Governance, Security & Compliance Specialist (AI Engagements)

Sri LankaSri Lanka·Colombomid
Legal & ComplianceCompliance Specialist
0 views0 saves0 applied

Quick Summary

Overview

Review and enforce information security policies and cybersecurity standards across all engagement activities Guide teams on AI governance and responsible AI practices ("Knowledge AI"),

Technical Tools
Legal & ComplianceCompliance Specialist
  • Review and enforce information security policies and cybersecurity standards across all engagement activities
  • Guide teams on AI governance and responsible AI practices ("Knowledge AI"), ensuring AI systems are used and deployed ethically
  • Ensure all data handling practices meet data protection and privacy requirements (e.g. GDPR or applicable local data privacy laws)
  • Monitor and ensure engagement delivery meets regulatory requirements applicable to the financial services sector
  • Apply and oversee model risk management practices for AI/ML models, including validation, documentation, and risk classification
  • Review development practices against secure software development standards (secure SDLC, code review, vulnerability management)
  • Assess and manage third-party risk management requirements for any vendors, tools, or sub-contractors involved in the engagement
  • Coordinate resource background verification for all personnel assigned to the engagement
  • Ensure confidentiality commitments (NDAs, data handling agreements) are signed and enforced
  • Establish protocols for secure handling of sensitive information, including storage, access control, and transmission

Requirements

~1 min read
  • 10+ years of experience in information  security, IT compliance, risk management, or governance roles (financial services experience strongly preferred)
  • Working knowledge of cybersecurity frameworks and standards (e.g. ISO 27001, NIST)
  • Understanding of data privacy regulations such as GDPR, and any relevant local data protection laws
  • Familiarity with financial sector regulatory requirements (e.g. relevant central  bank guidelines, SOX, PCI-DSS, or similar depending on jurisdiction)
  • Experience with model risk management frameworks (e.g. SR 11-7 or equivalent) is a plus
  • Understanding of secure software development lifecycle (SDLC) practices
  • Experience conducting or coordinating third-party/vendor risk assessments
  • Ability to manage confidentiality processes, including NDAs and background verification procedures
  • Strong attention to detail, integrity, and ability to work with sensitive/confidential information
  • Relevant certifications (e.g. CISSP, CISA, CRISC, ISO 27001 Lead Auditor) are an advantage

Location & Eligibility

Where is the job
Colombo, Sri Lanka
On-site at the office
Who can apply
LK

Listing Details

First seen
July 31, 2026
Last seen
August 5, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
51%
Scored at
July 31, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust

4 other jobs at george-bernard-consulting

View all →

Explore open roles at george-bernard-consulting.

Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

george-bernard-consultingGovernance, Security & Compliance Specialist (AI Engagements)