Sr. AI Risk Analyst
RemoteMexico or Colombia
Job Summary
Conduct AI, security, privacy, and data risk assessments across the AI lifecycle using structured methodologies aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF. Perform impact assessments to evaluate risks to individuals, safety, and fundamental rights, while identifying control gaps and defining treatment options. Embed governance requirements into AI use case intake, design, deployment, and monitoring through partnership with cross-functional stakeholders. Maintain AI system inventory and produce traceable, audit-ready documentation supporting conformity assessments and regulatory readiness. Continuously monitor systems for changes in risk, triggering reassessment and control updates. Provide actionable risk insights to technical teams, business stakeholders, and governance forums.
Required Qualifications
- Bachelor's degree in Computer Science, Information Systems, Risk Management, or related field, or equivalent experience
- Previous experience conducting structured risk assessments, with demonstrated use of formal methodologies (risk identification, analysis, evaluation, scoring, treatment)
- Hands-on experience performing AI risk and/or AI impact assessments, including evaluation of organizational, individual, and regulatory risk
- Proven ability to identify control gaps, evaluate control effectiveness, and define risk treatment and residual risk decisions
- Working knowledge of AI governance and risk frameworks, including ISO/IEC 42001, NIST AI RMF, and ISO/IEC 27001/27005
- Familiarity with EU AI Act concepts, including risk classification, high-risk systems, and core regulatory expectations (e.g., transparency, human oversight)
- Experience in a global, regulated environment, with exposure to privacy, data protection, and cross-border requirements
- Ability to translate technical and regulatory risk into clear, actionable business insights
- Demonstrated ability to work cross-functionally across Security, Privacy, Legal, Compliance, Technology, and Business teams
- Experience implementing or supporting AI governance programs and lifecycle-based risk management
- Experience with AI risk classification, impact assessment, or regulatory alignment related to EU AI Act or similar frameworks
- Experience producing audit-ready documentation and evidence supporting risk, controls, and governance decisions
- Familiarity with AI-specific risks, including bias, explainability, data quality, model drift, and system robustness
- Experience supporting conformity assessment or regulatory readiness activities
- Relevant certifications (e.g., ISO/IEC 42001, ISO/IEC 27001, CISSP, CISM, CRISC, AIGP)
Desired Qualifications
- Demonstrated governance-first mindset and ability to operate in evolving regulatory environments
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.