Technology Risk Senior Analyst- Data, AI and Emerging Technology
Role Overview
The Data, AI and Emerging Technology Risk Senior Analyst will support first-line technology risk oversight for customized data platforms, data engineering enablement, and emerging AI/ML enablement capabilities. This role is designed as a low-to-no-code governance and oversight position focused on identifying, assessing, documenting, and helping mitigate technology, data, security, stability, third-party, and AI-related risks across hybrid-cloud and on-premises environments. The analyst will partner directly with engineering, data, API, BI, AI/ML, and risk stakeholders to provide risk coverage for data transformation platforms, customized subprocess tools, AI use case triage, model/AI engineering tooling, process mapping, RCSA work, issue management, and control uplift activities.
Responsibilities
- Act as a first-line technology risk partner for customized data platforms and data engineering enablement areas, including Talend, CCM, Commercial Data Solutions, HR Data Solutions, Fraud Data Solutions, Leapfrog & Payments Solutions, Wealth Data Solutions, and related RFT engineering processes.
- Support oversight of enterprise AI/ML enablement and tooling, including AWS Bedrock, SageMaker, H2O.ai, MLflow, Galileo/Arize, Gloo, AgentCore, and related AI/ML engineering processes.
- Serve as a delegate for AI use case triage by reviewing intake information, identifying potential technology, data, security, operational, model, and control considerations, and coordinating with appropriate stakeholders for follow-up.
- Perform stability and security discovery through periodic review of applications, code bases, logging and monitoring capabilities, authentication patterns, vulnerability data, and operational signals to identify gaps requiring risk escalation or remediation.
- Lead or support process mapping, RCSA activities, control adequacy reviews, control uplift efforts, procedure updates, and control testing support across assigned data platform and AI/ML domains.
- Identify, document, and steward technology risk issues through the enterprise issue management lifecycle, including issue creation, second-line challenge, action plan tracking, target date management, evidence review, closure, and significance downgrade support.
- Analyze risk, security, operational, and compliance data from tools such as GRC Archer, ServiceNow, Splunk, Datadog, Qualys, Sonatype IQ, Nexus, Jira, and similar platforms to identify trends, gaps, and actionable risk insights.
- Partner with first-line risk, technology, data engineering, AI/ML engineering, cybersecurity, third-party risk, audit, and second-line stakeholders to assess control design and effectiveness, support remediation, and drive risk-aligned outcomes.
- Support third-party risk coordination, internal audit inquiries, regulatory requests, and information requests related to customized data platforms, AI/ML tooling, security findings, and technology control environments.
- Develop clear, well-researched, data-driven risk reports, issue summaries, control documentation, stakeholder updates, and decision support materials within assigned deadlines.
- Use strong organizational skills and tools such as Jira, Confluence, Visio, Excel, Tableau, and enterprise documentation repositories to manage concurrent workloads, stakeholder meetings, deliverables, and follow-ups.
- Stay current on evolving data engineering, cloud, DevSecOps, AI/ML, model risk, data governance, security, and regulatory trends that may affect the bank’s technology risk profile.
Team-Specific Requirements
This backfill is focused on customized data platform support, data integration engineering enablement, AI/ML enablement tooling, stability/security discovery, RCSA and process mapping, issue management, control uplift, third-party coordination, and AI use case triage.
Domain-Specific Technical Skills
- Working knowledge of data processing, transformation, integration, ETL/ELT, data sharing, reporting, and analytics enablement patterns across hybrid-cloud and on-premises environments.
- Familiarity with customized data platforms across a variety of deployment mores (private cloud, commercial-off-the-shelf, in-house, etc.) and technology tools supporting commercial, HR, fraud, payments, wealth, and risk/finance technology data solutions (e.g. Firco, Oracle EBS, Black Diamond Wealth, etc.).
- Understanding of DevSecOps, CI/CD, source control, application deployment, logging, monitoring, vulnerability management, access control, and production support concepts.
