06 Sep
|
Alvarez u0026 Marsal
|
Gurugram
06 Sep
Alvarez u0026 Marsal
Gurugram
Description
About Alvarez &
- Marsal
Alvarez &
- Marsal (A&M;) is a global consulting firm with over 10,000 entrepreneurial, action and results-oriented professionals in over 40 countries. We take a hands-on approach to solving our clients' problems and assisting them in reaching their potential. Our culture celebrates independent thinkers and doers who positively impact our clients and shape our industry. The team-oriented environment and engaging work—guided by A&M;'s core values of Integrity, Quality, Objectivity, Fun, Personal Reward, and Inclusive Diversity - are why our people love working at A&M.;
The Team The Security Governance, Risk and Compliance Senior Associate (AI) will play a key role in supporting the security governance and assurance activities associated with Alvarez &
- Marsal’s Artificial Intelligence Management System (AIMS). The role will primarily focus on the security aspects of AI governance, including ISO/IEC 42001 assurance, AI security risk and control assessments, audit activities, evidence gathering, risk reporting and corrective action followup. The role will also support the GRC Lead with relevant ISO/IEC 27001 surveillance and certification audit activities. The successful candidate will require a strong understanding of information security controls and AI-related security risks, with the ability to assess technical and procedural evidence and effectively communicate security requirements and identified risks to technical and non-technical stakeholders across the firm. The role provides independent security assurance over relevant aspects of the AIMS and does not own the implementation or operation of the controls it assesses.
How You Will Contribute
Management
- Develop rationale for prioritizing assurance activities, audit requests and workload based on risk and business requirements.
- Provide proactive updates and reporting on audit, assessment and remediation progress.
- Provide excellent and timely communication and service to business and technical stakeholders.
AI Security Governance &
- Risk
- Support the ongoing operation and continuous improvement of security governance activities within A&M;’s AIMS.
- Assess AI-specific security risks and controls across relevant stages of the AI system lifecycle, including those associated with areas such as AI models, data, access, third-party services, sub-processors and emerging AI technologies.
- Contribute security and assurance input to AI risk assessments and gap analyses,
identifying where controls may not adequately address applicable ISO/IEC 42001 requirements.
- Support the maintenance, monitoring and reporting of AI security risks through relevant GRC and risk management processes.
ISO/ IEX 42001 Audit &
- Assurance
- Plan and execute AI security assurance and audit activities aligned with ISO/IEC 42001.
- Support ISO/IEC 42001 certification, surveillance and internal audit activities.
- Evaluate applicable AI security and Annex A controls against organisational requirements and technical evidence.
- Conduct stakeholder interviews, review documentation and gather evidence relating to AI systems and supporting processes.
- Document non-conformities, control gaps and opportunities for improvement, and track corrective actions through to verified closure.
ISO/IEC 27001 Audit Support
- Support the GRC Lead with ISO/IEC 27001 surveillance, certification and internal audit activities.
- Coordinate and review audit evidence with relevant control and process owners.
- Support the tracking of non-conformities and corrective actions through to closure.
- Contribute to audit documentation and reporting
Risk Reporting &
- Stakeholder Communication
- Communicate identified AI security risks, control deficiencies and recommendations to technical and nontechnical stakeholders.
- Work closely with relevant stakeholders to understand AI systems, processes and associated security risks.
- Liaise with internal and external auditors and relevant system and process owners throughout the audit lifecycle.
- Engage Privacy, Legal and Compliance teams where assessments identify regulatory, contractual, privacy or data protection considerations requiring specialist input.
- Participate in governance activities including metrics gathering, risk reporting and recurring assurance activities.
Stakeholder Coordination
- Contribute to improvements in AI security governance, risk assessment and assurance processes.
- Support the development and maintenance of AI security control assessment methodologies, audit procedures and evidence requirements.
- Identify opportunities to integrate AI security assurance into existing GRC processes and tooling.
- Suggest and implement appropriate process improvements, including the use of Artificial Intelligence and automation.
- Maintain awareness of emerging AI security risks, relevant standards and industry good practice.
Qualifications
- 4+ years of relevant experience in information security, governance, risk management, technology risk, audit or a related discipline.
- Practical understanding of AI technologies and AI system lifecycles sufficient to assess associated security and control risks.
- Experience performing security control assessments, technology audits or risk assessments.
- Experience with ISO management systems, preferably ISO/IEC 42001, ISO/IEC 27001 or similar standards.
- Good understanding of information security controls and recognised security frameworks such as ISO/IEC 27001 and NIST.
- Strong analytical, technical writing and stakeholder communication skills.
- Ability to assess and communicate technical security requirements and risks across technical and non-technical teams
- ISO/IEC 42001 Lead Auditor certification or equivalent practical ISO/IEC 42001 audit experience.
- ISO/IEC 27001 Lead Auditor, CISA, CRISC, CISSP or equivalent certification.
- Familiarity with GRC platforms and broader security control assessment frameworks.
- Knowledge of AI-specific security risks including model governance, data security and residency, third-party and sub-processor assurance, and agentic/AI-agent risks.
- Experience within professional services, consulting or a similarly regulated, global environment.
Your journey at A&M; We recognize that our people are the driving force behind our success, which is why we prioritize an employee experience that fosters each person’s unique professional and personal development. Our robust performance development process promotes continuous learning, rewards your contributions, and fosters a culture of meritocracy. With top-notch training and on-the-job learning opportunities, you can acquire new skills and advance your career. We prioritize your well-being, providing benefits and resources to support you on your personal journey. Our people consistently highlight the growth opportunities, our unique, entrepreneurial culture, and the fun we have together as their favorite aspects of working at A&M.; The possibilities are endless for high-performing and passionate professionals.
📌 Senior Associate, Security, Governance, Risk & Compliance (AI), GESS - Global Capability Center (Gurugram)
🏢 Alvarez u0026 Marsal
📍 Gurugram