Lead Risk Engineer

๐Ÿข College Board ยท all College Board jobs
๐Ÿ“ United States
๐Ÿ’ฐ USD 168,000 - 183,000 / annual
๐Ÿ“… Posted 2026-08-03 ยท via Himalayas
๐Ÿท Risk-Engineering,Security-Engineering,Cloud-Security,Application-Security,IT-Risk-Management,Senior-Risk-Engineer,Principal-Risk-Engineer,Risk-Management-Lead
Apply on original site โ†—

College Board โ€“ Technology โ€“ Risk Engineering

Location: This is a fully remote role. Candidates who live near CB offices have the option of being fully remote or hybrid (Tuesday and Wednesday in office).
Type: This is a full-time position
About the Team

College Board โ€™s Enterprise Security Engineering (ESE) team currently consists of 6 full-time staff and additional contractors. ESE is responsible for implementing and managing cutting-edge security solutions and tools. We protect the confidentiality, integrity and availability of data and endpoints across physical and cloud environments. We protect workloads and data in AWS and Azure, corporate networks, user endpoints around the country and data in SaaS and PaaS environments. We enable our developers and colleagues to deliver new, secure digital offerings that include the Digital SAT and AP exams. The work we perform supports the College Board โ€™s mission to connect students to college success and opportunity. College Board is committed to creating an inclusive environment where all team members feel valued, respected, and supported in their work. We welcome individuals from diverse backgrounds and experiences to join our team and contribute to our ongoing success.โ€ฏ
About the Opportunity

As a Lead Risk Engineer, you will provide technical leadership for how College Board identifies, reviews, and manages risk across its technology systems. College Board 's technology footprint spans cloud infrastructure, vendor and API integrations, identity and access for automated systems, and an expanding set of AI and agentic capabilities โ€” and the organization needs a consistent, repeatable practice for assessing risk across all of it, not AI alone. This role exists to build and lead that practice.

You will work within an existing security engineering team and across the Technology division to run risk reviews of new and existing systems, define controls and identity practices for automated and machine-driven access (including AI agents and non-human identities where relevant), and partner with stakeholders across the organization to bring security into decisions early. You will not only execute this work โ€” you will shape the standards, patterns, and practices that let others execute it consistently, and you will lift the engineers around you through mentoring, paired reviews, and shared knowledge rather than becoming a single point of expertise.

This is a role for a technical leader comfortable operating across team and service boundaries, spanning risk domains where standards are still maturing โ€” from cloud and vendor risk to identity and access for automated systems to emerging technologies such as agentic AI. You will contribute to the strategic direction of the risk engineering program โ€” identifying risks and opportunities that influence roadmap decisions โ€” while remaining hands-on in reviews, threat modeling, and control design. Your impact will be measured in durable outcomes: reviews that are repeatable and evidenced, risk that is owned and documented rather than assumed, and stakeholders across the organization who engage security early because the engagement is practical and predictable.
In this role, you will:

Lead operational risk reviews and delivery enablement (45%)

-
Lead risk-based security reviews of technology implementations across domains โ€” including cloud architecture, application security, vendor/third-party integrations, identity and access, and emerging technologies such as GenAI and agentic AI systems โ€” assessing architectures, data flows, data classification handling, and misuse scenarios.

-
Evolve the risk review practice into a documented, repeatable methodology with risk tiering, reusable templates, decision records, and findings tracking.

-
Define and maintain secure-by-default standards, patterns, and reference guidance that reduce review friction and enable delivery teams to meet expectations on the first pass.

-
Cross team and service

โ† All remote jobs