- Functional understanding of AI/ML engineering and enablement patterns, including model development workflows, feature/data pipelines, AI platform governance, model observability, and operational controls.
- Ability to identify stability and security gaps such as missing monitoring, incomplete logging, authentication weaknesses, vulnerable components, incomplete operational procedures, or unclear ownership models.
- Comfort working with incomplete information, asking probing questions, documenting process flows, and translating technical details into risk, control, and issue management language.
Team-Specific Tools, Platforms & Coverage Areas
- Customized data platform support across a range of engineering processes and tools, inlcuding Talend, Master Data Management, Commercial, HR Data Solutions, Fraud Data Solutions, Leapfrog & Payments Solutions, Wealth Data Solutions, and RFT engineering processes.
- Enterprise AI/ML enablement and tools: AWS Bedrock, SageMaker, H2O.ai, MLflow, Galileo/Arize, Gloo, AgentCore, and AI/ML engineering processes.
- Risk, workflow, and documentation platforms: GRC Archer, ServiceNow, Jira, Confluence, Visio, Excel, Tableau, and enterprise documentation repositories.
- Security, monitoring, and operational data sources: Splunk, Datadog, Qualys, Sonatype IQ, Nexus, code repositories, vulnerability findings, logging tools, and related engineering telemetry.
- Primary stakeholder groups may include data engineering, RFT engineering, enterprise AI/ML enablement, platform owners, third-party risk, internal audit, second-line risk, and technology control owners.
Experience & Skills
Required:
- 5–7 years of progressive experience in technology risk management, information security, data management, internal audit, engineering governance, or related technology oversight roles.
- Practical understanding of data engineering, data transformation, ETL/ELT, API, BI/reporting, cloud, DevSecOps, CI/CD, and technology control environments.
- Familiarity with AI/ML, Data Engineering and Data Platform enablement concepts, including AI use case intake, platform/tooling risk considerations, model lifecycle controls, data governance, security, observability, and operational readiness.
- Experience conducting or supporting RCSAs, ad-hoc risk assessments, business initiative risk assessments, control adequacy reviews, issue management, control testing support, and audit/regulatory response activities.
- Proficiency with GRC, ITSM, collaboration, and monitoring tools such as Archer, ServiceNow, Jira, Confluence, Splunk, Qualys, Datadog, Nexus, Sonatype IQ, Excel, and Tableau.
- Strong analytical ability to interpret technical, security, operational, and risk data and convert findings into clear risk statements, control observations, remediation actions, and stakeholder-ready reporting.
- Strong communication skills with the ability to engage technical contributors, platform owners, AI/ML teams, risk partners, audit stakeholders, and non-technical audiences.
- Demonstrated ability to manage multiple concurrent priorities, recurring stakeholder meetings, time-sensitive deliverables, and issue/action plan deadlines with minimal oversight.
Preferred:
- Experience in a regulated financial institution or banking environment, especially supporting enterprise data, risk, finance, or AI/ML technology platforms.
- Operational knowledge of Python, SQL, or other scripting/querying skills to support data analysis, automation, risk reporting, or control validation activities.
- Familiarity with AWS services, AI/ML tooling, data governance platforms, model observability tools, SOAR concepts, or DevSecOps automation patterns.
- Prior experience coordinating with third-party risk, internal audit, second-line challenge teams, or control owners to resolve findings and support remediation evidence.
Education
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Data Analytics, Business, Risk Management, or a related field required; Master's degree preferred.
- One or more of the following certifications are preferred:
- CISA, CRISC, CISM, CISSP, PMI-RMP or equivalent technology risk/security certification
- AWS Cloud Practitioner, AWS Solutions Architect, Azure Fundamentals, or comparable cloud certification
- Data governance, AI/ML, analytics, or platform-specific certifications such as Collibra Ranger, CCDAK, IBM API Connect, or similar credentials
Hours & Work Schedule
- Hours per Week: 40
- Work Schedule: Monday-Friday
- Hybrid: 4 days per week on-site, 1 day remote