Job Overview
ONLY US CITIZENS. REMOTE.
We are seeking a highly skilled and strategic IT Compliance & AI Governance Consultant to partner directly with our client CTO office. In this role, you will be the foundational architect responsible for updating, scaling, and managing our corporate IT security frameworks and data governance models.
Your primary mandate will be to bridge departmental silos, conducting deep-dive discovery across the organization to map data flows and establish an accurate data inventory. You will ensure our technology ecosystem safely accommodates, governs, and scales Artificial Intelligence (AI) and Machine Learning (ML) initiatives, while maintaining bulletproof alignment with global security and privacy standards.
Key Responsibilities
1. Cross-Functional Discovery & Data Inventory
- Departmental Interviews: Conduct structured interviews and workshops with various department heads (e.g., Product, Engineering, Marketing, HR, Legal, and Sales) to comprehensively audit, discover, and document the flow of structured and unstructured data across the organization.
- Data Flow Mapping: Build and maintain an enterprise-wide data inventory and data lineage map, specifically identifying where sensitive data is stored, how it is ingested, and how it migrates across different systems.
- Shadow IT & AI Detection: Proactively identify and catalogue unauthorized "shadow" AI tools, SaaS platforms, and data repositories currently utilized by various business units.
2. AI & Data Governance Framework Architecture
- Adapt Data Frameworks: Redesign and expand the existing enterprise data governance framework to address specific AI risks (e.g., data lineage, synthetic data usage, retrieval-augmented generation (RAG) pipelines, and model training inputs) discovered during the inventory process.
- Ethical & Responsible AI: Establish policies surrounding algorithmic fairness, bias mitigation, explainability (XAI), transparency, and intellectual property (IP) protection regarding generative AI.
- Data Lifecycle Management: Define clear rules for data classification, minimization, retention, and isolation, specifically ensuring proprietary data is not leaked into public LLM training sets.
3. Security & Compliance Integration
- Framework Alignment: Manage, maintain, and map IT controls across core security frameworks such as SOC 2 Type II, ISO/IEC 27001, and NIST CSF.
- Incorporate AI Security Standards: Integrate emerging AI security frameworks, specifically ISO/IEC 42001 (Artificial Intelligence Management System) and the NIST AI Risk Management Framework (AI RMF), into the broader corporate compliance program.
- Regulatory Mapping: Ensure continuous adherence to evolving global regulations, including GDPR, CCPA/CPRA, and emerging AI-specific laws (e.g., the EU AI Act).
4. Risk Assessment & Third-Party Oversight
- AI Risk Assessments: Conduct comprehensive impact assessments on all internal and product-facing AI deployments to identify security vulnerabilities, potential model drift, and compliance gaps.
- Vendor Vetting: Evaluate third-party AI vendors, APIs, and SaaS tools. Formulate a vetting protocol to approve or deny incoming AI tech stacks based on security and data privacy mandates.
Required Qualifications & Skills
Experience & Education
- Experience: 3–6+ years of experience in IT compliance, information security auditing, data governance, or technology risk management.
- AI/ML Familiarity: Minimum 1–2 years of hands-on experience dealing with data privacy/governance issues explicitly related to cloud-native environments, big data pipeline architecture, or AI/ML model deployment.
- Education: Bachelor’s degree in information technology, Cybersecurity, Legal/Compliance, Data Science, or a related field (Master’s or JD a plus).
Technical & Leadership Skills
- Stakeholder Management & Discovery: Proven ability to interview diverse department leads, translate complex technical data workflows from engineering, and extract operational data usage habits from non-technical business units.
- Framework Expertise: Deep expertise in mapping controls for SOC 2, ISO 27001, and NIST. Strong familiarity with ISO/IEC 42001 and the NIST AI RMF.
- Technical Literacy: Ability to understand data infrastructure, API integrations, LLM guardrails, and access control models (RBAC/ABAC).
Preferred Certifications (One or more)
- IAPP Certified AI Governance Professional (AIGP) (Highly preferred).
- CISA (Certified Information Systems Auditor) or CRISC (Certified in Risk and Information Systems Control).
- CIPP/US/E (Certified Information Privacy Professional).
- CDMP (Certified Data Management Professional).
Pay: $60.00 - $63.00 per hour
Work Location: Remote