Lead Risk Engineer

Posted 2 Days Ago
Be an Early Applicant
Hiring Remotely in USA
Remote
168K-183K Annually
Senior level
Edtech
The Role
Lead the development and operation of a repeatable risk review practice across cloud, application, vendor, identity, and emerging AI systems. Perform threat modeling and risk reviews, define secure-by-default standards and controls, embed risk into procurement and delivery, mentor engineers, and drive cross-organizational governance to improve risk posture and program maturity.
Summary Generated by Built In

College Board – Technology – Risk Engineering

Location: This is a fully remote role. Candidates who live near CB offices have the option of being fully remote or hybrid (Tuesday and Wednesday in office).

Type: This is a full-time position

About the Team

College Board’s Enterprise Security Engineering (ESE) team currently consists of 6 full-time staff and additional contractors. ESE is responsible for implementing and managing cutting-edge security solutions and tools. We protect the confidentiality, integrity and availability of data and endpoints across physical and cloud environments. We protect workloads and data in AWS and Azure, corporate networks, user endpoints around the country and data in SaaS and PaaS environments. We enable our developers and colleagues to deliver new, secure digital offerings that include the Digital SAT and AP exams. The work we perform supports the College Board’s mission to connect students to college success and opportunity. College Board is committed to creating an inclusive environment where all team members feel valued, respected, and supported in their work. We welcome individuals from diverse backgrounds and experiences to join our team and contribute to our ongoing success.  

About the Opportunity

As a Lead Risk Engineer, you will provide technical leadership for how College Board identifies, reviews, and manages risk across its technology systems. College Board's technology footprint spans cloud infrastructure, vendor and API integrations, identity and access for automated systems, and an expanding set of AI and agentic capabilities — and the organization needs a consistent, repeatable practice for assessing risk across all of it, not AI alone. This role exists to build and lead that practice.

You will work within an existing security engineering team and across the Technology division to run risk reviews of new and existing systems, define controls and identity practices for automated and machine-driven access (including AI agents and non-human identities where relevant), and partner with stakeholders across the organization to bring security into decisions early. You will not only execute this work — you will shape the standards, patterns, and practices that let others execute it consistently, and you will lift the engineers around you through mentoring, paired reviews, and shared knowledge rather than becoming a single point of expertise.

This is a role for a technical leader comfortable operating across team and service boundaries, spanning risk domains where standards are still maturing — from cloud and vendor risk to identity and access for automated systems to emerging technologies such as agentic AI. You will contribute to the strategic direction of the risk engineering program — identifying risks and opportunities that influence roadmap decisions — while remaining hands-on in reviews, threat modeling, and control design. Your impact will be measured in durable outcomes: reviews that are repeatable and evidenced, risk that is owned and documented rather than assumed, and stakeholders across the organization who engage security early because the engagement is practical and predictable.

In this role, you will:

Lead operational risk reviews and delivery enablement (45%)

  • Lead risk-based security reviews of technology implementations across domains — including cloud architecture, application security, vendor/third-party integrations, identity and access, and emerging technologies such as GenAI and agentic AI systems — assessing architectures, data flows, data classification handling, and misuse scenarios.

  • Evolve the risk review practice into a documented, repeatable methodology with risk tiering, reusable templates, decision records, and findings tracking.

  • Define and maintain secure-by-default standards, patterns, and reference guidance that reduce review friction and enable delivery teams to meet expectations on the first pass.

  • Cross team and service boundaries to unblock delivery — translating risk and governance requirements into practical implementation steps that fit Agile delivery, and anticipating risks before they become launch blockers.

  • Where systems involve automated or autonomous behavior (e.g., AI agents, service accounts, machine identities), assess and document ownership, credential scope, and control requirements as part of the standard review.

Drive cross-organizational risk alignment (30%)

  • Serve as a primary security/risk partner to organization-level teams and governance bodies — including teams driving responsible AI use, such as GenAI Studio and the GenAI Governance Committee, as well as platform, procurement, and legal stakeholders — establishing recurring consultation touchpoints and pre-procurement engagement.

  • Embed risk requirements into tool onboarding, procurement, and vendor contract processes (e.g., data handling, retention and no-train terms, telemetry expectations, identity and access provisions).

  • Identify emerging or higher-uncertainty risk areas early — including agentic AI, non-human identities, and new integration patterns — and bring them into the standard review process rather than handling them ad hoc.

Build program maturity and grow the team (25%)

  • Define risk acceptance criteria, control requirements, and escalation thresholds; ratify them through appropriate governance bodies and apply them consistently across use cases entering production.

  • Mentor engineers on risk review practices through paired reviews, documentation, and teaching; ensure knowledge is shared and no capability depends on a single person.

  • Contribute to defining the strategic direction of the risk engineering program — synthesizing findings from real implementations into roadmap priorities, and producing leadership reporting on risk posture and program outcomes.

About you, you have:

  • 8+ years in security engineering, application security, cloud security, or security architecture, including demonstrated technical leadership of work that crosses team and service boundaries.

  • Deep, practical expertise in at least two relevant technical areas — for example: cloud security architecture, identity and access management (including non-human/service identities), application security, vendor/third-party risk, or AI/GenAI application security.

  • Experience designing identity and access controls for service accounts, API credentials, or machine identities, and applying least-privilege principles in automated systems.

  • Experience running or contributing to risk-based security reviews of technology implementations, including assessing architecture, data flows, and misuse scenarios; exposure to AI/GenAI or agentic systems is a plus but not required.

  • A track record of turning ambiguous, emerging risk domains into documented standards, repeatable processes, and adoptable guidance.

  • Demonstrated ability to work through others: mentoring engineers, sharing knowledge deliberately, and lifting the capability of a team rather than concentrating expertise.

  • Strong stakeholder skills — building relationships with product, platform, legal, procurement, and governance partners, and presenting risk tradeoffs to technical and non-technical audiences.

  • Comfort operating where standards, tooling, and regulatory expectations are still evolving (e.g., FERPA and student data privacy obligations, and emerging AI governance frameworks).

  • Ability to travel 3–5 times per year to College Board offices.

  • Authorization to work in the United States.

All roles at College Board require:

  • A passion for expanding educational and career opportunities and mission-driven work

  • Authorization to work in the United States for any employer

  • Curiosity and enthusiasm for emerging technologies, with a willingness to experiment with and adopt new AI-driven solutions and a comfort learning and applying new digital tools independently and proactively

  • Clear and concise communication skills, written and verbal

  • A learner's mindset and a commitment to growth: welcoming diverse perspectives, giving and receiving timely, respectful feedback, and continuously improving through iterative learning and user input

  • A drive for impact and excellence: solving complex problems, making data-informed decisions, prioritizing what matters most, and continuously improving through learning, user input, and external benchmarking

  • A collaborative and empathetic approach: working across differences, fostering trust, and contributing to a culture of shared success

About Our Process

  • Application review will begin immediately and will continue until the position is filled. This role is expected to accept applications for a minimum of 5 business days.

  • While the hiring process may vary, it generally includes: resume and application submission, recruiter phone/video screen, hiring manager interview, performance exercise, a panel interview, a conversation with leadership and reference checks.

What We Offer

At College Board, we offer more than just a paycheck—we provide a meaningful career, a supportive team, and a comprehensive package designed to help you thrive. We're a self-sustaining nonprofit that believes in fair and competitive compensation, grounded in your qualifications, experience, impact, and the market.

A Thoughtful Approach to Compensation

  • The hiring range for this role is $168,000 - $183,000

  • Your exact salary will depend on your location, experience, and how your background compares to others in similar roles at the College Board.

  • We aim to make our best offer upfront—rooted in fairness, transparency, and market data.

  • We adjust salaries by location to ensure fairness, no matter where you live.

#LI-DC1 

#LI-REMOTE 

Skills Required

  • 8+ years in security engineering, application security, cloud security, or security architecture
  • Deep, practical expertise in at least two areas (cloud security architecture, IAM, application security, vendor risk, AI/GenAI security)
  • Experience designing identity and access controls for service accounts, API credentials, or machine identities and applying least-privilege
  • Experience running risk-based security reviews including assessing architecture, data flows, and misuse scenarios
  • Track record of turning ambiguous/emerging risk domains into documented standards and repeatable processes
  • Demonstrated ability to mentor engineers, share knowledge, and elevate team capability
  • Strong stakeholder skills with product, platform, legal, procurement, and governance partners
  • Comfort operating where standards and tooling are evolving (e.g., FERPA and student data privacy, emerging AI governance)
  • Ability to travel 3-5 times per year to College Board offices
  • Authorization to work in the United States
  • Exposure to AI/GenAI or agentic systems
  • Strong written and verbal communication skills and a learner's mindset
  • Mission-driven orientation and collaborative, empathetic approach

The College Board Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about The College Board and has not been reviewed or approved by The College Board.

  • Retirement Support A notably generous employer retirement match after six months stands out and is positioned as a differentiator among nonprofits. The structure supports meaningful long-term savings and serves as a core value driver in total rewards.
  • Leave & Time Off Breadth Generous PTO alongside major holidays and a full week off around New Year’s are included in the package. This breadth of time away strengthens work-life balance and adds tangible value beyond salary.
  • Parental & Family Support Paid parental leave for all parents and tuition assistance for employees and dependents provide robust family-oriented support. These benefits expand the package’s relevance for different life stages and needs.

The College Board Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
4,968 Employees
Year Founded: 1900

What We Do

College Board is a not-for-profit organization that clears a path for all students to own their future through the Advanced Placement Program, the SAT, Official SAT Practice on Khan Academy, BigFuture, and more. For more information, go to collegeboard.org

Similar Jobs

Turner & Townsend Logo Turner & Townsend

Lead Risk Engineer – PMC

Professional Services • Real Estate • Consulting
In-Office or Remote
17 Locations
17263 Employees

Citadel Logo Citadel

Global Quantitative Strategies | Quantitative Research Engineer

Information Technology • Software • Financial Services • Big Data Analytics
In-Office or Remote
3 Locations
4000 Employees
275K-350K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Technical Director, Commercial Auto

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
8 Locations
40000 Employees
106K-197K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Inside Sales Representative

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
9 Locations
40000 Employees
45K-85K Annually

Similar Companies Hiring

ReUp Education Thumbnail
Social Impact • Edtech
Austin, TX
180 Employees
Learneo Thumbnail
Software • Machine Learning • Edtech • Artificial Intelligence
NL
397 Employees
CodePath.org Thumbnail
Edtech • Social Impact
San Francisco, CA
55 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account