Job Title: GRC Consultant - AI Security Management Systems
EC Council is the worlds largest cyber security technical certification body. We operate in 170 countries globally and we are the owner and developer of various world-famous cyber security programs. We are proud to have trained and certified over 400,000 information security professionals globally that have influenced the cyber security mindset of countless organizations worldwide.
www.eccouncil.org
Role Overview:
GRC Consultant to help clients assess, design, and operate AI Security Management Systems (AISMS) that demonstrably assess & govern their AI estate. The ideal candidate combines a solid GRC/audit/security foundation with real, working exposure to how AI systems are built and can carry both into a client engagement.
Key Responsibilities:
Assessment & Gap Analysis: Assess AI governance posture against ISO/IEC 42001, the NIST AI Risk Management Framework, and applicable regulation; build AI system inventories and risk-tiered remediation roadmaps.
Management System Design: Draft AI governance policies, intake and approval workflows, risk registers, and statements of applicability; define control ownership across the three lines of defence.
Audit & Certification Readiness: Run mock audits and evidence sampling; prepare clients for internal audit and third-party certification, and support surveillance and recertification cycles.
Third-Party AI Risk: Assess third-party models, GenAI SaaS features, and agentic integrations; review vendor AI provisions and help clients maintain AI bills of materials.
Client Enablement: Facilitate workshops across legal, security, data science, and audit stakeholders; produce assessment reports, board papers, and training material.
Mentorship: Mentor junior consultants on AI governance methodology and client delivery.
Required Qualifications & Skills:
Education & Experience
Years of Experience: 2 to 5 years in GRC, IT audit, information security, or privacy,
with meaningful exposure to AI-specific governance, risk, or assurance work.
Education: Bachelor's degree in a related field.
Certifications: AI governance credential (e.g. IAPP AIGP or ISO/IEC 42001 Lead Auditor); ISO/IEC 27001 Lead Auditor or Lead Implementer, or CISA/CISM/CRISC is a plus.
Technical Literacy: Working understanding of the AI/ML lifecycle nd foundation vs. fine-tuned models, agentic tool use, and where governance gaps typically hide nd sufficient to hold a credible conversation with an ML engineer.
About Our Culture:
EC-Council is driven by a mission to strengthen global cybersecurity capability and advance the profession of ethical hacking and information security. Our teams operate across regions and cultures, united by integrity, professionalism, and a commitment to meaningful impact. Continuous learning and accountability are encouraged, empowering individuals to take ownership of their contributions.
Respect, trust, and ethical conduct guide how we work with colleagues, partners, and the global cybersecurity community.
Additional Information:
EC-Council is an equal prospect workplace and an affirmative action employer. We are committed to providing equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or veteran status. We do not discriminate based on these or any other characteristics protected by applicable laws or regulations in the locations where we operate.
EC-Council is dedicated to working with and providing reasonable accommodations to individuals with disabilities. If you have a medical condition or disability that limits your ability to complete any part of the application process and require reasonable accommodation, please contact us at
[email protected] and let us know how we can assist.
To be eligible for this position, candidates must be able to provide proof that they are either a citizen of the country or have legal authorization to work in the country where the position is posted and are currently residing there. EC-Council does not offer employment to ineligible candidates and reserves the right to revoke employment in case the candidate loses the authorization to work.
If, as part of the recruitment process, you are required to complete or submit any form of work, project, case study, or assignment, please note that such material will be considered the exclusive property of EC-Council. By submitting such work, you acknowledge that EC-Council retains all rights, title, and interest in the submitted content, including any intellectual property contained therein.
Candidates further waive any intellectual property or moral rights in such submissions, confirm that the work is original and free of third-party infringement, and acknowledge that it is provided solely for evaluation purposes, with no ownership or other rights retained.
Our Privacy Policy outlines how we collect, use, store, and protect your personal data during the recruitment process. This may include information such as your name, contact details, employment history, qualifications, and any other details you provide as part of your application. All data is handled in compliance with applicable data protection and privacy regulations.
Please review our policy here: EC-Council Privacy Policy- User & company | Data Protection. Submission of your application will be considered as your acceptance of the terms stated above.
📌 GRC Consultant AI Security (Hyderabad)
🏢 EC-Council
📍 Hyderabad