Skip to main content
Airbnb

Process Risk and Compliance Operations Manager

RemoteUnited States only· except AK, India, Niger +9 more
Published
Role
Operations
Experience
Lead
Employment
Full-time
Company size
Enterprise
$156k–$193k/yr
Check eligibility

Open to US only · except AK, IN, NE, ND, OH, SD, WI, AL, MS, OK, DE, RI. Set where you work from to check your eligibility.

No BS summary

Risk and Compliance Operations Manager needed for Airbnb's Community Support organization. Requires 10+ years in risk management/compliance, proven program management for cross-functional remediation, and experience governing AI/ML systems. Must be able to synthesize complex information into executive-level narratives and influence senior leaders.

Core skills

risk frameworksrisk registryAI risk governance

Required skills

risk managementcompliancegovernanceoperational riskprogram managementAI risk management frameworksNIST AI RMFISO 42001EU AI Act compliance frameworksfraud risk frameworkssafety risk frameworksinsider threat risk frameworksGRC platformsrisk management toolscase management systemsinvestigation ticketing platforms

Optional skills

contact center operationsprocess designoptimizationcustomer support strategiesquality assurance

Required languages

English

What you'll do

  • Own the strategic design and continuous evolution of risk frameworks, the risk registry, and executive risk narratives for Community Support
  • Translate investigative findings, AI/ML model outputs, operational signals, and emerging threats into decisions and actions that protect Airbnb
  • Ensure that investigative outcomes are contextualized within the broader risk ecosystem — informing risk appetite decisions, shaping detection strategy, and driving remediation accountability
  • Co-own escalation frameworks, jointly challenge detection model effectiveness, and ensure that the feedback loop between investigations, risk governance, and AI-driven detection is robust and continuously improving
  • Serve as the program manager for systemic root cause resolution — ensuring that when investigations, incidents, or risk assessments reveal structural vulnerabilities, those root causes do not languish in a findings log but are tracked, assigned, resourced, and driven to completion across the organization
  • Serve as a risk steward for AI systems that touch Community Support — leading governance and discussions of the implications of deploying AI in high-stakes decision-making environments
  • Design and own the CS Risk Appetite Framework — define guardrails, escalation triggers, and pre-approved response actions
  • Own and evolve the CS Risk Registry as a living strategic instrument
  • Develop and stress-test risk assessment standards — including key risk indicators (KRIs), risk typologies, and emerging threat hypotheses
  • Support the evolution of models and processes used in detection triage and investigation — not by building models, but by interrogating model assumptions and sources of risk
  • Establish ongoing governance cadences — risk review boards, quarterly risk assessments, and challenge sessions where risk assumptions are pressure-tested by diverse stakeholders, not simply ratified
  • Collaborate closely with the Insider Threat Investigations to ensure investigative outcomes are systematically captured, contextualized, and integrated into risk governance
  • Co-design escalation and review protocols for high-severity investigation findings and risk non-compliant transactions
  • Participate in joint case reviews, postmortems, and incident debriefs to extract systemic insights
  • Provide strategic risk context to the Investigations team — help prioritize investigative focus areas based on risk registry intelligence, KRI trends, and organizational risk appetite rather than solely on case volume or severity scores
  • Coordinate the feedback loop between investigations and AI-driven detection systems — ensuring that investigative findings inform detection improvements, and that detection model performance is tracked, challenged, and reported as part of the broader risk posture
  • Own the end-to-end lifecycle of root cause resolution — from the moment a systemic root cause is identified (through investigations, incidents, postmortems, risk assessments, or AI model failures) through to verified remediation and closure
  • Maintain and govern a centralized root cause and remediation tracker that captures all identified systemic issues, assigns clear ownership, defines resolution milestones and deadlines, and provides real-time visibility into remediation progress
  • Distinguish between symptomatic fixes and true root cause resolution
  • Drive cross-functional remediation workstreams — coordinate across relevant partner teams to ensure that root cause resolution plans are resourced, sequenced, and executed
  • Track resolution effectiveness over time — monitor whether implemented fixes actually reduce the recurrence of the underlying risk
  • Integrate root cause intelligence into the risk registry and risk appetite framework
  • Report on root cause resolution health to senior leadership — including metrics on open vs. closed root causes, average time to resolution, aging items, recurrence rates, and cross-functional accountability
  • Craft and deliver executive-level risk narratives, provide the interpretive layer that tells leadership what the data means, what decisions are required, and what trade-offs are at stake
  • Own the reporting architecture — determine what should be measured, how it should be presented, and to whom
  • Define and maintain monitoring thresholds and escalation triggers in collaboration with the Investigations Manager
  • Translate investigative findings, root cause resolution status, and AI model performance data into actionable risk mitigation recommendations
  • Drive cross-functional risk alignment — serving as the connective tissue that ensures risk is managed holistically rather than in silos
  • Lead systemic risk reviews — going beyond surface-level incident response to identify structural vulnerabilities, incentive misalignments, and process design flaws that create risk
  • Champion the integration of risk thinking into operational design — ensuring that new processes, tools, and AI deployments are evaluated through a risk lens before launch, not after failure
  • Serve as a change agent for risk culture — moving the organization from reactive compliance toward proactive risk intelligence
  • Provide leadership and mentorship to more junior team members — developing their ability to think critically about risk, challenge data, and communicate effectively with senior stakeholders
  • Design and deliver risk and compliance training that goes beyond checkbox compliance — building genuine risk literacy across CS teams, including an understanding of AI risks and limitations
  • Foster a culture of constructive challenge — where team members are expected to question assumptions, flag concerns, and contribute to the continuous evolution of the risk program

What they require

  • Bachelor's degree in Business, Risk Management, Finance, Operations, or related field (advanced degree preferred), or equivalent practical experience.
  • 10+ years of experience in risk management, compliance, governance, or operational risk — with a demonstrated track record of building and evolving risk frameworks, registries, and reporting programs (not just maintaining them).
  • Proven program management capability — specifically the ability to drive complex, cross-functional remediation and root cause resolution efforts from identification through verified closure.
  • Experience collaborating with or providing strategic oversight to investigations teams — with a strong understanding of how investigative findings translate into enterprise risk intelligence and governance action.
  • Demonstrated ability to evaluate and govern AI/ML systems from a risk perspective — you do not need to build models, but you must be able to critically assess model assumptions, failure modes, bias risks, and governance requirements.
  • Experience challenging technical teams on AI outputs and driving human-in-the-loop governance is essential.
  • Proven ability to synthesize ambiguous, complex, and sometimes conflicting information into clear risk narratives and strategic recommendations for executive audiences.
  • Strong organizational influence and stakeholder management skills — with a track record of driving cross-functional alignment, navigating ambiguity, and influencing senior leaders without direct authority.
  • Critical thinking and intellectual curiosity — a default posture of healthy skepticism toward automated outputs, historical baselines, and consensus assumptions.
  • Ability to adapt and innovate, challenge the status quo, and identify new solutions while effectively balancing risk, speed, and cost.
  • Experience with AI risk management frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act compliance frameworks) or direct involvement in governing AI systems in operational environments.
  • Experience developing fraud, safety, or insider threat risk frameworks, strategies, and operational models.
  • The role may include occasional work at an Airbnb office or attendance at offsites, as agreed to with your manager.
  • Airbnb,Inc. can employ in states where we have registered entities. Currently, employees can not be located in: Alaska, Indiana, Nebraska, North Dakota, Ohio, South Dakota, Wisconsin, Alabama, Mississippi, Oklahoma, Delaware and Rhode Island.
  • This list is continuously evolving and being updated, please check back with us if the state you live in is on the exclusion list.
  • If your position is employed by another Airbnb entity, your recruiter will inform you what states you are eligible to work from.

Benefits

  • This role may also be eligible for bonus, equity, benefits, and Employee Travel Credits.

American online platform for rental accommodations

🇺🇸 United StatesHospitalityEnterpriseairbnb.com/

What people say about this company

4.2/ 5

$156k–$193k/yr