Technology and AI Risk, Manager
Jeffersonhealth ยท Pennsylvania
๐ Montgomery County, PAvia workdayFirst listed here 2026-09-20
Apply on company site โ
Career Moonshot pulls this listing straight from the employer's hiring system โ no recruiter middleman, no reposts. Applying takes you directly to Jeffersonhealth.
Number of Positions In Requisition
1
Job Details
The Manager, Technology, AI, and Security Risk leads the organization's Security Risk Assessment portfolio with a hands-on technical and security architecture focus. The role is accountable for reviewing the architecture, design, and controls of internally developed applications, AI-enabled applications and agents, APIs and integrations, cloud environments, and external connections, and for turning those technical findings into clear, prioritized risk decisions. Alongside this technical work, the manager owns the broader Governance, Risk, and Compliance (GRC) components of the portfolio, including control framework management, enterprise and regulatory assessments, external and third-party risk, cyber risk management, issues management, and cloud security and posture management, as well as the GRC platform and its AI-enablement capabilities. The position exists to ensure that as the organization expands its internal development and adoption of AI, it designs, builds, and operates those systems securely and in line with applicable legal and regulatory requirements.
Job Description
Summary
The Manager, Technology, AI, and Security Risk leads the organization's Security Risk Assessment portfolio with a hands-on technical and security architecture focus. The role is accountable for reviewing the architecture, design, and controls of internally developed applications, AI-enabled applications and agents, APIs and integrations, cloud environments, and external connections, and for turning those technical findings into clear, prioritized risk decisions. Alongside this technical work, the manager owns the broader Governance, Risk, and Compliance (GRC) components of the portfolio, including control framework management, enterprise and regulatory assessments, external and third-party risk, cyber risk management, issues management, and cloud security and posture management, as well as the GRC platform and its AI-enablement capabilities. The position exists to ensure that as the organization expands its internal development and adoption of AI, it designs, builds, and operates those systems securely and in line with applicable legal and regulatory requirements.
Job Duties
Lead security architecture reviews across internally developed applications, AI systems and agents, APIs, and cloud environments, assessing design, data flows, trust boundaries, and control coverage both before and after deployment.
Perform and oversee threat modeling and secure design reviews for custom-built and AI-enabled applications throughout the development lifecycle, identifying design-level weaknesses and driving fixes into engineering work.
Define the technical assessment approach for AI and machine learning systems, covering model and data governance, prompt and agent security, guardrails, output validation, and misuse scenarios.
Evaluate and validate security controls at the application, integration, and infrastructure layers, including authentication, authorization, encryption, logging, segmentation, and secrets management.
Own the Security Risk Assessment portfolio end to end, ensuring a consistent and technically rigorous methodology, prioritization, and reporting across control framework management, enterprise and regulatory assessments, external and third-party risk, cyber risk, issues management, and cloud posture.
Lead cloud security posture management, including configuration and hardening review, identity and access design, and asset and attack-surface visibility.
Assess third-party, medical device, and B2B integration risk with real attention to the technical interfaces, data exchange, and connectivity involved, not just questionnaire responses.
Maintain the cyber risk register and apply quantitative analysis to technical findings, translating architecture and control gaps into decision-ready risk.
Drive remediation of findings from architecture reviews, assessments, audits, and testing through to validated technical closure.
Ensure applications and platforms meet information security policies, standards, and applicable regulatory frameworks (e.g., HIPAA, NIST, PCI), and inform updates to technical and secure-design standards as technology and threats evolve.
Partner with engineering, cloud, data, and AI teams to embed security into how systems are designed, built, and run, advancing internal development and AI enablement securely.
Advance AI enablement across the team, applying AI-assisted automation to assessment, architecture review, and reporting workflows to strengthen efficiency gains and scale the portfolio's output.
ORGANIZATIONAL IMPACT: Establishes and works to implement key elements of tactical and operational plans with measurable contribution towards the achievement of results of the job area or completion of a project. Makes significant decisions on what their team of responsibility focuses on or executes as directed. Focus is on short-term operational plans (e.g., 1 year or less). Develops new products, processes, standards or operational plans in support of the job area strategy. May have budget or P&L accountability for area of responsibility. Manage resources or elements of the budget.
INNOVATION & COMPLEXITY: Responsible for making moderate to significant improvements of processes, systems or products to enhance performance of job area. May also demonstrate technical innovation in supporting business objectives. Problems and issues faced are numerous and typically undefined, and require detailed information gathering, analysis and investigation to understand the problem. Problems are difficult and moderately complex. Problems typically impact multiple job areas or specialties. Problems are typically solved through drawing from prior experience and analysis of issues. Executes on moderately complex tasks to enhance simplicity and standardization across Jefferson.
COMMUNICATION & INFLUENCE: Communicates with parties
More Pennsylvania jobs
Pennsylvania jobs ยท Browse all locations