AI Engineer – Controls & Capability Enablement

Location
Hamilton
Workplace
On-site

About this role

About Rockefeller Capital Management

Rockefeller Capital Management was established in 2018 as a leading independent financial advisory services firm. Originally founded in 1882 as the family office of John D. Rockefeller, the Firm has evolved to offer strategic advice to ultra- and high-net-worth individuals and families, institutions, and corporations from offices in 35 markets throughout the United States, as well as an office in London. The Firm oversees $228 billion in client assets as of July 31, 2026.


Position

The primary purpose of this role is to enable the safe, deliberate, and accelerated adoption of AI across Rockefeller Capital Management. Partnering closely with Risk, Compliance, Cybersecurity (CISO), and AI Risk Governance teams, the individual translates governance requirements into scalable technical controls that govern the firm's AI ecosystem, including agents, copilots, skills, plugins, connectors, and the large language models that power them.

 

AI platforms evolve rapidly, with new models, capabilities, and features released on a near-weekly basis. This role is responsible for staying ahead of that pace by continuously evaluating emerging technologies from providers such as Microsoft, Anthropic, and other vendors. The individual will assess new capabilities through both a business value and risk lens, providing clear recommendations on whether they should be adopted, piloted, restricted, or deferred.

 

This is a highly hands-on technical role focused on operationalizing AI governance. Rather than creating policy, the individual interprets existing requirements and implements them directly through platform configuration, policy enforcement, APIs, automation, and administrative tooling across Microsoft and Anthropic environments. The goal is to ensure AI controls are embedded, measurable, and enforceable while supporting the firm's continued innovation and growth.


Responsibilities

  • Interpret and implement enterprise control requirements. Translate policies, standards, and risk decisions issued by Risk, Compliance, the CISO organization, and AI Risk Governance into concrete technical controls, review gates, and deployment standards for AI capabilities.
  • Configure and script the controls. Implement guardrails directly across Microsoft and Anthropic services — tenant and admin center settings, Copilot and Copilot Studio policies, Azure AI Foundry configuration, Anthropic enterprise administration, Entra access policies, and Purview data protection controls.
  • Automate governance at scale. Build scripts and automation (PowerShell, Graph API, Python, KQL) to inventory agents and skills, enforce policy, detect drift, monitor usage, and produce audit and compliance evidence.
  • Own agents and skills end to end. Maintain the inventory, ownership model, and lifecycle — from intake and review through deployment, monitoring, recertification, and retirement.
  • Run capability review assessments. Evaluate new AI features and use cases against firm-defined risk, security, and compliance criteria — covering business value, security exposure, data access and entitlement impact, supervisory obligations, operational readiness, and fit with enterprise
  • architecture standards — and escalate to the appropriate governance body where a policy decision is required.
  • Assess LLMs and model changes. Test and compare models across providers, track model and version updates, evaluate capability shifts and failure modes, and provide the technical evidence governance bodies need to decide where each model may be used.
  • Stay ahead of AI evolution. Systematically track roadmaps, release notes, and previews across Microsoft 365 Copilot, Copilot Studio, Azure AI Foundry, Anthropic, and emerging platforms, and translate each change into a clear enable, pilot, restrict, or defer recommendation.
  • Implement controls for safe sharing and reuse. Configure how agents and skills are scoped, shared, and permissioned in line with approved requirements, including departmental boundaries, intent review, and guardrails against unintended data exposure.
  • Partner across the firm. Work closely with Risk, Compliance, the CISO organization, AI Risk Governance, platform engineering, product, and business teams to confirm intent, close gaps, and ensure capabilities launch with the required controls already in place.
  • Report clearly to leadership and governance forums. Produce decision records, review summaries, control evidence, and executive-ready briefings on AI capability posture, risks, and adoption

