> Markdown version of [/jobs/ext/3464105-artificial-intelligence-governance-and-risk-manager](https://www.wearedevelopers.com/jobs/ext/3464105-artificial-intelligence-governance-and-risk-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Artificial Intelligence Governance and Risk Manager - **Company:** Ferguson Enterprises Inc. - **Location:** United States (Remote available) - **Experience:** Starter - **Salary:** $39,520.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Data Security, IT Management, Data Processing, Data Classification, Generative AI, Information Technology, Performance Monitor, Virtual Agents - **Published:** September 10, 2026 - **Apply:** https://www.builtincolorado.com/job/artificial-intelligence-governance-and-risk-manager/11144472?handler=ApplyRedirect ## About the Role * Experience in AI/technology governance, risk management, or compliance operations, ideally in a matrixed enterprise environment. * Working knowledge of legal and regulatory considerations related to AI, data privacy, vendor risk, and responsible technology governance, including the ability to recognize potential compliance risks and engage Legal and other stakeholders as appropriate. * Data privacy experience, including working knowledge of data classification and privacy impact assessment methodology - this role's core judgment calls depend on correctly assessing the data a use case or tool touches. * Working knowledge of GRC processes and third-party/vendor risk review. * Experience with AI discovery, monitoring, or governance tooling, including hands-on administration - not solely policy-level familiarity. * Ability to operate independently against a governance framework that is still maturing, and to help build out undefined parts of it. * Autonomous decision making to assess when and what level of governance assessment is needed for AI use cases or vendor requests. * Strong cross-functional coordination skills - this role works constantly with Legal, InfoSec, Sourcing, and business stakeholders who don't report to it., * Privacy certification (e.g., CIPP/E, CIPM) alongside AI governance training or audit credential. * Familiarity with AI-specific risk considerations (model risk, agentic system risk, bias/explainability) distinct from general IT governance. * Experience standing up or operating governance committee structures at the functional or business-unit level. ## Description The AI Governance and Risk Manager owns the day-to-day execution of AI governance and risk review across Ferguson's AI portfolio - evaluating use cases, vendors, and tools against Ferguson's risk framework, running the AI Impact Assessment process, and building visibility into where AI is being used across the organization, approved or not. This role works in close, standing partnership with Legal/InfoSec on day-to-day risk determinations. Policy and standards work is co-owned between this role and the Senior Manager, who remains the final checkpoint before any policy artifact moves forward for review by Legal, InfoSec, the AI Council, or other stakeholders; day-to-day operational review and risk assessment is fully owned by this role. Ferguson's AI governance model is actively maturing. This role will operate against frameworks that are partly built and help finish building the parts that aren't - it is not a role for someone who needs a fully defined process before they can execute., Location: This role is approved to be either Remote within the United States or Hybrid for associates in Newport News, VA, in accordance with company policy. Key ResponsibilitiesUse case and AI Impact Assessment (AIIA) * Own the AI Impact Assessment process for new and materially changed AI use cases, from intake through disposition, including maintenance of the AIIA repository as the governance record of use cases reviewed. * Own the routing logic that determines which reviews a use case or vendor/tool requires - based on data classification, AI Solution Tier, vendor/tool status, and whether the system is agentic - captured through intake questions asked at first contact, before deeper assessment begins. * Ensure AI-specific assessment (classification, tiering, privacy screen, vendor questionnaire, agentic review as applicable) is complete before a use case or vendor request proceeds to Sourcing, InfoSec, and Legal - so those teams receive Ferguson's AI-specific assessment already answered rather than working the AI questions themselves. * Conduct a high-level data privacy impact screen for each use case. The screen identifies whether a use case's data handling raises privacy concerns warranting escalation to a full data privacy assessment; it is a triage step, not a substitute privacy determination. * Assess fairness/bias and explainability considerations as part of the AIIA, calibrated to the use case's risk tier. * Define and apply clear escalation criteria for