About this role
Job title: AI Governance & Risk Analyst
About this role
The AI Governance & Risk Analyst keeps each client's Managed AI program current, usable, and defensible as tools and risks change. You'll turn usage and vendor signals into decisions, maintain the operating records behind those decisions, guide users toward approved practices, and coordinate the governance side of AI incidents.
Location & Travel
Hiring locations
- Tucson, AZ
- Remote
Travel requirement
No regular travel required.
International travel
Not required.
Compensation
Pay range
$75,000 to $95,000 per year
Offer factors
Where you land in the range depends on experience, certifications, and role scope.
What you'll do
-
Establish and maintain each client's AI inventory, sanctioned-tool list, Acceptable Use Policy, exception records, and vendor-onboarding workflow
-
Analyze DNS-layer shadow AI and Microsoft 365 usage signals, investigate material changes, and produce the monthly AI Usage Report
-
Review AI vendors for data access, retention, contractual, security, and material-change risks before approval and throughout the relationship
-
Maintain DPA and BAA inventories where applicable, including owners, status, renewal dates, approved data scope, and unresolved gaps
-
Run recurring policy, tool, and risk reviews; document decisions, assign remediation, and track open actions to closure
-
Package clear evidence and executive summaries for client leadership, insurance, audit, and governance reviews
-
Support role-based AI training and manager communications so approved tools, prohibited uses, and escalation paths become operating behavior
-
Coordinate AI-specific incident response, including triage, evidence collection, stakeholder communication, follow-up actions, and policy or control updates
-
What we're looking for
-
3+ years in IT governance, security GRC, or comparable risk-analysis role
-
Strong written communication and policy-drafting discipline
-
Familiarity with regulatory frameworks (HIPAA, SOC 2, NIST CSF, NIST AI RMF, ISO 42001)
-
Comfortable with technical security data (DNS logs, M365 audit, SIEM extracts)
-
Eligible to work in the U.S.
-
How We Work
-
Our Core Values
-
These four values are the same on every role. They describe how the team operates, not the duties of this posting.
-
Dream Big, Then Make It Real
-
Bring the ambitious idea, then do the work that makes it real. Ambition counts here, and so does follow-through.
-
Client Driven Results
-
Your scoreboard is the client's result. Find the solution, own the outcome, and treat their success as the job.
-
Own Your Progress
-
You own your work, your misses, and your next skill. We help. We do not hide from problems.
-
We Do It Right
-
Do the correct thing even when no one is watching. Quality is the job, not a slogan.
-
Equal Opportunity
-
Unió Digital hires for skill, character, and fit with our team. Full stop. We do not consider race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, marital status, or any other legally protected characteristic in employment decisions. If you need an accommodation during the application or interview process, we will figure it out together.