See yourself in our team:
Risk Management is an independent function within CommBank accountable for providing approval and acceptance of decisions to ensure the Group remains within its risk appetite.
The Technology and Operations Risk team is responsible for providing specialist Operational Risk and Compliance advice, assurance, oversight and acceptance or approval of decisions made across the Technology, COO and Supplier Support Units.
The Artificial Intelligence Technology Risk team provides specialist Line 2 oversight, advice, challenge and assurance in relation to the technology, cyber, data and operational risks arising from the Group’s development and use of artificial intelligence. The team supports the safe and sustainable adoption of AI by providing independent risk insights across AI platforms, foundational capabilities, services and use cases.
Do work that matters:
As a Senior Manager, Artificial Intelligence Technology Risk, reporting to the Executive Manager, you will be a member and technical leader within a team of technology risk professionals providing Operational Risk and Compliance support to the Chief Artificial Intelligence Office (CAIO) that are building and operating the core foundations used to develop, deploy and manage AI technology across CBA.
You will lead and support complex and material AI technology risk assessments, provide independent and commercially balanced challenge, form clear Line 2 risk opinions and support sound risk acceptance and approval decisions. Your work will improve the identification and management of AI, data, technology, and cyber risks and strengthen the design and operating effectiveness of controls managed by Technology.
The role requires strong judgement, leadership and senior stakeholder influence. You will build trusted relationships with Technology, Cyber and AI leaders, represent Line 2 in senior governance and change forums, guide the delivery of risk and assurance activities, and coach team members in the consistent application of risk management practices.
Key responsibilities for this role include:
Technical
Lead the provision of specialist, independent and commercially balanced AI technology risk advice and constructive challenge to teams aligned to the Chief Technology Office and Chief Artificial Intelligence Office, particularly those building and operating the Group’s foundational AI platforms and capabilities.
Own and coordinate Line 2 oversight for an assigned AI technology portfolio, setting priorities based on materiality, strategic change, emerging risk, control performance and the Group’s risk appetite.
Assess the risks and controls associated with generative AI and agentic systems, including retrieval-augmented generation, LLM-based applications, agentic workflows, orchestration tooling, APIs, data pipelines, cloud and platform infrastructure, identity and access management, security, resilience, third-party dependencies, monitoring and human oversight.
Form and communicate clear, evidence-based Line 2 risk opinions and recommendations, including whether identified risks require remediation, escalation, additional assurance, formal acceptance or referral to the relevant decision-making authority.
Shape and lead the delivery of risk-based Line 2 oversight and assurance activities, including thematic reviews, risk-in-change assessments, control reviews and monitoring of material AI technology initiatives.
Oversee monitoring and reporting of three lines of accountability activities for the assigned portfolio, including the effective operation of the Risk Management Approach, Operational Risk Management Framework and Compliance Management Framework in support of CPS 220.
Lead the oversight and monitoring of key AI, data, technology and cyber risks, controls, issues, incidents, obligations and risk-in-change activities, identifying systemic themes, concentrations and emerging risks.
Lead the identification, escalation and reporting of material technology, cyber and compliance matters to relevant stakeholders, including NFRCs, the Executive Manager, General Manager and Technology and Operations CRO.
Prepare and present concise, decision-useful risk reporting and governance material that translates complex technical matters into clear risk implications, priorities and recommended actions.
Drive the continuous uplift of AI risk frameworks, standards, control guidance, assurance approaches, risk data and stakeholder reporting, incorporating relevant external developments and lessons from incidents and assurance activity.
Coordinate with other Line 2 specialists, Line 1 risk teams, Group Audit and Assurance and relevant subject-matter experts to provide integrated risk coverage and reduce unnecessary duplication.
Leadership
Provide technical and delivery leadership across a cross-skilled team supporting interconnected AI, data, technology, cyber and operational risk domains.
Establish clear expectations and quality standards for risk assessments, assurance activities, written risk opinions and governance reporting; review significant outputs before escalation or submission.
Coach and mentor Managers and other team members, supporting the development of technical risk capability, professional judgement, stakeholder engagement and confidence in providing constructive challenge.
Develop and maintain effective partnerships with senior Technology stakeholders, becoming a trusted adviser through commercial acumen, sound judgement and practical recommendations.
Represent the AI Technology Risk team in senior risk, governance and strategic change forums, ensuring that material matters are clearly articulated, appropriately challenged and progressed to resolution.
Influence the prioritisation of risk remediation and control uplift by helping stakeholders understand the nature, materiality and potential consequences of identified risks.
Lead through ambiguity and competing priorities, coordinating team delivery, managing dependencies and escalating constraints or emerging risks in a timely manner.
Encourage speaking up, intellectual curiosity and constructive debate, creating an environment in which differing technical and risk perspectives can be considered safely.
Contribute to the broader development of Line 2 risk management and assurance practices, including data analytics, reporting, knowledge sharing and continuous improvement.
Role model behaviours consistent with CBA values expectations and leadership principles and contribute to a safe, inclusive and collaborative workplace.
We’re interested in hearing from people who have:
Extensive experience in technology, cyber, data, or AI risk management, controls, assurance or audit within a large and complex environment, with experience in regulated financial services strongly preferred.
Strong technical knowledge of generative AI and agentic systems, including modern architectures such as retrieval-augmented generation, agentic workflows and LLM-based applications.
Significant experience applying risk management frameworks and three lines of accountability models and providing independent Line 2 oversight, advice and challenge.
Experience leading risk-in-change assessments, control assurance activities, thematic reviews or equivalent complex risk engagements involving multiple teams and senior stakeholders.
Broad knowledge of relevant technology and cyber control domains, including cloud, identity and access management, secure development and DevSecOps, APIs, change and release management, incident management, systems resilience, monitoring and third-party risk.
Strong judgement and the ability to distinguish between tactical control gaps, material risk exposures and broader systemic or emerging risk themes.
Strong written and verbal communication skills, including executive and governance reporting, evidence-based risk assessment and the ability to translate complex technical concepts into clear risk insights and recommendations.
Demonstrated ability to influence senior stakeholders, deliver constructive challenge and achieve commercially balanced outcomes while maintaining the independence of Line 2.
Experience providing technical leadership, coaching or quality review to risk professionals or other team members.
A relevant tertiary qualification in Computer Science, Data Science, Engineering, Cyber Security or a related discipline.
Industry certifications in cyber, cloud, technology risk or AI and machine learning are highly regarded, such as CISA, CRISC, CISSP, or AWS, Azure or GCP certifications.
A curious and humble mindset, strong awareness of external AI developments and a commitment to continuous learning and the ongoing uplift of risk management practices.
Risk mindset: All CommBank employees are expected to proactively identify and understand, openly discuss and act on current and future risks.
If this sounds like the role for you then we would love to hear from you. Apply today!
At CommBank, we're committed to creating an accessible, inclusive and respectful workplace. If you require support or adjustments, please let us know. We welcome applications from people of all backgrounds and we're particularly committed to making a positive difference for Aboriginal and/or Torres Strait Islander Peoples. For support please contact 1800 989 696.
If you're already part of the Commonwealth Bank Group (including Bankwest, x15ventures), you'll need to apply through Sidekick to submit a valid application. We’re keen to support you with the next step in your career.
We're aware of some accessibility issues on this site, particularly for screen reader users. We want to make finding your dream job as easy as possible, so if you require additional support please contact HR Direct on 1800 989 696.
Skills Required
- Extensive experience in technology, cyber, data, or AI risk management, controls, assurance, or audit within a large and complex environment
- Experience in regulated financial services
- Strong technical knowledge of generative AI and agentic systems, including retrieval-augmented generation, agentic workflows, and LLM-based applications
- Significant experience applying risk management frameworks and three lines of accountability models
- Experience providing independent Line 2 oversight, advice, and challenge
- Experience leading risk-in-change assessments, control assurance activities, thematic reviews, or equivalent complex risk engagements
- Broad knowledge of cloud, identity and access management, secure development, DevSecOps, APIs, change and release management, incident management, systems resilience, monitoring, and third-party risk
- Strong judgement in distinguishing tactical control gaps, material risk exposures, systemic risks, and emerging risks
- Strong written and verbal communication skills, including executive and governance reporting
- Ability to translate complex technical concepts into clear risk insights and recommendations
- Demonstrated ability to influence senior stakeholders and deliver constructive challenge while maintaining Line 2 independence
- Experience providing technical leadership, coaching, or quality review to risk professionals or team members
- Relevant tertiary qualification in Computer Science, Data Science, Engineering, Cyber Security, or a related discipline
- Industry certification in cyber, cloud, technology risk, or AI and machine learning, such as CISA, CRISC, CISSP, AWS, Azure, or GCP certification
- Curious and humble mindset, awareness of external AI developments, commitment to continuous learning, and commitment to improving risk management practices
Commonwealth Bank Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Commonwealth Bank and has not been reviewed or approved by Commonwealth Bank.
-
Leave & Time Off Breadth — The bank offers additional Life Leave, the option to purchase up to four extra weeks, pet leave, and paid volunteering leave alongside flexible-working options. Public materials indicate these leave features compare well within Australian banking.
-
Parental & Family Support — Permanent employees can access up to 18 weeks of paid parental leave, and superannuation is paid for up to 34 weeks of unpaid parental leave. These provisions extend support for new parents beyond standard settings.
-
Wellbeing & Lifestyle Benefits — Access includes CBHS Health Fund, Fitness Passport, a 24/7 wellbeing platform with telehealth, an Employee Assistance Program, and employer‑paid income protection for up to two years, alongside staff banking perks and share plans. This combination provides day‑to‑day value across health, protection, and financial perks.
Commonwealth Bank Insights
What We Do
Australia’s leading provider of financial services including retail, premium, business and institutional banking, funds management, superannuation, insurance, investment and sharebroking products and services. We are a business with more than 800,000 shareholders and over 52,000 employees. We offer a full range of financial services to help all Australians build and manage their finances.