when a use case requires full PIA, Legal review, or AI Council-level escalation, rather than resolving ambiguous cases informally case by case. * Identify when an approved use case has materially changed (scope, data, vendor terms) and needs re-review. Vendor and tool risk review * Own the vendor and tool AI risk review process, including sending and evaluating AI risk questionnaires. * Coordinate vendor risk disposition through the Ironclad routing process with Sourcing and InfoSec. * Develop and apply a review approach specific to agentic AI (autonomy level, action scope, data access, escalation path if an agent acts incorrectly) distinct from standard tool/vendor review - in coordination with AI Technology & Innovation on technical risk factors. Shadow AI * Build visibility into unapproved AI usage across the organization - what's being used, by whom, and why - using discovery tooling and direct engagement with teams. * Evaluate, select, and administer AI governance/discovery tooling as Ferguson brings it in. * Partner with teams found using unapproved tools to understand the underlying need (capability gap, workflow friction, awareness gap) and support migration to approved alternatives, positioning this as enablement rather than enforcement alone. * Feed shadow AI findings into policy and standards work as evidence of where existing guidance has gaps. Governance infrastructure and reporting * Maintain the AI registry / governance repository as the record of approved use cases, tier, classification, and status. * Track and report governance health - review cycle time, backlog, risk distribution across the portfolio - to the Senior Manager. * Maintain awareness of the AI regulatory landscape and support maintenance of a regulatory register to keep policy and standards current as external requirements evolve. Policy and standards (co-owned) * Draft and refine AI governance policy, standards, and guidelines (e.g., AUP updates, tiering framework changes, committee charter revisions) in partnership with the Senior Manager. * Bring proposed policy changes to the Senior Manager for review before they move to Legal, InfoSec, AI Council, or other stakeholders for their own review - the Senior Manager is the checkpoint before external visibility, not a gate on day-to-day operational work., Coordinates installation projects from initial customer and provider contact through scheduling, product delivery, compliance documentation, issue resolution, and post-completion work orders. Communicates with customers, service providers, stores, and vendors through inbound and outbound calls, documents interactions in company systems, ensures SLA adherence, assesses costs and chargebacks, and supports consistent customer service and process improvement in a fast-paced environment. Top Skills: Installation Management SystemMyredvestSalesforce Corporate Tools LLC Merchant Services Representative 3 Hours Ago Remote or Hybrid 19-19 Hourly Entry level 19-19 Hourly Entry level eCommerce * Legal Tech * Professional Services * Software * Data Privacy Conduct outbound consultation calls with clients about credit card processing, assess merchant needs, recommend cost-effective solutions, and convert leads into merchant account applications. Provide customer service, manage client relationships, communicate by phone and email, follow up on pricing quotes, and support other customer service teams. The role requires learning point-of-sale systems and credit card terminals while using consultative sales, negotiation, and problem-solving skills. Top Skills: Credit Card TerminalsPoint-Of-Sale Systems Coupa ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Your imaginations is (no longer) the limit: how Generative AI empowers people to be creative](https://www.wearedevelopers.com/videos/741-your-imaginations-is-no-longer-the-limit-how-generative-ai-empowers-people-to-be-creative) - [Responsible AI @ Microsoft - Governance, Standards, Learnings](https://www.wearedevelopers.com/videos/1544-responsible-ai-microsoft-governance-standards-learnings) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Web-based Information Visualization](https://www.wearedevelopers.com/videos/84-web-based-information-visualization) ## Related Articles - [Should AI be Regulated? The Arguments For and Against](https://www.wearedevelopers.com/magazine/271-should-ai-be-regulated-the-arguments-for-and-against) - [Panel Discussion: Responsible AI in Practice - Real-World Examples and Challenges](https://www.wearedevelopers.com/magazine/488-panel-discussion-responsible-ai-in-practice-real-world-examples-and-challenges) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [What Industries Outside of AI Are Hiring The Most AI Experts?](https://www.wearedevelopers.com/magazine/98-what-industries-outside-of-ai-are-hiring-the-most-ai-experts) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship)