree or equivalent experience in Information Systems, Risk Management, Computer Science, Business, or a related field.
  • Demonstrated experience applying AI, agentic workflows, automation, or sophisticated analytics to technology risk, security, resilience, control assurance, or operations, including guardrails and human-in-the-loop review.
  • Experience leading evidence-based resilience, control-effectiveness, or AI lifecycle testing as systems, models, data, and dependencies evolve.
  • Experience connecting fragmented risk or compliance programs into a common operating model while leaving domain risks and remediation execution with the teams that own them.
  • Experience building closed-loop risk management with named owners, action tracking, verified closure, and measures such as automation coverage, signal-to-action time, or repeat-risk reduction.
  • Fosters candid communication and balanced debate.
  • Acknowledges all perspectives and drives consensus on decisions that improve business outcomes.

Responsibilities

  • Own the ITRM standard and methodology: risk sensing, aggregation, prioritization, risk appetite, taxonomy, thresholds, and common methods.
  • Lead the AI-enabled risk intelligence model. Define how sub-agents use signals from across AI + IT to prioritize exposure by business impact and support real-time leadership insight.
  • Define the assurance model for critical service outcomes, failure tolerances, resilience, control effectiveness, and AI lifecycle safeguards.
  • Challenge disaster-recovery capability through evidence-based tests of objectives, dependencies, and recovery procedures.
  • Operate the closed-loop model through named owners, action tracking, risk acceptance and escalation paths, and verification that risk reduction actually occurred.
  • Feed incidents, test results, and lessons back into standards and design.
  • Provide technical thought leadership on AI-enabled risk management.
  • Partner with the Software Engineer and leaders across AI + IT, STO, Finance, Security, Compliance, and Resiliency to set guardrails, evaluate agent behavior, enable automation and telemetry, and preserve domain ownership of risk decisions and remediation execution.

Benefits

  • medical, dental and vision insurance
  • a 401(k) plan with a Cisco matching contribution
  • paid parental leave
  • short and long-term disability coverage
  • basic life insurance
  • 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees
  • 1 paid day off for employee’s birthday
  • paid year-end holiday shutdown
  • 4 paid days off for personal wellness determined by Cisco
  • 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees (non-exempt)
  • flexible vacation time off program (exempt)
  • 80 hours of sick time off provided on hire date and each January 1st thereafter
  • up to 80 hours of unused sick time carried forward from one calendar year to the next
  • Additional paid time away may be requested to deal with critical or emergency issues for family members
  • Optional 10 paid days per full calendar year to volunteer
  • annual bonuses
  • performance-based incentive pay
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service