Role Purpose
The Senior Consultant AI & ISMS Delivery will support hands-on delivery of AI Governance and Information Security Management System (ISMS) initiatives.
The role focuses on following tasks, aligned with ISO 27001 and ISO 42001 frameworks under the guidance of the Lead Consultant.
- executing assessments,
- developing documentation,
- supporting audits, and
- implementing controls
Key Responsibilities
AI Governance & Responsible AI
- Support AI governance implementation aligned with ISO/IEC 42001 and NIST AI RMF
- Perform AI risk assessments covering bias, fairness, explainability, robustness, and privacy
- Assist in AI use-case classification and risk scoring
- Maintain AI registers, risk logs, and governance documentation
- Support reviews of GenAI, analytics, and automated decision systems
ISMS Implementation & Cyber Governance
- Execute ISO/IEC 27001 ISMS activities including:
- Risk assessments and risk treatment plans
- Control mapping and implementation support
- Statement of Applicability (SoA)
- Develop and maintain ISMS documentation such as policies, standards, procedures, and guidelines
- Support internal audits, management reviews, and certification readiness activities
- Assist with third-party, cloud, and technology risk assessments
Risk, Compliance & Reporting
- Conduct technology and vendor risk assessments
- Map controls to ISO 27001, ISO 42001, NIST CSF, and regulatory requirements
- Prepare audit evidence and compliance artifacts
- Support dashboards, metrics, and management reporting
Required Skills & Experience
- 68 years of experience in Information Security, GRC, Technology Risk, or Cybersecurity
- Hands-on experience with ISO 27001 ISMS implementation or support
- Experience in risk assessments, control testing, and compliance documentation
- Basic to intermediate exposure to AI governance, model risk, or data governance
- Strong analytical, documentation, and stakeholder coordination skills
Preferred Certifications
ISO 27001 Lead Implementer or Lead Auditor, CISA / CRISC / CISM (any one preferred)
AI Governance, Data Privacy, or GRC-related certifications (added advantage)
Key Deliverables
ISMS risk assessment and treatment documentation
AI governance support artifacts and risk logs
Audit-ready evidence packs and compliance reports
Client-ready assessment and status reports