Senior Staff, Data & AI Governance
Job description
Senior Staff, Data & AI Governance at Openloop Health.
About the role
OpenLoop is a company that brings care anywhere through telehealth support solutions designed to streamline go-to-market care delivery. The hire will own the day-to-day running of OpenLoop's AI governance program, including use-case intake, risk triage, and the AI Use Case Register. They will author and evolve the AI governance standard, keeping it aligned with U.S. regulatory changes and state AI laws. The role requires running intake and review to SLA, assessing new AI use cases, and driving findings to closure. They will prepare and lead AI Governance Council sessions to ensure decisions are recorded and acted upon. The hire will also help stand up and run the data governance program, including the Data Governance Council and data ownership models. They will measure adherence to standards and report on the organization's performance against data governance expectations.
Key facts
What you'll do
- Own and operate OpenLoop's AI governance program end-to-end, covering use-case intake, risk tripe scoring, the AI Use Case Register, issue tracking, and the AI Governance Council review cadence.
- Author and evolve OpenLoop's AI governance standard, including the scoring rubric, risk taxonomy, and review framework, while keeping it current with evolving AI risk frameworks and the U.S. regulatory landscape.
- Run intake and review to SLA by assessing new AI use cases, documenting risk and regulatory exposure, setting conditions of approval, and driving findings to closure.
- Prepare and lead AI Governance Council sessions, handling agenda creation, materials preparation, and ensuring decisions are made, recorded, and acted on without escalation.
- Help stand up and then run OpenLoop's data governance program using the same model, covering the Data Governance Council, the data governance standard, the enterprise data classification scheme, and the data ownership and stewardship model.
- Measure adherence to the data governance standard across operating teams and report clearly on where the organization meets or fails to meet these standards.
- Partner with teams that operate data day to day, including Privacy, Data Security, Data Protection (DLP), Data Platform, and Data Engineering & Analytics, setting the standards they run against and measuring compliance.
- Govern the data that feeds AI systems as a priority, focusing on provenance, lineage, classification, and quality of training and inference data to ensure models are built on trustworthy data.
- Assess AI vendor and model risk in partnership with Third-Party Risk, Security, and Legal, covering both standalone AI tools and AI features embedded in existing vendors.
- Maintain AI and data governance metrics, dashboards, and reporting, translating AI and data risk posture into language the leadership team and board can act on.
- Support SOC 2, HITRUST, and HIPAA assurance activities related to AI and data governance controls.
- Use AI to run the program, automating governance workflows for intake, scoring, evidence gathering, and reporting, and continuously improving these automations.
- Perform other duties as assigned by leadership and stakeholders.
Requirements
- 5-7 years experience in GRC (governance, risk and compliance), with at least 2 years hands-on in AI/ML governance or AI risk management.
- Experience with AI and data governance, including oversight of data flows and third-party risks.
- Experience with workflow automation, bringing specific hands-on experience with agentic tools like Claude Code.
- Experience with AI governance frameworks such as the NIST AI RMF, and the U.S. AI regulatory landscape, including new federal executive orders and emerging state AI laws.
- Experience building or operating an AI use-case intake, risk-scoring, and review process, including registers, review boards, or AI governance councils.
- Working knowledge of a data governance operating model, including classification, ownership and stewardship, lineage, and quality, ideally aligned to CDMC or DAMA-DMBOK.
- Proven experience standing up and running a data governance program.
- Ability to author governance standards and risk taxonomies, and measuring adherence to them.
- Experience with healthcare data, HIPAA, and PHI handling.
- Strong analytical and writing skills, capable of building a rubric, scoring a use case, and producing executive-ready reporting.
- Experienced with being an autonomous team player in a lean, fast-moving environment.
Nice to have
- AIGP (IAPP), ISO/IEC 42001 Lead Implementer, CIPP, CISA, or equivalent certifications.
- CDMC certification or hands-on experience standing up a data governance council, standard, or stewardship program.
- Experience supporting IPO readiness or SOC 2/HITRUST audit cycles.
- Experience governing third-party and embedded AI, and model risk.
- Familiarity with data lineage, classification, and catalog tooling.
Practical notes
None of the sections below apply to this role based on the SOURCE content.