About WGA Consulting
WGA Consulting is a global management consulting firm and a world-class alternative to the big-name consulting firms. We help senior leaders make and execute the decisions that matter most, across AI and digital transformation strategy, ESG, growth, culture, operations, and enterprise transformation. Our firm focuses on areas of senior management concern, creating enduring value and delivering measurable impact at the intersection of strategy, technology, and operating model design. WGA's WGA Advisors AI Workforce Solutions practice is at the forefront of helping global enterprises move from isolated AI experimentation to scaled, business-led agentic AI deployment.
The Situation
WGA Advisors is delivering an AI Workforce program for an enterprise client preparing to move from AI experimentation to production AI Agents. A completed readiness diagnostic identified a set of security control gaps that gate deployment:
- The security framework aligns to ISO 27000 series guidance and NIST but carries no certification or third-party attestation, so control evidence for an AI environment would be assembled by hand rather than produced on demand.
- Managed Security Operations Center coverage is scoped only to the top two asset criticality tiers, leaving the remainder of the estate unmonitored.
- No business continuity plan exists, and disaster recovery is backup and restore rather than a standby posture.
- Segregation of duties is defined but confirmed manually, with no governance, risk, and compliance toolset licensed, across a large enterprise resource planning user population.
- Periodic access recertification does not run, and privileged administrative access is concentrated in very few individuals.
- An annual information technology general controls audit is performed by an external firm, so an audited baseline exists, but findings are remediated outside any managed control system.
An enterprise resource planning replacement program is underway in parallel, which paces when a stable control environment can be evidenced.
The certification case is an AI case. Every additional AI Agent widens the attack surface and increases the volume of automated reads and writes against systems of record. Without certified controls, agent-era access, logging, segregation of duties, and recovery cannot be evidenced to a regulator, a customer, or the board.
The Opportunity
WGA Advisors is engaging a Lead Consultant to take the client from a self-defined security framework to a certified ISO/IEC 27001 information security management system, and to prepare and carry the client through third-party certification audit.
This is a hands-on implementation and audit readiness role, not an assessment-only role. The consultant builds the management system, drives control remediation with named client owners, closes the business continuity and recovery gaps, manages the certification body relationship, and runs the client through Stage 1 and Stage 2 to certificate.
The role works alongside engagement leadership, the client's cybersecurity and infrastructure functions, the enterprise resource planning program team, internal audit, and the parallel data classification workstream.
This is a temporary project-based engagement of 9 to 12 months, structured around scoping, gap closure, evidence window, and certification audit. Strong potential for extension based on performance and continued client demand across WGA's pipeline.
Core ResponsibilitiesScoping and gap assessment
- Define and document the information security management system scope, boundaries, and interfaces, recommending a first-certification scope that is defensible and achievable, typically shared information technology services plus the first operating unit in scope, with a documented path to extend
- Perform the Annex A control gap assessment against the existing framework, and produce the Statement of Applicability with justified inclusions and exclusions
- Incorporate the findings of the most recent information technology general controls audit and any open remediation items into the gap plan rather than running a parallel exercise
- Build the remediation plan with named client owners, dependencies, effort estimates, and dates, and run it to closure
Management system build
- Author the policy set, information security management system manual, and supporting procedures
- Establish the risk assessment and risk treatment methodology, populate the risk register, and run the first treatment cycle to management approval
- Establish the asset inventory and criticality tiering model, and align monitoring and recovery coverage to it
- Define roles, responsibilities, and competence requirements, and stand up management review, internal audit, corrective action, and continual improvement processes
- Deliver awareness and role-based training, and evidence its completion
Control remediation
- Design and implement access control remediation across a large enterprise resource planning user population, including a workable periodic access recertification cycle mapped to job function and position, and privileged account governance where privileged access is concentrated in very few individuals
- Design the segregation-of-duties control approach, including a compensating manual control set sufficient for initial certification where no governance, risk, and compliance toolset is licensed, and frame the toolset purchase as a subsequent-year decision rather than a certification blocker
- Extend logging, monitoring, and Security Operations Center coverage beyond the top two asset criticality tiers, and define what agent-generated activity must be logged