Qualifications

  • Bachelor’s degree in Computer Science, Information Systems, Data Science, Cybersecurity, or a related technical field.
  • 5+ years in enterprise technology, with at least 2 years working directly with generative AI, LLMs, copilots, or agent platforms.
  • Demonstrated hands-on experience configuring tenants, platform, or security controls — not just specifying them.
  • Proficiency in scripting and automation with PowerShell, Python, Microsoft Graph API, and KQL, applied to policy enforcement, monitoring, or audit reporting.
  • Hands-on experience with at least one major enterprise AI platform: Microsoft 365 Copilot, Copilot Studio, Azure AI Foundry, or Anthropic Claude.
  • Working knowledge of how agents, skills, prompts, grounding, connectors, and retrieval behave — including where they can leak data or produce unreliable results.
  • Strong grasp of identity, access, and data protection fundamentals, ideally in an Entra and Purview environment.
  • Proven ability to read a policy or control standard and determine what it means in practice for a platform configuration.
  • Clear, concise writing and the confidence to present recommendations to senior stakeholders.

Skills

  • Familiarity with AI cost and consumption management — token metering, prompt-caching economics, spending limits, and chargeback or show back models.
  • Exposure to responsible AI or AI risk frameworks such as the NIST AI Risk Management Framework or ISO/IEC 42001.
  • Familiarity with AI supply-chain risk — untrusted skills, plugins, and MCP servers as an attack vector — and with registry, scanning, and gating approaches to control them.
  • Practical experience with model evaluation, benchmarking, red-teaming, or prompt-injection and jailbreak testing.
  • Experience ingesting AI platform telemetry into Microsoft Sentinel or Defender XDR and extending incident-response playbooks to AI-specific alerts.
  • Experience with network- and proxy-layer enforcement of AI traffic, including application-identity or URL-category policy, TLS inspection, and egress control for cloud-resident agents that bypass the corporate firewall.
  • Familiarity with Microsoft Purview DLP, sensitivity labels, Entra External ID, and data entitlement enforcement.
  • Hands-on experience deploying client and endpoint policy through Intune or Group Policy — for example, pinning an AI desktop application to the enterprise tenant and forcing SSO.
  • Familiarity with agent and non-human identity models, including on-behalf-of execution, admin-assigned agent permissions, and central agent registration in Entra, Agent 365, or Azure AI Foundry.
  • Experience administering the agent and skill lifecycle in Copilot Studio, Agent 365, or Anthropic enterprise administration — inventory, ownership, sharing controls, and inactivity review.
  • Experience with infrastructure-as-code or configuration management (Terraform, Bicep, ARM) applied to platform governance.
  • Experience supporting technology intake, control testing, or audit and evidence process.
  • Experience in financial services or another regulated industry, including familiarity with supervisory and recordkeeping obligations.
  • Experience validating audit, e-discovery, and records-retention coverage for a new platform, including provider compliance or audit APIs and OpenTelemetry-based log export.

Compensation Range

The anticipated base salary range for this role is $150,000 to $200,000. Base salary for the role will depend on several factors, including a candidate’s qualifications, skills, competencies, and experience, and may fall outside of the range shown. In addition, this role may be eligible for a discretionary bonus. Rockefeller Capital Management offers a comprehensive benefit package including health coverage, vacation time, paid leave, retirement plan, and more. Visit careers.rockco.com to learn more about additional opportunities and benefits offerings.


Disclosure

Rockefeller & Co. LLC, Rockefeller Financial LLC, Rockefeller Trust Company, N.A., The Rockefeller Trust Company (Delaware), Rockefeller Financial Services, Inc. and all other subsidiaries of Rockefeller Capital Management L.P. (individually and collectively, “Rockefeller”) is an equal opportunity employer and does not discriminate on the basis of race, religion, sex, gender, sexual orientation, gender identity or expression, national origin, citizenship, age, military or veteran status, marital or partnership status, caregiver status, legally recognized disability, or any other basis protected by applicable federal, state or local law (“protected characteristics”).

 

Rockefeller Capital Management participates in the E-Verify program in certain locations, as required by law.

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?

Top Benefits

  • Health coverage
  • Vacation time
  • Paid leave
  • Retirement plan