…

Manager II - Information Security

UST · IT Services & Consulting

  • Trivandrum, Chennai, Bangalore, Kochi
  • On-site
  • Posted today
  • Cybersecurity

About the job

AI Governance SME & Advisor — Role Description Programme: AI Security & Governance Programme Role overview We are seeking an experienced AI Governance SME to help establish, operationalise and embed our Client's enterprise AI governance framework as part of their AI Security & Governance Programme. You will advise senior stakeholders on how to govern AI responsibly and securely at enterprise scale, and on the establishment of frameworks, registers, processes and controls that make governance real. You will bring hands-on experience of AI governance frameworks, AI boards, registers and management processes: their use within large enterprises, and will be comfortable operationalising these through a dedicated AI Governance platform that acts as the client's system of record, risk management and control for AI. Key responsibilities AI governance framework and operating model (establishment and advisory) ● Design and establish the enterprise AI governance framework and target operating model, aligned to recognised standards and regulation (eg. ISO/IEC 42001, NIST AI RMF, the EU AI Act and the OECD AI Principles). ● Liaise with senior stakeholders to establish the AI Governance Board / AI Council — defining its mandate, membership, decision rights, terms of reference, escalation routes, meeting cadence and reporting lines — and integrate it with existing data, privacy, security, risk and procurement forums ● Liaise with senior stakeholder to define the AI governance operating model, including roles, responsibilities and a clear RACI across all stakeholder groups ● Design and stand up the AI use-case lifecycle: intake, triage, risk assessment, review, approval, ongoing monitoring and decommissioning ● Ensure AI policies, standards, acceptable-use guidance and Responsible AI principles (fairness, transparency, accountability, explainability and human oversight) are embedded into governance gates ● Act as trusted advisor and SME to leadership on AI governance, maturity uplift, and regulatory developments AI register, inventory and ownership ● Establish the AI Register as a single source of truth — including AI asset classification, risk tiering, risk mitigations and clear ownership and accountability AI Governance platform enablement ● Lead requirements definition, configuration and operationalisation of the client's AI Governance platform, covering workflows, registers, risk assessments, control libraries, evidence capture and reporting ● Map governance processes to platform workflows so that inventory, risk assessment, approvals and assurance are managed and evidenced through the platform AI risk management ● Support the development of templates for the AI risk taxonomy, risk-tiering methodology, controls mapping, exception and waiver framework and associated governance processes AI security controls and assessment (delivery) ● Support delivery of the programme, ensuring roadmap activities are progressed and tracked across all workstreams ● Develop and operationalise AI security controls, standards and procedures aligned to the AI framework ● Develop plans and processes for technical assessments of AI platforms, AI-enabled applications, AI agents, MCP integrations and embedded vendor AI capabilities ● Liaise with expert teams to define the security requirements for AI agents, including identity, privilege management, logging, monitoring, recertification and approval processes ● Create security guidance for AI development, secure prompt engineering, model consumption and AI-assisted development (“vibe coding”) practices Monitoring, shadow AI and incident response ● Establish AI security monitoring requirements and work with the Cyber Defence Centre (CDC) to develop detections, use cases, dashboards and reporting ● Support shadow AI discovery through analysis of Microsoft, AWS, SAP and other telemetry sources, helping identify unsanctioned AI usage and associated risks Reporting and assurance ● Produce management reporting, implementation metrics, control-effectiveness measures and quarterly assurance outputs for leadership review ● [Real-time monitoring for all registered AI assets in production?] Required skills and experience ● Demonstrable knowledge of the establishment of enterprise AI governance frameworks, operating models and AI governance boards ● Hands-on knowledge of the definition of AI registers and inventories, ownership models and AI management processes ● Sound understanding of AI regulation and standards, including the EU AI Act, ISO/IEC 42001 and NIST AI RMF, together with data-protection considerations (UK GDPR) ● AI security knowledge, ideally including the OWASP Top 10 for LLM Applications and MITRE ATLAS, and experience of AI threat modelling ● Excellent stakeholder management, advisory and communication skills, with the credibility to influence at senior and executive level Desirable qualifications ● ISO/IEC 42001 Lead Implementer or Lead Auditor ● IAPP AIGP (Artificial Intelligence Governance Professional) ● Relevant cloud certifications