Technology and AI Risk, Manager

Jefferson Health System

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in science, technology, engineering, or math discipline
  • 7 years of related work experience

Responsibilities

  • Lead security architecture reviews for applications, AI systems, APIs, and cloud environments
  • Oversee threat modeling and secure design reviews for custom and AI-enabled applications
  • Define the technical assessment approach for AI and machine learning systems
  • Evaluate and validate security controls across application and infrastructure layers
  • Own the Security Risk Assessment portfolio, ensuring rigorous methodology and reporting
  • Lead cloud security posture management and configuration reviews
  • Assess third-party and B2B integration risks with a technical focus

Benefits

  • Comprehensive medical insurance including prescription coverage
  • Supplemental insurance options available
  • Dental and vision insurance included
  • Life and AD&D insurance provided
  • Short- and long-term disability coverage
  • Flexible spending accounts offered
  • Retirement plans available
  • Tuition assistance and discounts at Thomas Jefferson University after qualifying period
  • Access to group rates on insurance and discounts for voluntary benefits
Full Job Description
Number of Positions In Requisition
1
Job Details
The Manager, Technology, AI, and Security Risk leads the organization's Security Risk Assessment portfolio with a hands-on technical and security architecture focus. The role is accountable for reviewing the architecture, design, and controls of internally developed applications, AI-enabled applications and agents, APIs and integrations, cloud environments, and external connections, and for turning those technical findings into clear, prioritized risk decisions. Alongside this technical work, the manager owns the broader Governance, Risk, and Compliance (GRC) components of the portfolio, including control framework management, enterprise and regulatory assessments, external and third-party risk, cyber risk management, issues management, and cloud security and posture management, as well as the GRC platform and its AI-enablement capabilities. The position exists to ensure that as the organization expands its internal development and adoption of AI, it designs, builds, and operates those systems securely and in line with applicable legal and regulatory requirements.

Job Description

Summary
The Manager, Technology, AI, and Security Risk leads the organization's Security Risk Assessment portfolio with a hands-on technical and security architecture focus. The role is accountable for reviewing the architecture, design, and controls of internally developed applications, AI-enabled applications and agents, APIs and integrations, cloud environments, and external connections, and for turning those technical findings into clear, prioritized risk decisions. Alongside this technical work, the manager owns the broader Governance, Risk, and Compliance (GRC) components of the portfolio, including control framework management, enterprise and regulatory assessments, external and third-party risk, cyber risk management, issues management, and cloud security and posture management, as well as the GRC platform and its AI-enablement capabilities. The position exists to ensure that as the organization expands its internal development and adoption of AI, it designs, builds, and operates those systems securely and in line with applicable legal and regulatory requirements.

Job Duties
  • Lead security architecture reviews across internally developed applications, AI systems and agents, APIs, and cloud environments, assessing design, data flows, trust boundaries, and control coverage both before and after deployment.
  • Perform and oversee threat modeling and secure design reviews for custom-built and AI-enabled applications throughout the development lifecycle, identifying design-level weaknesses and driving fixes into engineering work.
  • Define the technical assessment approach for AI and machine learning systems, covering model and data governance, prompt and agent security, guardrails, output validation, and misuse scenarios.
  • Evaluate and validate security controls at the application, integration, and infrastructure layers, including authentication, authorization, encryption, logging, segmentation, and secrets management.
  • Own the Security Risk Assessment portfolio end to end, ensuring a consistent and technically rigorous methodology, prioritization, and reporting across control framework management, enterprise and regulatory assessments, external and third-party risk, cyber risk, issues management, and cloud posture.
  • Lead cloud security posture management, including configuration and hardening review, identity and access design, and asset and attack-surface visibility.
  • Assess third-party, medical device, and B2B integration risk with real attention to the technical interfaces, data exchange, and connectivity involved, not just questionnaire responses.
  • Maintain the cyber risk register and apply quantitative analysis to technical findings, translating architecture and control gaps into decision-ready risk.
  • Drive remediation of findings from architecture reviews, assessments, audits, and testing through to validated technical closure.
  • Ensure applications and platforms meet information security policies, standards, and applicable regulatory frameworks (e.g., HIPAA, NIST, PCI), and inform updates to technical and secure-design standards as technology and threats evolve.
  • Partner with engineering, cloud, data, and AI teams to embed security into how systems are designed, built, and run, advancing internal development and AI enablement securely.
  • Advance AI enablement across the team, applying AI-assisted automation to assessment, architecture review, and reporting workflows to strengthen efficiency gains and scale the portfolio's output.
  • ORGANIZATIONAL IMPACT: Establishes and works to implement key elements of tactical and operational plans with measurable contribution towards the achievement of results of the job area or completion of a project. Makes significant decisions on what their team of responsibility focuses on or executes as directed. Focus is on short-term operational plans (e.g., 1 year or less). Develops new products, processes, standards or operational plans in support of the job area strategy. May have budget or P&L accountability for area of responsibility. Manage resources or elements of the budget.
  • INNOVATION & COMPLEXITY: Responsible for making moderate to significant improvements of processes, systems or products to enhance performance of job area. May also demonstrate technical innovation in supporting business objectives. Problems and issues faced are numerous and typically undefined, and require detailed information gathering, analysis and investigation to understand the problem. Problems are difficult and moderately complex. Problems typically impact multiple job areas or specialties. Problems are typically solved through drawing from prior experience and analysis of issues. Executes on moderately complex tasks to enhance simplicity and standardization across Jefferson.
  • COMMUNICATION & INFLUENCE: Communicates with parties within and outside of own job area, which may include external customers or vendors. Requires the ability to influence others outside of own job area on policies, practices and procedures.


Minimum Qualifications
  • Bachelor's Degree in science, technology, engineering, or math discipline
  • 7 years related work experience


Physical Demands
Lift and carry 25 lbs. frequent sitting/standing, frequent keyboard use, *patient care providers may be required to perform activities specific to their role including kneeling, bending, squatting and performing CPR.

Job Description Disclaimer: This position description provides the major duties/responsibilities, requirements and working conditions for the position. It is intended to be an accurate reflection of the current position, however management reserves the right to revise or change as necessary to meet organizational needs. Other responsibilities may be assigned when circumstances require.

Work Shift
Workday Day (United States of America)

Worker Sub Type
Regular

Employee Entity
Thomas Jefferson University
Primary Location Address
1100 Virginia Drive, Fort Washington, Pennsylvania, United States of America

Benefits

Jefferson offers a comprehensive package of benefits for full-time and part-time colleagues, including medical (including prescription), supplemental insurance, dental, vision, life and AD&D insurance, short- and long-term disability, flexible spending accounts, retirement plans, tuition assistance, as well as voluntary benefits, which provide colleagues with access to group rates on insurance and discounts. Colleagues have access to tuition discounts at Thomas Jefferson University after one year of full time service or two years of part time service. All colleagues, including those who work less than part-time (including per diem colleagues, adjunct faculty, and Jeff Temps), have access to medical (including prescription) insurance.

For more benefits information, please click here

Similar Jobs

More Jobs at Jefferson Health System

More Information Technology Jobs

Find similar Technology and AI Risk, Manager jobs: