Senior Director, AI Operations Governance
The Senior Director, AI Operations Governance leads the operational engine that governs how The Coca-Cola Company designs, reviews, approves, deploys, and retires Artificial Intelligence across the enterprise. The role establishes and runs the intake, review, and approval process for AI use cases across every function and Operating Unit worldwide — enabling the business to move at speed while ensuring every AI solution is safe, secure, standardized, and compliant with Company policy and applicable law.
Reporting to the Senior Vice President & Chief Information Security Officer (CISO), this role serves as the CISO organization's senior operating leader on AI Governance and as a member of the Company's AI Risk Governance Council. Under delegated authority, the Senior Director holds tiered decision rights — approving lower-risk use cases within defined guardrails, requiring corrections on cases that don't meet standard, and escalating high-risk, novel, or regulated use cases to the Council or CISO for final decision.
This is a people-leader role. The Senior Director builds and leads a global team of governance professionals and partners closely with Legal, Privacy, the Data & AI organization, Cyber Risk, Cyber Defense, Internal Audit, and business leaders across Operating Units — bringing the enterprise one clear, consistent, and credible AI governance experience from idea to production and beyond.
AI Operational Governance Program Ownership
Own the Company's enterprise AI operations governance model — the process, standards, roles, decision rights, and tools that govern AI use cases at Coca-Cola.
Set the operating cadence — intake reviews, tiered risk boards, exception forums, and escalation paths to the AI Risk Governance Council.
Use-Case Intake, Review & Approval
Classify each use case (including tools and products) by risk tier using clear, published criteria that reflect strategic alignment, business impact, return on investment, data sensitivity, model type, autonomy, and regulatory exposure.
Under delegated authority, approve, require corrections on, or deny lower- and medium-risk use cases within defined guardrails.
AI Solution Lifecycle Governance
Embed governance into the full AI solution lifecycle — ideation, design, data sourcing, build, validation, deployment, ongoing monitoring, re-validation, and retirement.
Define lifecycle gates and evidence requirements appropriate to each risk tier (e.g., human oversight, bias and fairness testing, security review, privacy review, model documentation, monitoring plan).
Oversee operations of model provisioning and approval, agent build approval, agent publishing approval, and approval of models and tools to be used Company-wide.
Policies, Standards & Guardrails
Own the Company's AI operating standards, and operating guardrails, keeping them clear, current, and workable for the business with oversight from the AI Risk Governance Council.
Coordinate with Legal, Privacy, Cyber Risk Management, Data & AI, and Ethics & Compliance so guardrails reflect legal, regulatory, ethical, security, and business realities.
Cross-Functional Partnership & Council Engagement
Serve as a working member of the AI Risk Governance Council (Chair: CISO; Vice-Chair: Senior Director Cyber Risk Management), bringing forward operational insight, decision papers, and escalations.
Partner day-to-day with Legal, Privacy, the Data & AI organization, Ethics & Compliance, Internal Audit, and Cyber leadership to ensure a single, coherent enterprise governance experience.
Regulatory & Standards Alignment
Ensure the operating program aligns to leading standards — including NIST AI Risk Management Framework and ISO/IEC 42001 — and to the global body of AI regulation, including the EU AI Act, Chinese AI rules, U.S. state AI laws, and emerging frameworks in other Coca-Cola markets.
AI Inventory, Reporting & Assurance
Maintain an accurate, enterprise-wide inventory of AI systems, their risk tiers, owners, decisions, and lifecycle status.
Produce clear, executive-framed reporting to the CISO, Cyber Risk Management, the Council, and senior management on AI operational governance posture, throughput, risk trends, and material decisions.
Develop and maintain a regular cadence with Cyber Risk Management (Senior Director, Cyber Risk) on AI Policy adherence, AI risk and issues trends, data feeds for Cyber GRC risk reporting and metrics for AI, challenges in execution of AI controls, and AI Council escalations.
Support Internal Audit, external auditors, and regulator engagements with defensible narratives, decision records, and evidence.
Set a clear vision, hire strong talent, and develop a deep bench of AI operations professionals, both global/corporate and at the operating unit level.
Hold the team accountable for outcomes — throughput, decision quality, evidence rigor, and business enablement.
Minimum 15+ years of progressive experience in AI governance, technology risk, data governance, privacy, or regulatory compliance in large, global organizations, with a meaningful portion focused on AI or emerging technology.
Strong working command of leading AI governance frameworks (NIST AI RMF, ISO/IEC 42001) and the global AI regulatory landscape (EU AI Act, Chinese AI rules, U.S. state AI laws).
Working knowledge of AI technology fundamentals — machine learning, large language models, agentic AI, third-party AI — enough to engage credibly with technical and business teams.
Proven ability to operate across a networked, matrixed, global organization and partner ecosystem (Operating Units, bottling system, or analogous complex networks).
Strong people-leadership experience, including hiring, developing, and leading multi-disciplinary global teams.
Experience partnering closely with Legal, Privacy, Data, Cyber, Ethics & Compliance, and Internal Audit on cross-functional governance.
Relevant certifications such as IAPP AIGP, CIPP/E, CIPM, CDPSE, CISM, or CRISC are strongly preferred.
Bachelor's degree in Law, Public Policy, Information Systems, Computer Science, Data Science, Risk Management, or related field required.
Master's degree, JD, MBA, or advanced credential (AIGP, CIPP/E, CISSP, CISM, or equivalent) highly desirable.
The Coca-Cola Company will not offer sponsorship for employment status (including, but not limited to, H1-B visa status and other employment-based nonimmigrant visas) for this position. Accordingly, all applicants must be currently authorized to work in the United States on a full-time basis and must not require The Coca-Cola Company's sponsorship to continue to work legally in the United States.
Pay Range:
United States of America: 202,000 USD - 229,000 USD
Base pay offered may vary depending on geography, job-related knowledge, skills, and experience. A full range of medical, financial, and/or other benefits, dependent on the position, is offered.
Annual Incentive Reference Value Percentage:
30
Annual Incentive reference value is a market-based competitive value for your role. It falls in the middle of the range for your role, indicating performance at target.
Location(s):
United States of America
City/Cities:
Atlanta
Travel Required:
00% - 25%
Relocation Provided:
No
Job Posting End Date:
August 14, 2026
Our Purpose and Growth Culture:
We are taking deliberate action to nurture an inclusive culture that is grounded in our company purpose, to refresh the world and make a difference. We act with a growth mindset, take an expansive approach to what’s possible and believe in continuous learning to improve our business and ourselves. We focus on four key behaviors – curious, empowered, inclusive and agile – and value how we work as much as what we achieve. We believe that our culture is one of the reasons our company continues to thrive after 130+ years. Visit Our Purpose and Vision to learn more about these behaviors and how you can bring them to life in your next role at Coca-Cola.
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, national origin, religion, sexual orientation, gender identity and/or expression, status as a veteran, and basis of disability or any other federal, state or local protected class. When we collect your personal information as part of a job application or offer of employment, we do so in accordance with industry standards and best practices and in compliance with applicable privacy laws.
Pay Range:United States of America: 0 USD - 0 USD
Base pay offered may vary depending on geography, job-related knowledge, skills, and experience. A full range of medical, financial, and/or other benefits, dependent on the position, is offered.
Annual Incentive Reference Value Percentage:30
Annual Incentive reference value is a market-based competitive value for your role. It falls in the middle of the range for your role, indicating performance at target.
Long-term Incentive Reference Value Percentage:0 - 20
Long-term Incentive reference value is a market-based competitive value for your role.