Synchrony Financial

VP, Generative AI Risk Oversight

Stamford HubFull timeVpPosted 5 days ago
Apply on Synchrony Financial →

Sign in to see who you know at Synchrony Financial.

Role Summary/Purpose:The Operational Risk Management team is part of the 2nd Line of Defense (2LOD) within Synchrony.   The Risk Manager for AI, Generative AI, and Agentic AI is responsible for identifying, assessing and monitoring, risks arising from the design, development, deployment, and operation of AI-enabled capabilities. This role partners with the AI Solutions team to embed effective governance, controls, and assurance across the AI lifecycle. The position reports to the VP, Information Technology Oversight.Essential ResponsibilitiesEngage the Information Technology organization in reviewing and assessing AI risk management practices and controls for AI/GenAI/Agentic AI solutions, ensuring risks are understood, measured, and managed in alignment with business objectives and risk appetite.Risk assessment and control design: Perform or oversee AI risk assessments (use case, model, vendor, and process), documenting inherent/residual risk, control effectiveness, and remediation plans.GenAI and LLM risk controls: Recommend guardrails for prompt/response safety, content moderation, jailbreak/prompt injection defenses, RAG data hygiene, retrieval security, and output verification.Agentic AI controls: Establish policies and technical controls for tool access, authorization, least privilege, action confirmation, rate limiting, sandboxing, memory management, and Human-in-the-Loop approval for high-impact actions.Model risk management: Partner with Model Validation/Analytics teams to define validation expectations (performance, robustness, bias/fairness, explainability, drift) and ensure independent review where required.Security and privacy alignment: Coordinate with Security and Privacy teams on data classification, access control, encryption, secrets management, secure SDLC, privacy-by-design for AI solutions.Regulatory and policy alignment: Maintain alignment with relevant standards and regulations (as applicable) and ensure internal AI policies and procedures are current and auditable.Third-party and vendor risk: Conduct due diligence on AI vendors (foundation models, platforms, data providers) including security posture, data usage terms, IP considerations, and model transparency/documentation.Incident response and issue management: Oversee triage, containment, communications, and lessons learned.Monitoring and KRIs: Define and track AI risk metrics (e.g., safety events, policy violations, drift, override rates, hallucination indicators, agent action errors) and report insights to governance forums.Training and enablement: Deliver risk guidance and training to product and engineering teams; promote responsible AI practices and documentation discipline.Audit readiness: Ensure evidence collection, control testing support, and documentation standards to satisfy internal audit, regulators, and customer due diligence inquiries.Perform formal assessments of technology risks using common processes within Risk Management, including Targe...