- Establish supplier and cloud provider security requirements, including contractual control clauses, audit and access rights, incident notification, and exit provisions
- Confirm control operation across cloud-hosted enterprise resource planning, the data platform, and the supporting application estate
Business continuity and disaster recovery
- Perform the business impact analysis and set recovery time and recovery point objectives with business owners
- Author the business continuity plan, which does not exist today, and the supporting incident and crisis management procedures
- Lift disaster recovery from backup and restore toward a standby posture appropriate to the criticality tiers, and specify the technical and commercial requirements to get there
- Build and run the test and exercise calendar, and evidence the results
AI and agent control extension
- Map AI Agent and automation risks into the management system risk register and control set, rather than treating them as outside the scope
- Extend identity, access, logging, and change control to non-human accounts and agent identities
- Align the management system with ISO/IEC 42001 and related AI management guidance where it strengthens the certification case, without expanding scope beyond what is achievable in the first cycle
- Confirm that the evidence an AI governance board requires can be produced from the same control environment
Certification readiness and audit management
- Select and contract the certification body, and manage that relationship through to certificate
- Plan the evidence window and audit calendar, sequencing the window to start after enterprise resource planning hypercare sign-off so that evidence reflects the steady-state environment
- Run the internal audit and a full mock audit, and close findings before Stage 1
- Prepare and support the client through Stage 1 and Stage 2 audits, manage auditor requests, and drive nonconformity closure to certificate
- Transition surveillance audit readiness and the operating cadence to client ownership
Qualifications
Education
- Bachelor's degree required in a relevant discipline, including but not limited to Information Systems, Computer Science, Cybersecurity, Engineering, or a closely related technical field
- Strong academic record from a recognized institution
Experience
- 10 years of overall professional experience, including delivery with a tier-one consulting firm such as BCG, Accenture, or Deloitte
- At least two full ISO/IEC 27001 implementations personally led from scoping through to a granted certificate, with references
- Experience in complex, multi-entity organizations where scope definition and shared services boundaries are contested
- Experience remediating information technology general controls audit findings, and working alongside external auditors
- Track record of client-facing delivery under structured acceptance criteria, change control, and tier-one consulting quality standards
Required certifications
- ISO/IEC 27001 Lead Implementer required. ISO/IEC 27001 Lead Auditor strongly preferred
- CISA, CISM, or CISSP a plus. ISO/IEC 22301 or ISO/IEC 42001 credentials a plus
Required expert skills
- Expert-level authorship of the full management system documentation set, including the Statement of Applicability, risk methodology, and procedures that survive auditor scrutiny
- Practical control remediation in enterprise resource planning environments, including access recertification at scale, privileged access, and segregation of duties without a dedicated governance, risk, and compliance toolset
- Business impact analysis, business continuity plan authorship, and disaster recovery uplift specification
- Certification body selection and audit management, including Stage 1 and Stage 2 preparation and nonconformity closure
Technical fluency
- Strong command of ISO/IEC 27001 and 27002, with working knowledge of the NIST Cybersecurity Framework and how an existing NIST-aligned framework maps to Annex A
- Working knowledge of SAP environments, public cloud infrastructure, managed Security Operations Center models, identity and access management, and logging and monitoring architectures
- Familiarity with the agentic AI landscape and the control implications of autonomous reads and writes against systems of record
- Working knowledge of data classification and data loss prevention as Annex A control dependencies, and the ability to coordinate with the parallel classification workstream without duplicating it
Communication and execution
- Clear written and verbal communication, including the ability to hold a control position with an auditor and to explain a remediation trade-off to an executive committee
- Proven ability to deliver on a pipelined schedule with iterative feedback, tight timelines, and high quality standards
- Demonstrated ownership, follow-through, and the ability to drive remediation owned by client staff who do not report to the consultant
Engagement Details
- Duration: 6 months
- Work location: Remote, with periodic on-site presence at the client site as required by the remediation, internal audit, and certification audit cadence
- Travel: Periodic travel to the client site as required, including presence for Stage 1 and Stage 2 audits
- Language: Professional written and spoken English required
- Authorization: Must be authorized to work in the consultant's country of residence and able to travel internationally as required
WGA Consulting is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity or expression, national origin, disability, protected veteran status, or any other characteristic protected under federal, state, or local law, where applicable.
Pay: $85.00 - $95.00 per hour
Benefits:
Work Location: Remote