AI GRC Consulting Partner
RemoteUnited States
Job Summary
Lead AI governance and GRC engagements from discovery through assessment, roadmap development, and executive reporting. Help clients establish governance models, resolve regulatory conflicts, and apply NIST AI RMF, ISO/IEC 42001, and the EU AI Act to actual systems. Assess AI inventories, translate requirements into controls, and develop risk strategies with evidence-based remediation plans. Advise executives on material exposures and lead third-party model-provider assessments. Mentor other consultants, develop firm methods and templates, and use approved AI tools responsibly while verifying outputs. Complete a six-month development programme including workshops, simulations, and a capstone, followed by potential paid client engagements under separate agreements.
Required Qualifications
- Ten or more years of professional experience in information technology or cybersecurity
- At least five years of client-facing GRC consulting experience with demonstrable depth in risk, controls, compliance, audit, or assurance
- Hands-on AI delivery experience in client, employer, or comparably accountable project settings
- Experience implementing or operating security or compliance programmes
- Experience leading engagements and communicating with executive stakeholders
- Evidence that your recommendations have progressed beyond assessment into implementation, remediation, operation, or monitored production use
- NIST AI RMF, including Govern, Map, Measure, and Manage
- ISO/IEC 42001 management-system design and certification-readiness work
- Integration of an AI management system with an existing ISO/IEC 27001 information security management system
- The EU AI Act, including prohibited practices, risk classification, high-risk-system requirements, deployer obligations, technical documentation, transparency, human oversight, and post-market monitoring
- NIST Cybersecurity Framework, NIST SP 800-53, ISO/IEC 27001 and 27002, SOC 2, and CIS Controls
- Cybersecurity and privacy laws and regulations relevant to client engagements
- AI-system and data lifecycles, model and agent concepts, common architectures, data flows, model limitations, and emerging operating patterns
- AI security, including identity, access, prompt injection, data protection, third-party risk, secure development, testing, monitoring, and incident response
- Supply-chain and model-provider risk
- Risk assessment, control design, control testing, evidence evaluation, remediation planning, and assurance
- Cognitive bias and its effect on risk analysis and executive decision-making
- Define a system boundary and identify the evidence needed to support a decision
- Translate operational, legal, regulatory, and business requirements into implementable controls
- Assess security and governance controls for design and operating effectiveness
- Identify gaps in technical capability, evidence, accountability, and oversight
- Develop practical remediation and monitoring plans
- Evaluate vendor claims and technical documentation critically
- Facilitate disagreements among technical, legal, security, privacy, and business stakeholders
- Write concise findings, executive reports, decision records, and implementation guidance
- Present recommendations to clients, executives, boards, auditors, and other reviewers
- Lead delivery teams and review the work of other practitioners
- Use AI assistants and GRC tooling without delegating professional accountability to the tool
- Working-level technical literacy
- ISACA Certified Information Systems Auditor (CISA)
- ISO/IEC 27001 Implementer or Lead Implementer credential
- Advanced professional English
- EF SET C1 or higher, or equivalent evidence of proficiency
- One facilitated two-hour workshop each week
- Approximately 10–15 additional hours of independent and group work each week
- Up to 20 hours during some capstone and simulation weeks
- Participation in lectures, workshops, group projects, simulations, peer review, document production, and assessed exercises
- Compliance with programme confidentiality, intellectual-property, data-handling, professional-conduct, and approved-tool requirements
Desired Qualifications
- IAPP Artificial Intelligence Governance Professional (AIGP)
- PCI Qualified Security Assessor (QSA)
- Project Management Professional (PMP)
- Experience with Vanta
- Experience with an enterprise GRC platform such as ServiceNow GRC, Archer, LogicGate, or Drata
- Experience evaluating or implementing an AI governance platform
- Familiarity with model-risk, drift-monitoring, bias-testing, fairness, or explainability tools
- Experience with Python, Microsoft Purview, or cloud AI platforms
- Active participation in relevant professional associations
- A record of speaking, teaching, publishing, or contributing to professional communities
- Professional Spanish for cross-border engagements
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.