Sr. Enterprise Risk Operations Specialist
New York, NY • FullTime
Posted 11h ago
Remote Work Policy
On-site
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Reflection is seeking a Sr. Enterprise Risk Operations Specialist to join their Enterprise Risk & Trust team. This senior individual contributor role is responsible for translating the organization's risk governance frameworks and policies into operational reality. You will personally operate the machinery that validates adherence, surfaces issues, and drives resolution, ensuring an audit-ready risk posture. The role spans commercial risk support, third-party risk management, controls assurance, and risk issue management, coordinating across product, engineering, legal, and compliance teams to ensure risk obligations are actively evidenced and remediated. Success requires translating complex risk concepts into verifiable risk management, influencing without direct authority, and building trusted relationships.
Responsibilities
- Drive the end-to-end lifecycle for risk assessments and certifications supporting the deals pipeline and go-to-market efforts.
- Partner with sales, legal, and product teams to scope and deliver risk assessments tailored to customer requirements.
- Develop and maintain a library of reusable risk assessment artifacts, certifications, and evidence packages.
- Serve as a risk subject-matter expert in customer-facing conversations, due diligence requests, and RFP responses.
- Conduct upfront due-diligence assessments, ongoing risk monitoring, and on-demand risk reviews of third parties and vendors.
- Design and operate a scalable third-party risk management program.
- Define and maintain clear criteria for vendor risk tiering, onboarding requirements, and ongoing monitoring cadences.
- Coordinate with procurement, legal, and technology teams to ensure vendor risk findings are reflected in contracting and relationship management.
- Validate and evidence the design and operational efficacy of policies, standards, controls, and guardrails.
- Design and execute controls testing programs that provide reliable, audit-quality evidence of control effectiveness.
- Develop and maintain structured assurance documentation for regulators, auditors, and customers.
- Identify and escalate control design or operational gaps, working cross-functionally to drive remediation.
- Operate the organization’s risk issue management lifecycle, including inventory, escalation, prioritization, and exception management.
- Define and apply clear standards for issue documentation, severity classification, ownership, and remediation timelines.
- Drive prioritization of remediation efforts in alignment with the organization’s risk appetite.
- Manage the exception management process, including evaluation, approval, and tracking.
- Provide regular reporting to leadership on open issues, remediation velocity, and systemic risk trends.
Requirements
- 7+ years of progressive experience in risk operations, compliance, internal audit, information security, or a closely related discipline.
- Demonstrated track record as a hands-on practitioner and builder of operational risk programs.
- Demonstrated track record of building and operating scalable risk operational programs (controls assurance, third-party risk management, issue management, or incident response).
- Hands-on experience with commercial risk support functions, including delivering risk assessments or certifications in a go-to-market or enterprise sales context.
- Prior experience in technology risk operations with working knowledge of AI system risk evaluation, safety testing methodologies, and AI model operational lifecycle.
- Experience operating in regulated environments and interacting directly with auditors, regulators, or enterprise customers on risk, compliance, or security topics.
- Exceptional operational discipline — proven ability to design, document, and run repeatable, audit-quality risk management processes at scale.
- Strong analytical and investigative skills.