VP, Generative AI Risk Oversight

SynchronyCincinnati, OH
$110,000 - $185,000Hybrid

About The Position

The Operational Risk Management team is part of the 2nd Line of Defense (2LOD) within Synchrony. The Risk Manager for AI, Generative AI, and Agentic AI is responsible for identifying, assessing and monitoring, risks arising from the design, development, deployment, and operation of AI-enabled capabilities. This role partners with the AI Solutions team to embed effective governance, controls, and assurance across the AI lifecycle.

Requirements

  • Bachelor’s degree in Risk Management, Information Systems, Computer Science, Data Science, Engineering, Mathematics/Statistics, Cybersecurity, or a related field (or equivalent practical experience).
  • 6+ years in technology risk, model risk management, information security risk, compliance, operational risk, or assurance roles in a regulated bank or financial institution.
  • 1+ years supporting AI/ML or data-driven systems (or demonstrably equivalent exposure) in a regulated bank or financial institution.
  • Working knowledge of supervised/unsupervised learning, evaluation metrics, overfitting, data leakage, bias/fairness concepts, drift, and monitoring. Understanding of failure modes ((hallucinations, prompt injection, data exfiltration, jailbreaks), RAG architecture basics)
  • Familiarity with AI agents that plan and use tools (APIs), including risks introduced by autonomy (goal misalignment, unsafe actions, cascading failures) and control patterns (scoped tools, approvals, sandboxing).
  • Demonstrated experience creating risk assessments, control frameworks, KRIs/KPIs, and remediation plans; ability to articulate risk in business terms and quantify impact/likelihood where possible.
  • Strong capability to produce clear governance documentation (policies, standards, procedures, risk assessments, controls) and present to senior stakeholders.
  • Evidence of ongoing learning in AI risk, security, privacy, and compliance (courses, workshops, internal enablement, or certifications).
  • Ability and flexibility to travel for business as required

Nice To Haves

  • Familiarity with information security and risk management concepts
  • Proven analytical skills with strong attention to detail and quality control of work product
  • Experience in financial services or banking industry with understanding of financial services regulatory environment
  • Competencies: Risk-based decision making; stakeholder management; technical literacy in AI/GenAI/Agentic AI; strong writing and policy craftsmanship; facilitation and influence; analytical thinking; incident and issue management; pragmatic control design.
  • Experience in IT operations and/or application support
  • Experience with data sourcing and reporting processes with ability to design and implement new analytical capabilities
  • Experience with Internal Audits and/or Regulatory Exams and preparing materials to respond to external inquiries providing evidence and rationales and reasoning for provided materials
  • IT Project management experience
  • Proven experience working in an ambiguous environment with proven ability to explain complex concepts and support points of view
  • Strong presentation and communication skills (written and oral) with proven experience interacting with all levels of the organization
  • Experience writing formal reports to Senior and Executive levels of Management
  • Excellent interpersonal skills - ability to foster relationships and create informal networks, both internal and external
  • Curiosity with the ability to learn new concepts

Responsibilities

  • Engage the Information Technology organization in reviewing and assessing AI risk management practices and controls for AI/GenAI/Agentic AI solutions, ensuring risks are understood, measured, and managed in alignment with business objectives and risk appetite.
  • Perform or oversee AI risk assessments (use case, model, vendor, and process), documenting inherent/residual risk, control effectiveness, and remediation plans.
  • Recommend guardrails for prompt/response safety, content moderation, jailbreak/prompt injection defenses, RAG data hygiene, retrieval security, and output verification.
  • Establish policies and technical controls for tool access, authorization, least privilege, action confirmation, rate limiting, sandboxing, memory management, and Human-in-the-Loop approval for high-impact actions.
  • Partner with Model Validation/Analytics teams to define validation expectations (performance, robustness, bias/fairness, explainability, drift) and ensure independent review where required.
  • Coordinate with Security and Privacy teams on data classification, access control, encryption, secrets management, secure SDLC, privacy-by-design for AI solutions.
  • Maintain alignment with relevant standards and regulations (as applicable) and ensure internal AI policies and procedures are current and auditable.
  • Conduct due diligence on AI vendors (foundation models, platforms, data providers) including security posture, data usage terms, IP considerations, and model transparency/documentation.
  • Oversee triage, containment, communications, and lessons learned.
  • Define and track AI risk metrics (e.g., safety events, policy violations, drift, override rates, hallucination indicators, agent action errors) and report insights to governance forums.
  • Deliver risk guidance and training to product and engineering teams; promote responsible AI practices and documentation discipline.
  • Ensure evidence collection, control testing support, and documentation standards to satisfy internal audit, regulators, and customer due diligence inquiries.
  • Perform formal assessments of technology risks using common processes within Risk Management, including Targeted Reviews, Concurrent Reviews and Continuous Monitoring
  • Monitor risks being accepted by the business and provide an independent assessment of the risk-taking activities
  • Attend and represent 2LOD at multiple Technology Strategic planning sessions including but not limited to: Responsible AI Working Group
  • Manage risks and issues within the Synchrony’s enterprise governance application (eGRC)
  • Perform other duties and/or special projects as assigned
  • Support 2nd Line of Defense processes such as the Enterprise Risk Assessment (ERA) and Risk and Control Self-Assessment (RCSA) processes

Benefits

  • eligible for an annual bonus based on individual and company performance
  • option to work from home near one of our Hubs or come into one of our offices
  • inclusive culture where your individual skills, experience, and voice are not only heard – but valued
  • community and passion intersect to offer a safe space to learn and grow
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service