SlipstreamJobsFresh Startup & VC-Backed Jobs

Sr. Enterprise Risk Operations Specialist

Reflection AI - New York, NY, USA - In-office - posted 2026-09-14

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Reflection AI is seeking a Senior Enterprise Risk Operations Specialist to join the Enterprise Risk & Trust function, reporting to the Head of Enterprise Risk & Trust. This is a hands-on senior individual contributor role responsible for translating the organization's risk governance frameworks and policies into operational reality across commercial risk support, third-party risk management, controls assurance, and risk issue management. In this high-visibility position, you will serve as an operational center of gravity for the Enterprise Risk & Trust function, coordinating across product, engineering, legal, and compliance teams to ensure risk obligations are understood, evidenced, and actively remediated. Key responsibilities include: **Commercial Risk & Go-to-Market Support:** Drive end-to-end risk assessments and certifications supporting the deals pipeline. Partner with sales, legal, and product teams to scope risk assessments tailored to customer requirements and industry verticals. Develop and maintain reusable risk assessment artifacts, certifications, and evidence packages. Serve as a risk subject-matter expert in customer-facing conversations, due diligence requests, and RFP responses involving risk, compliance, and AI safety. **Third-Party & Vendor Risk Management:** Conduct upfront due-diligence assessments and ongoing risk monitoring of third parties and vendors. Design and operate a scalable third-party risk management program reflecting organizational risk appetite and vendor criticality tiers. Define vendor risk tiering criteria, onboarding requirements, and monitoring cadences. Coordinate with procurement, legal, and technology teams to ensure vendor risk findings inform contracting and remediation decisions. **Controls Assurance & Obligation Validation:** Validate and evidence the design and operational efficacy of policies, standards, controls, and guardrails. Design and execute controls testing programs providing audit-quality evidence of control effectiveness. Develop structured assurance documentation for confident representation to regulators, auditors, and enterprise customers. Identify and escalate control gaps, driving cross-functional remediation. **Risk Issue Management & Remediation:** Operate the organization's risk issue management lifecycle, including maintenance of risk issue inventory, escalation protocols, and remediation prioritization frameworks. Define standards for issue documentation, severity classification, ownership assignment, and remediation timelines. Drive prioritization of remediation efforts aligned with organizational risk appetite. Manage exception management processes including evaluation, approval, and compensating control requirements. Provide regular reporting to leadership on open issues, remediation velocity, and systemic risk trends. You will influence without direct authority, build trusted relationships internally and externally, and operate across all business functions with the ability to translate complex risk concepts into verifiable risk management. **Requirements:** - 7+ years of progressive experience in risk operations, compliance, internal audit, information security, or closely related discipline, with demonstrated track record as a hands-on practitioner and builder of operational risk programs - Demonstrated track record building and operating scalable risk operational programs: controls assurance, third-party risk management, issue management, or incident response - Hands-on experience with commercial risk support functions, including delivery of risk assessments, certifications, or security questionnaires in go-to-market or enterprise sales context - Prior experience in technology risk operations with working knowledge of AI system risk evaluation, safety testing methodologies, and operational lifecycle of AI models - Experience operating in regulated environments and interacting directly with auditors, regulators, or enterprise customers on risk, compliance, or security topics - Exceptional operational discipline with proven ability to design, document, and run repeatable, audit-quality risk management processes at scale - Strong analytical and investigative skills with ability to triage complex risk issues and synthesize large volumes of evidence - Demonstrated ability to manage and report on multi-workstream operational programs, balancing competing priorities and cross-functional dependencies - Excellent written and verbal communication skills, including ability to document risk findings clearly and represent organizational risk posture credibly - Proficiency in risk management tools and GRC platforms; familiarity with evidence management, controls testing workflows, and incident tracking systems - Deeply collaborative and cross-functionally astute, with ability to engage engineering, legal, product, and compliance stakeholders as trusted partner - Calm and structured under pressure with judgment to triage and respond to fast-moving risk events without sacrificing rigor - Genuine curiosity about AI and technology risk, motivated to develop meaningful operational expertise in rapidly evolving domain

Similar roles