AI Governance Specialist

CGI

$95K — $145K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years in AI governance, data governance, technology risk, or compliance
  • Expertise applying the NIST AI RMF and ISO/IEC 42001 frameworks
  • Experience in Canadian privacy laws, including PIPEDA and Quebec's Law 25
  • Hands-on experience conducting AI and technology risk assessments
  • Proven ability to author and implement governance processes and policies
  • Strong stakeholder management and facilitation skills
  • Degree in Information Science, IT Management, Law, or related fields

Responsibilities

  • Implement and uphold enterprise AI governance frameworks and policies
  • Manage the AI intake and review process end-to-end
  • Collaborate with stakeholders throughout the AI lifecycle
  • Conduct AI risk assessments and develop necessary controls
  • Maintain a register of approved AI use cases and models
  • Translate compliance requirements into actionable guidance
  • Track and respond to changes in Canada’s AI policy environment

Benefits

  • Support for AI literacy through training and resources
  • Opportunities for collaboration with various business units
  • Engagement with cutting-edge AI governance practices
  • Participation in workshops and cross-functional teams
  • Role in shaping organizational AI strategy and compliance
Full Job Description
AI Governance Specialist

Category: Analytics and Emerging Digital Technologies

Main location: Canada, Ontario, Toronto

Position ID:J0826-1822

Employment Type: Full Time

Position Description:

Are you an experienced AI professional with expertise in governance, risk or compliance who wants to shape how artificial intelligence is actually used inside an organization not just how it's described in a policy binder? Do you regularly find yourself in conversations where everyone agrees AI needs guardrails, but nobody can tell you where the training data came from, who approves the use case, who owns the model once it's live, or what happens when it drifts?

If you have the expertise to turn frameworks like the NIST AI RMF and ISO/IEC 42001 into intake forms, risk tiers, control checklists and decision rights that teams will actually follow, a genuine flair for solving ambiguous problems, and the mindset to collaborate with legal, privacy, security, data and business stakeholders alike, we're looking for you.

**Working knowledge of the NIST AI Risk Management Framework and ISO/IEC 42001 is required for this role Intermediate and Senior profiles both welcome**

Your future duties and responsibilities:

As an AI Governance Specialist on this team your responsibilities will include:
• Implementing and maintaining the enterprise AI governance framework policies, standards, guardrails, acceptable use practices and supporting controls aligned to an agreed implementation roadmap
• Operating the AI intake and review process end to end: triage, risk classification, assessment of value, data suitability, explainability and organizational readiness, and recommendation or escalation along defined approval paths
• Partnering with stakeholders across the full AI lifecycle, from use case intake through development, deployment, monitoring and retirement
• Conducting AI risk assessments and embedding risk based controls covering human accountability, override mechanisms, auditability, documentation, monitoring and retirement criteria
• Governing the data that feeds AI systems provenance, lawful basis and consent for secondary use, licensing and IP constraints, classification and handling, de identification, residency and cross border transfer, and permission inheritance so that RAG and copilot deployments don't quietly overexpose information
• Maintaining the enterprise register of approved AI use cases, models, tools, integrations, risks and realized outcomes, including third party and embedded vendor AI
• Translating Canadian and international requirements into practical implementation guidance technical teams can act on PIPEDA, Quebec's Law 25 (including automated decision transparency and cross border transfer assessments), Alberta and BC privacy legislation, applicable public sector and health information statutes, human rights and accessibility obligations, and, where relevant to our markets, the EU AI Act
• Tracking Canada's evolving AI policy landscape the post AIDA legislative patchwork, federal privacy and digital safety bills in progress, sector guidance such as OSFI Guideline E 23, and provincial developments and advising leadership on what changes for us and when
• Defining governance expectations for third party AI providers data handling, model transparency, subprocessor disclosure, evaluation evidence, exit and portability in partnership with Legal, Privacy, Security and Procurement
• Assessing and mitigating risks specific to modern AI systems, including hallucination, model drift, bias and discriminatory outcomes, data leakage, prompt injection, over reliance, shadow AI and unsafe automation, and recommending where decisions must remain human owned or deterministic
• Extending governance to agentic and multimodal systems: tool and data permissions, non human identity, action logging, audit trails and containment boundaries
• Defining what "monitored" means in practice for AI in production the evidence, logging and review cadence a system must sustain to stay approved and working with engineering teams to make that measurable rather than aspirational
• Facilitating workshops and working sessions with cross functional teams to gather requirements, resolve gaps and drive adoption of governance practices
• Building out the governance operating model forums, ownership structures, decision rights, RACI and supporting tooling
• Preparing executive level reporting: maturity assessments, governance KPIs, dashboards, adoption metrics, governance findings and roadmap updates for senior leadership
• Supporting AI literacy across the organization through plain language guidance, playbooks, templates, training and decision guides
• Monitoring program progress, surfacing risks early and recommending mitigation strategies to keep delivery on track

