BNY Mellon
Director, Technology and Cyber Risk Management

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
About the Role
This exciting role entails one thing: building and sustaining credible second line of defense oversight of AI risk across BNY. Activities include, but are not limited to:
- Build, lead, and sustain the newly established AI Risk team and its operating model as AI adoption, business use cases, and the threat environment evolve.
- Provide strategic second line of defense advice and credible challenge to senior first line of defense management, including senior technologists in the AI Hub and platform leaders integrating AI into their businesses.
- Establish and evolve a proportionate enterprise AI Risk framework, including risk principles, requirements, governance, and control expectations.
- Exercise judgment and make decisions on how to achieve short- and long-term goals when raising or creating new AI risk management requirements for the business.
- Oversee AI risk identification, assessment, measurement, monitoring, governance, and issue management across the risk management lifecycle.
- Challenge AI adoption decisions and control approaches when needed, including where risk considerations may affect business priorities or delivery outcomes.
- Coordinate across Risk & Compliance and other control functions to address AI as a transversal risk and align oversight with enterprise risk management and regulatory expectations.
- Monitor changes in AI technology, business adoption, regulation, and the threat environment, and translate them into proportionate adjustments to the AI Risk program.
- Provide clear reporting and risk insights to senior leadership and governance forums on AI risk exposure, control gaps, issues, and remediation progress.
- Promote responsible AI adoption by partnering with stakeholders to enable innovation while upholding the Firm’s risk principles.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Requirements


Get help with your application
Your very own career expert that helps elevate your application to the next level.
To be successful in this role, we're seeking the following:
- 10+ years of relevant experience in risk management, technology risk, cyber risk, data risk, model risk, or AI risk, including significant on-the-job risk management experience within a highly regulated financial institution.
- Strong AI risk subject matter expertise and practical knowledge of the risks and controls associated with enterprise AI adoption.
- Robust knowledge of how to apply and sustain a risk management framework across risk identification, assessment, measurement, monitoring, governance, and issue management.
- Demonstrated ability to build or materially enhance a risk program or oversight capability in a complex organization.
- Proven ability to advise, influence, and credibly challenge senior technology and business leaders, including when risk requirements may affect strategic priorities or delivery timelines.
- Strong judgment and strategic thinking, with the ability to establish proportionate requirements in a rapidly changing business, technology, and threat environment.
- Experience working across Risk & Compliance and partnering with first and second line stakeholders on transversal risk matters.
- Excellent written and verbal communication skills, with the ability to translate complex AI and risk topics into clear, decision-oriented messages.
- Relentless curiosity and a passion for enabling safe, high-impact innovation.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London