Jobs › California › San Francisco Bay Area › Manager of Risk & Governance (AI Safety)
Manager of Risk & Governance (AI Safety)
Reflection AI is hiring for the role of Manager of Risk & Governance (AI Safety), San Francisco, CA (On-site). This is an AI Governance role in the governance, risk, and compliance field. Review the full details below and apply directly with Reflection AI.
Our Mission Reflection is a research lab making intelligence open and accessible for everyone to use, customize, and build on. We build open models that let anyone control their intelligence and help shape the future of AI. Our mission: make intelligence open and accessible to all. Role Overview The Head of Risk & Trust Governance is responsible for designing, operating, and continuously maturing the organization's enterprise risk management and control environment. This leader owns the full lifecycle of risk governance — from obligation identification and control architecture to risk measurement, reporting, and external representation — ensuring the organization operates within its stated risk appetite while advancing its strategic objectives. Sitting at the intersection of risk, compliance, technology, and AI safety, this role is uniquely positioned to shape how the organization understands and responds to a dynamic regulatory and operational risk landscape. The ideal candidate brings deep expertise in enterprise risk frameworks, a systems-level perspective on controls design, and the executive presence to represent the organization's risk posture to regulators, customers, and other critical external stakeholders. This is a high-visibility, high-impact role that operates across all business functions. Success requires the ability to translate complex risk concepts into actionable governance structures, influence without direct authority, and build trusted relationships internally and externally. What You'll Do Control Environment & Risk Framework Architecture Architect and govern a control environment that drives efficient, prioritized adherence to organizational obligations in alignment with management's objectives and stated risk appetite. Design and continuously operate an enterprise risk management framework spanning risk identification, measurement, mitigation, monitoring, and reporting — contextualized against the organization's obligations, objectives, and risk tolerance. Establish a disciplined approach to risk prioritization that balances operational efficiency with the rigor required to address high-severity exposures across the enterprise. Policy, Standards & Controls Governance Architect and govern the organization's policy and standards issuance lifecycle, ensuring timely coverage of emerging obligations and strategic priorities. Oversee the design, implementation, and ongoing operation of controls and guardrails that drive adherence to obligations and objectives within defined risk appetite thresholds. Develop and maintain a structured controls taxonomy and policy hierarchy, ensuring alignment, traceability, and clear ownership across the enterprise. Enterprise Inventories & Ecosystem Oversight Own and maintain the enterprise risk registry and control inventory, ensuring completeness, accuracy, and operationalization across all relevant functions. Provide oversight over the design, quality, and utilization of key risk-related ecosystem inventories, including data inventories, IT asset inventories, and other foundational records management infrastructure. Champion data quality and governance standards across risk-related inventories, enabling confident risk measurement and management decisions. Risk Reporting & Executive Communication Develop and maintain executive-quality reporting on enterprise risk posture, policy and standards coverage, and the efficacy of regulatory and risk-driven controls. Contextualize risk reporting against the organization's obligations, objectives, and risk appetite — enabling senior leadership and the Board to make well-informed decisions. Drive continuous improvement of risk metrics, dashboards, and reporting cadences to reflect evolving organizational priorities and stakeholder needs. AI Governance & Ethics Coordinate with the Head of AI Governance (in Legal) to manage AI risk. Own and maintain the AI use-case inventory and the AI use-case risk and ethics evaluation framework, including use-case tiering and risk classification methodologies. Ensure AI governance practices are aligned with regulatory expectations, ethical principles, and enterprise risk appetite, and that evaluation frameworks evolve in step with the rapidly changing AI landscape. Partner with product, engineering, legal, and compliance stakeholders to embed AI risk considerations into the design and deployment of AI systems. External Engagement & Regulatory Representation Represent the organization on risk, governance, and AI safety topics in interactions with regulators, customers, auditors, and other external stakeholders. Lead or contribute to the negotiation of contracts, agreements, and licenses with risk and compliance implications, advocating for risk-informed terms and organizational protections. Monitor the external regulatory and industry landscape to anticipate emerging obligations, translate new requirements into actionable internal frameworks, and proactively position the organization ahead of compliance deadlines. What We're Looking For Experience & Background 20+ years of progressive experience in enterprise risk management, compliance, internal audit, or a closely related governance discipline. Demonstrated track record of designing, implementing, and maturing enterprise risk management frameworks and control environments at scale. Prior experience owning or significantly contributing to policy and standards governance programs, including the lifecycle management of policies, standards, and controls. Meaningful exposure to AI governance, responsible AI, or technology risk — with working knowledge of AI risk and ethics frameworks, use-case evaluation methodologies, and emerging AI regulation. Experience engaging with external regulators, auditors, or enterprise customers on risk and compliance topics; including participation in regulatory examinations, customer due diligence processes, or contract negotiations. Skills & Capabilities Exceptional ability to desig
Location and market context
This role is based in San Francisco on-site. Local candidates benefit from being close to Reflection AI's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About AI governance roles
AI governance sits at the intersection of policy, risk, and engineering. Teams are standing up model inventories, use-case intake and review, risk classification, and control monitoring as regulation and board scrutiny of AI intensify. Roles like this one are typically evaluated against frameworks such as NIST AI RMF, ISO/IEC 42001, the EU AI Act, and internal model-risk and privacy practices.
How to position yourself for this AI governance role
Strong candidates emphasize experience translating policy into operational controls, working across legal, compliance, security, product, and data teams, documenting AI system risks, and supporting governance processes. In your resume and outreach, tie your experience to how Reflection AI would apply NIST AI RMF, ISO/IEC 42001, the EU AI Act, and internal model-risk and privacy practices, and lead with concrete outcomes rather than duties.
Similar GRC roles
- AI Governance Analyst · TransUnion · Los Angeles, CA, CA Chicago
- Policy Design Manager, Age-Appropriate Design · Anthropic · San Francisco, CA
- Governance, Risk & Compliance · Runway · San Francisco, CA, WA
- Tech Governance - Security Compliance Engineer · OKX · San Francisco, CA
- Senior GRC Analyst · Crusoe · San Francisco, California
- Governance, Risk, and Compliance Analyst · You.com · San Francisco, California
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.