(usa) Risk Expert III

Walmart Walmart · Retail · HERNDON, VA TECH FACILITY VA Herndon, ISD - DGTC AR BENTONVILLE

This role focuses on developing and updating technology, AI, and information security policies and standards, evaluating policy revisions for control integrity and risk gaps, and performing risk assessments for AI initiatives. The primary goal is to ensure compliance with industry frameworks and drive remediation actions, leveraging AI and automation tools to enhance policy management processes.

What you'd actually do

  1. Develop and update technology, AI, and information security policies and standards to ensure compliance with industry frameworks (PCI‑DSS, HIPAA, NIST).
  2. Evaluate policy revisions to ensure strong control integrity, identify risk and compliance gaps, and recommend targeted improvements.
  3. Maintain and perform risk assessments and risk registers for technology and AI initiatives, driving appropriate remediation actions.
  4. Collaborate with Legal, Regulatory, AI Security, Data Governance, Decision Science, Audit, and business teams to ensure policy alignment and consistent governance.
  5. Translate complex policy requirements into clear, actionable guidance that supports global adoption and implementation.

Skills

Required

  • At least 5 years of experience in risk management, policy development, or a related field.
  • Strong understanding of technology compliance standards and emerging risks within technology and information security.
  • Proven experience in writing and updating policy documents to align with market specific compliance and business needs.
  • Proven experience in supporting business process improvement and implementation projects
  • Excellent communication and interpersonal skills, with the ability to effectively navigate multiple stakeholder groups.
  • Experience with various technologies, including AI.
  • Strong analytical and problem-solving skills, with the ability to assess risk and develop mitigation strategies.
  • Bachelor's degree in a related field (e.g., computer science, information assurance, law, or a related field).

Nice to have

  • Certification in Security+, GISF, GSEC, CISA, CISSP, or CCSP
  • Master’s degree in Computer Science, Information Technology, Engineering, Information Systems, Cybersecurity, or related area
  • background in creating inclusive digital experiences, demonstrating knowledge in implementing Web Content Accessibility Guidelin

What the JD emphasized

  • AI
  • policy and controls management program
  • technology and information security policies
  • risk assessments
  • compliance