Governance, Security & Compliance Specialist (AI Engagements)

  • Colombo, Sri Lanka
  • Full-Time
  • On-Site

Job Description:
  • Review and enforce information security policies and cybersecurity standards across all engagement activities
  • Guide teams on AI governance and responsible AI practices ("Knowledge AI"), ensuring AI systems are used and deployed ethically
  • Ensure all data handling practices meet data protection and privacy requirements (e.g. GDPR or applicable local data privacy laws)
  • Monitor and ensure engagement delivery meets regulatory requirements applicable to the financial services sector
  • Apply and oversee model risk management practices for AI/ML models, including validation, documentation, and risk classification
  • Review development practices against secure software development standards (secure SDLC, code review, vulnerability management)
  • Assess and manage third-party risk management requirements for any vendors, tools, or sub-contractors involved in the engagement
  • Coordinate resource background verification for all personnel assigned to the engagement
  • Ensure confidentiality commitments (NDAs, data handling agreements) are signed and enforced
  • Establish protocols for secure handling of sensitive information, including storage, access control, and transmission

Requirements

  • 10+ years of experience in information  security, IT compliance, risk management, or governance roles (financial services experience strongly preferred)
  • Working knowledge of cybersecurity frameworks and standards (e.g. ISO 27001, NIST)
  • Understanding of data privacy regulations such as GDPR, and any relevant local data protection laws
  • Familiarity with financial sector regulatory requirements (e.g. relevant central  bank guidelines, SOX, PCI-DSS, or similar depending on jurisdiction)
  • Experience with model risk management frameworks (e.g. SR 11-7 or equivalent) is a plus
  • Understanding of secure software development lifecycle (SDLC) practices
  • Experience conducting or coordinating third-party/vendor risk assessments
  • Ability to manage confidentiality processes, including NDAs and background verification procedures
  • Strong attention to detail, integrity, and ability to work with sensitive/confidential information
  • Relevant certifications (e.g. CISSP, CISA, CRISC, ISO 27001 Lead Auditor) are an advantage