Role descriptionPosition Title- AI Governance & Data Security ConsultantLocation- Toronto, ONWe are seeking an experienced AI Governance Consultant to support a strategic initiative focused on AI Governance, Data Security, and Security Posture Management. The ideal candidate will possess strong expertise in AI regulatory frameworks, governance standards, risk management, and security controls, with hands-on experience implementing governance programs for AI and data platforms.
This role will play a critical part in establishing governance frameworks, ensuring compliance with global AI regulations, and aligning AI deployments with enterprise security and risk management objectives.
Years of Experience: 7+ years
Technical SkillsRequired:- Strong understanding of:
- AI Governance frameworks.
- Responsible AI principles.
- AI Risk Management.
- Data Governance and Security.
- Model Risk Management.
- Experience implementing governance programs for AI, data platforms, cloud, or security initiatives.
- Knowledge of AI regulatory requirements and industry standards.
- Experience conducting risk assessments and compliance evaluations.
- Strong stakeholder management and cross-functional collaboration skills.
Required Standards & Regulatory Knowledge- AI Governance Standards
- ISO/IEC 42001 (AI Management System)
- NIST AI Risk Management Framework (AI RMF)
- OECD AI Principles
- Responsible AI frameworks
- Regulatory & Compliance Knowledge
- EU AI Act
- GDPR and privacy regulations
- Data governance and data protection requirements
- Emerging global AI regulations and compliance frameworks
- Security Standards (Preferred)
- ISO 27001
- NIST Cybersecurity Framework
- Data Security Posture Management (DSPM)
- Cloud Security Governance
Preferred- Experience with Generative AI governance programs.
- Experience implementing AI controls within Microsoft ecosystem.
- Experience working with large enterprise transformation initiatives.
- Strong understanding of data lineage, data classification, and AI model lifecycle governance.
Tools- Microsoft Purview
- Microsoft Security Copilot
- Microsoft Defender Suite
- DSPM solutions
- Data Classification and Data Loss Prevention (DLP)
- Cloud Security Posture Management (CSPM)
- Risk and Compliance platforms
- GCP
Preferred Certifications:- ISO/IEC 42001 Lead Implementer or Lead Auditor
- ISO 27001 Lead Implementer/Auditor
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Data Privacy Professional (CIPP)
- AI Governance or Responsible AI certifications
Key Responsibilities- Define and implement enterprise-wide AI Governance frameworks, policies, and operating models.
- Assess AI systems for compliance with regulatory and industry standards.
- Ensure alignment with emerging AI regulations, including the EU AI Act and other global AI governance requirements.
- Develop governance controls for responsible AI, model lifecycle management, risk assessment, and AI monitoring.
- Partner with Security, Data Governance, Privacy, Legal, and Compliance teams to integrate governance requirements across the organization.
- Support implementation of Data Security Posture Management (DSPM) and AI-related security controls.
- Conduct AI risk assessments, impact assessments, and compliance reviews.
- Establish governance processes for model inventory, documentation, explainability, transparency, and auditability.
- Define policies for AI data usage, data classification, retention, and protection.
- Create executive-level reporting, governance dashboards, and compliance metrics.
- Support security architecture reviews for AI and data platforms.
- Recommend controls to mitigate AI-specific cybersecurity, privacy, and data security risks.