Required qualifications to be successful in this role:
• Minimum 3+ years' experience in AI governance, data governance, technology risk, privacy or compliance including hands on development and implementation of frameworks, policies and controls
• Demonstrated proficiency applying the NIST AI RMF and ISO/IEC 42001; working familiarity with OECD AI Principles and the EU AI Act
Practical experience with Canadian privacy and data protection requirements, including PIPEDA and Quebec's Law 25, and their application to AI use cases
• Hands on background conducting AI, privacy, algorithmic or technology risk assessments and embedding risk based controls across enterprise systems
• Proven experience authoring governance processes, standards, policies and operating models and getting them adopted
• Sufficient technical fluency to hold a credible conversation with data engineers and ML practitioners about pipelines, model lifecycle, evaluation and monitoring, without needing to build the models yourself
• Ability to communicate complex governance and technical concepts credibly to both technical and non technical audiences
• Experience producing executive presentations, dashboards and status reporting for senior leadership
• Strong stakeholder management and facilitation skills, with the ability to influence across functions without direct authority including holding a governance position under pressure while keeping the relationship intact
• Degree or diploma in Information Science, IT Management, Law, Compliance, Policy Management, Computer Science, Data Science or a related discipline; equivalent demonstrated expertise will be considered

Nice to Have Qualifications:
• Experience collaborating on building an AI control plane a centralized enforcement layer for model access and routing, policy and guardrail application, prompt and output logging and retention, PII and secret redaction, entitlement propagation, rate and cost controls, and approved tool registries including the practical work of getting teams to route through it rather than around it
• Experience with AI agent monitoring and observability project instrumentation and tracing of agent runs and tool calls, evaluation pipelines and automated quality checks, drift and regression detection, incident detection and replay, and the use of platforms such as LangSmith, Langfuse, Arize, MLflow Tracing, Azure AI Foundry, Datadog LLM Observability or similar; familiarity with OpenTelemetry GenAI semantic conventions is a plus
• Experience translating observability telemetry into governance evidence the audit trail, control attestations and management reporting that satisfy internal audit or a regulator
• Certifications such as IAPP AIGP, CIPP/C, CIPM, CISA, CRISC, CISM, or ISO/IEC 42001 Lead Implementer or Lead Auditor
• Experience implementing governance programs in large, complex or federated organizations
• Familiarity with sector specific Canadian requirements relevant to our business for example OSFI Guideline E 23 (Model Risk Management, effective May 1, 2027) and B 10 for federally regulated financial institutions, provincial health information legislation, or the Treasury Board Directive on Automated Decision Making and Algorithmic Impact Assessment in the public sector
• Exposure to model risk management practice, model registries, model cards and dataset documentation
• Awareness of additional standards such as ISO/IEC 23894, ISO/IEC 27001 and 27701, and the NIST Generative AI Profile
• Practical working familiarity with large language models, copilots, RAG architectures, agentic workflows, MCP based tool integrations and AI systems connected to enterprise data
• Experience supporting vendor governance, AI tool rationalization or platform centralization initiatives
• Understanding of data sovereignty and residency considerations in a Canadian context, including cloud region strategy
• Experience designing and delivering training, communications or change readiness programs for technology adoption
• Familiarity with Agile delivery, change management practices and MLOps tooling

CGI is providing a reasonable estimate of the pay range for this role. The determination of this range includes factors such as skill set level, geographic market, experience and training, and licenses and certifications. Compensation decisions depend on the facts and circumstances of each case. A reasonable estimate of the current range is $95 000-$145 000. This role is an existing vacancy.

Skills:
  • Data Engineering
  • Data Engineering
  • Data Migration
  • Data Modeling
  • Data Validation
  • Data Warehousing
  • English

Similar Jobs

More Jobs at CGI

More Information Technology Jobs

Find similar AI Governance Specialist jobs: