Governance, Security & Compliance Specialist (AI Engagements)
Job Description:
- Review and enforce information security policies and cybersecurity standards across all engagement activities
- Guide teams on AI governance and responsible AI practices ("Knowledge AI"), ensuring AI systems are used and deployed ethically
- Ensure all data handling practices meet data protection and privacy requirements (e.g. GDPR or applicable local data privacy laws)
- Monitor and ensure engagement delivery meets regulatory requirements applicable to the financial services sector
- Apply and oversee model risk management practices for AI/ML models, including validation, documentation, and risk classification
- Review development practices against secure software development standards (secure SDLC, code review, vulnerability management)
- Assess and manage third-party risk management requirements for any vendors, tools, or sub-contractors involved in the engagement
- Coordinate resource background verification for all personnel assigned to the engagement
- Ensure confidentiality commitments (NDAs, data handling agreements) are signed and enforced
- Establish protocols for secure handling of sensitive information, including storage, access control, and transmission
Requirements
- 10+ years of experience in information security, IT compliance, risk management, or governance roles (financial services experience strongly preferred)
- Working knowledge of cybersecurity frameworks and standards (e.g. ISO 27001, NIST)
- Understanding of data privacy regulations such as GDPR, and any relevant local data protection laws
- Familiarity with financial sector regulatory requirements (e.g. relevant central bank guidelines, SOX, PCI-DSS, or similar depending on jurisdiction)
- Experience with model risk management frameworks (e.g. SR 11-7 or equivalent) is a plus
- Understanding of secure software development lifecycle (SDLC) practices
- Experience conducting or coordinating third-party/vendor risk assessments
- Ability to manage confidentiality processes, including NDAs and background verification procedures
- Strong attention to detail, integrity, and ability to work with sensitive/confidential information
- Relevant certifications (e.g. CISSP, CISA, CRISC, ISO 27001 Lead Auditor) are an advantage