AI Governance & Controls Lead

Apply
Apply

Share

successfully icon

Successfully

The vacancy has been successfully added to favorites

location icon

Buffalo, US, New York, United States of America

specialization icon

Enterprise Architecture

lob icon

BCM Industry

date icon

29/07/2026

Req. VR-124257

Apply
Project description

The AI Governance & Controls Lead is the senior individual contributor responsible for operationalizing M&T's AI governance framework: authoring and maintaining AI standards and controls, executing the policy exception and deviation processes, and producing the examiner-ready evidence that demonstrates our controls are enforced mechanically rather than attested annually. This role partners closely with Technology Risk Management, Model Risk Management, Compliance, Cybersecurity, Enterprise Architecture, and the enterprise AI platform team to ensure every AI use case at the bank operates within a defensible, testable control framework.

This is a hands-on, technically fluent governance role. The Lead works directly with platform-enforced controls (gateway policies, entitlements, quotas, audit logging), translates regulatory obligations (e.g., SR 26-2, NYDFS guidance) into implementable standards, and validates that evidence generated by the platform satisfies second-line and examiner expectations. The role serves as a key contributor to policy refresh cycles, regulatory response efforts, and the continuous-monitoring design that replaces point-in-time annual review

Responsibilities
bullet icon

Standards, Controls & Policy Execution

bullet icon

Author, maintain, and version the bank's AI standards library: model selection and approval, human oversight tiers, prompt/response logging and retention, agentic guardrails, and acceptable-use requirements.

bullet icon

Build and maintain the obligation-to-control-to-evidence mapping against applicable regulatory guidance (SR 26-2, NYDFS, and evolving supervisory expectations).

bullet icon

Operate the AI policy exception and TRM deviation processes: draft time-bound deviation requests, define compensating controls, track expiries and remediation paths to closure.

bullet icon

Support annual policy refresh cycles and translate policy principles into testable, enforceable requirements in partnership with policy owners.

bullet icon

Platform-Enforced Governance & Evidence

bullet icon

Partner with the AI platform team to ensure governance requirements are enforced mechanically at the enterprise AI gateway (entitlements, model allowlists, quotas, audit logging) and that enforcement produces native evidence.

bullet icon

Define evidence requirements and validate audit artifacts as queryable, export-ready, and sufficient for internal audit, second-line review, and examiner requests.

bullet icon

Design and operate continuous-monitoring practices: monitoring boundaries, event-based review triggers, and evidence expectations for AI systems that change frequently.

bullet icon

Maintain the AI use case and agent registry as the system of record, integrated with platform onboarding and entitlement workflows.

bullet icon

Provide governance ownership of the AI use-case intake framework in partnership with the AI Use Case Intake & Value Lead.

bullet icon

Risk Partnership & Regulatory Readiness

bullet icon

Serve as the primary working-level interface to Technology Risk Management, Model Risk Management, Compliance, and Internal Audit for AI governance matters.

bullet icon

Assemble examiner-readiness packages: control mappings, evidence samples from the live platform, and documented rationale for the standards the bank has defined.

bullet icon

Monitor the regulatory and industry landscape (agency guidance, FSB/trade-group developments) and assess impact to standards and controls.

bullet icon

Support AI Control Group and AI Ethics Working Group activities with documented assessments and control recommendations.

Skills

Must have

bullet icon

Bachelor's degree and a minimum of 5 years' experience in technology risk, IT governance, information security governance, or technology compliance within a regulated environment, or in lieu of a degree, a combined minimum of 9 years' education and/or relevant work experience.

bullet icon

Demonstrated experience authoring technology standards, controls, or policies and mapping them to regulatory obligations.

bullet icon

Working technical fluency with modern AI systems: LLM-based applications, API gateways, model access patterns, RBAC/entitlements, logging and monitoring architectures.

bullet icon

Experience preparing for or responding to internal audit, second-line review, or regulatory examination.

bullet icon

Strong analytical writing: able to produce standards, deviation requests, and evidence narratives that survive challenge.

bullet icon

Strong communication and stakeholder management skills across risk, technology, and business partners

Nice to have

bullet icon

Experience with AI/ML governance frameworks (NIST AI RMF, model risk management guidance, SR 11-7/SR 26-2 lineage).

bullet icon

Familiarity with Azure services relevant to AI workloads (API Management, Entra ID, Key Vault, Azure Monitor) and with policy-as-code or controls-automation concepts.

bullet icon

Financial services or other highly regulated industry experience.

bullet icon

Experience with GRC tooling and evidence management.

bullet icon

Experience supporting AI, data, or technology committees and governance forums

Other
seniority icon

Languages

English: C1 Advanced

seniority icon

Seniority

Lead

Buffalo, US, New York, United States of America

Req. VR-124257

Enterprise Architecture

BCM Industry

29/07/2026

Req. VR-124257

Apply for AI Governance & Controls Lead in Buffalo, US, New York

*Indicates a required field

Under the terms of your specific consent or to perform our obligations under a contract with you, as applicable, we, Luxoft Holding Inc. will manually and electronically process your personal data, specifically your first name, last name, phone number, e-mail address and other data you provide us through this form.


Within this context, we process personal data only for the specific purpose(s) indicated in the individual consent language or other notices provided below.


We will – insofar as reasonably necessary for the purpose you have agreed to and within the scope of applicable laws – transfer your personal data to other entities within the Luxoft Group and to the group of third party recipients listed in our Privacy Notice. Such Recipients can be located outside the European Union (EU) and/or the European Economic Area (EEA) (“Third Countries”). The Third Countries concerned, e.g. the USA, may not have the level of data protection that you enjoy e.g. under the GDPR. This can result in disadvantages such as an impeded enforcement of data subjects’ rights, a lack of control over further processing and access by state authorities. You may only have limited legal remedies against this. Insofar our transfer of your personal data to recipients in Third Countries is not covered by an adequacy decision of the EU Commission, we achieve an adequate level of data protection as further detailed out in our Privacy Notice.


With your consent, we personalise marketing communications to you by way of carrying out marketing research analysis, analysing the surfing-behaviour of our website visitors and to adjust it to their detected tendencies, as well as to plan more efficient future marketing activities. This personalised marketing does not include any automated decision-making activities.


Further information on how we process personal data in general is available in our Privacy Notice. You may withdraw any given consent at any time. The withdrawal of your consent(s) will not affect the lawfulness of processing before its withdrawal. For any request in this context, please e-mail us at: DPO@luxoft.com.


Before uploading CV or any other information to this website, to learn more about your obligations and restrictions arising from the use of this website, please read our Terms of Use.