NE

Near Shore Cyber

AI GRC Consulting Partner

Job summary

United States
Legal

Work model

Fully remote
Only US
2 days ago
Job description

AI GRC Consultant --- Virtual Bench (United States Remote)

Location: 100% remote; candidates must reside in the United States

Opportunity type: Six-month development programme and non-exclusive consultant bench

Employment status: Bench membership is not employment and does not guarantee assignments or hours

Work authorization: Candidates must already be legally authorized to work in the United States. True Aleph cannot sponsor or assist with visas, work permits, or employment authorization.

About True Aleph

True Aleph (true-aleph.ai) is the AI governance and advisory division of Nearshore Cyber USA, LLC. We help organizations govern, secure, and operate artificial intelligence in line with business requirements, risk tolerances, and applicable obligations.

We are building a virtual bench of experienced consultants for client work in AI governance, risk, compliance, security, privacy, and assurance. The bench combines assessed practitioner readiness, common delivery methods, and independent quality review.

Follow True Aleph on LinkedIn at https://www.linkedin.com/showcase/true-aleph/

The opportunity

We are recruiting senior AI GRC consultants for an initial six-month development programme and virtual delivery bench.

This opportunity is intended for established security and GRC consultants who already have substantial client-delivery experience and demonstrable hands-on experience with AI. The programme develops and assesses the additional capabilities required to lead AI governance work. It is not an introductory cybersecurity or GRC course.

Selected candidates will complete structured learning, workshops, group projects, simulations, assessed work, and a capstone. Practitioners who demonstrate readiness may be considered for paid client engagements suited to their approved roles, availability, experience, and location.

Admission, participation, or graduation does not guarantee employment, certification, paid work, placement, or a minimum number of hours.

Work you may perform

Assignments will vary, but a senior consultant on the bench may be asked to:

  • Lead AI governance and GRC engagements from discovery and scoping through assessment, roadmap development, implementation support, and executive reporting.
  • Help clients establish AI governance models, decision rights, accountability, policies, risk tolerances, and review structures.
  • Resolve conflicts among laws, regulations, contracts, policies, standards, risk tolerances, and operating requirements.
  • Apply NIST AI RMF, ISO/IEC 42001, the EU AI Act, and related security, privacy, and assurance practices to actual AI systems and use cases.
  • Assess AI inventories, system boundaries, data flows, model and provider dependencies, agents, tools, permissions, and human-oversight arrangements.
  • Translate business and operational requirements into proportionate security, privacy, risk, and compliance controls.
  • Assess control design and operating effectiveness, identify evidence gaps, and recommend remediation priorities.
  • Develop risk, compliance, assurance, testing, and monitoring strategies.
  • Advise executives and boards on material AI exposures, available options, residual risk, and the evidence supporting a recommendation.
  • Lead third-party AI and model-provider assessments, including supply-chain, concentration, contractual, security, privacy, and operational risks.
  • Evaluate certification readiness and support clients preparing for audits without misrepresenting advisory work as independent certification.
  • Develop risk assessments, decision records, policies, control libraries, monitoring plans, remediation roadmaps, and executive reports.
  • Establish and maintain effective communication among technical, legal, privacy, security, audit, risk, compliance, and business stakeholders.
  • Mentor other consultants, review their work, and provide specific, evidence-based feedback.
  • Help develop True Aleph methods, templates, quality standards, reusable artifacts, and professional guidance.
  • Use approved AI tools responsibly while verifying material outputs and protecting client information.

Nearshore Cyber remains accountable for services delivered under its name. Consultants must follow the methods, review requirements, security controls, and engagement terms applicable to each assignment.

Required experience

You must have:

  • Ten or more years of professional experience in information technology or cybersecurity.
  • At least five years of client-facing GRC consulting experience with demonstrable depth in risk, controls, compliance, audit, or assurance.
  • Hands-on AI delivery experience in client, employer, or comparably accountable project settings. Personal projects and independent study may supplement, but do not replace, delivery evidence.
  • Experience implementing or operating security or compliance programmes.
  • Experience leading engagements and communicating with executive stakeholders.
  • Evidence that your recommendations have progressed beyond assessment into implementation, remediation, operation, or monitored production use.

Required framework and subject-matter fluency

You must be able to work at senior-consultant depth with:

  • NIST AI RMF, including Govern, Map, Measure, and Manage.
  • ISO/IEC 42001 management-system design and certification-readiness work.
  • Integration of an AI management system with an existing ISO/IEC 27001 information security management system.
  • The EU AI Act, including prohibited practices, risk classification, high-risk-system requirements, deployer obligations, technical documentation, transparency, human oversight, and post-market monitoring.
  • NIST Cybersecurity Framework, NIST SP 800-53, ISO/IEC 27001 and 27002, SOC 2, and CIS Controls.
  • Cybersecurity and privacy laws and regulations relevant to client engagements.
  • AI-system and data lifecycles, model and agent concepts, common architectures, data flows, model limitations, and emerging operating patterns.
  • AI security, including identity, access, prompt injection, data protection, third-party risk, secure development, testing, monitoring, and incident response.
  • Supply-chain and model-provider risk.
  • Risk assessment, control design, control testing, evidence evaluation, remediation planning, and assurance.
  • Cognitive bias and its effect on risk analysis and executive decision-making.

Required skills

You must be able to:

  • Define a system boundary and identify the evidence needed to support a decision.
  • Translate operational, legal, regulatory, and business requirements into implementable controls.
  • Assess security and governance controls for design and operating effectiveness.
  • Identify gaps in technical capability, evidence, accountability, and oversight.
  • Develop practical remediation and monitoring plans.
  • Evaluate vendor claims and technical documentation critically.
  • Facilitate disagreements among technical, legal, security, privacy, and business stakeholders.
  • Write concise findings, executive reports, decision records, and implementation guidance.
  • Present recommendations to clients, executives, boards, auditors, and other reviewers.
  • Lead delivery teams and review the work of other practitioners.
  • Use AI assistants and GRC tooling without delegating professional accountability to the tool.

Working-level technical literacy is required. This is not a model-building or MLOps position, but you must understand AI systems well enough to challenge vendor claims and direct appropriate technical review.

Required certifications

Both of the following are required for admission to the initial cohort:

  • ISACA Certified Information Systems Auditor (CISA).
  • ISO/IEC 27001 Implementer or Lead Implementer credential.

Preferred qualifications

The following are desirable but not required:

  • IAPP Artificial Intelligence Governance Professional (AIGP).
  • PCI Qualified Security Assessor (QSA).
  • Project Management Professional (PMP).
  • Experience with Vanta.
  • Experience with an enterprise GRC platform such as ServiceNow GRC, Archer, LogicGate, or Drata.
  • Experience evaluating or implementing an AI governance platform.
  • Familiarity with model-risk, drift-monitoring, bias-testing, fairness, or explainability tools.
  • Experience with Python, Microsoft Purview, or cloud AI platforms.
  • Active participation in relevant professional associations.
  • A record of speaking, teaching, publishing, or contributing to professional communities.
  • Professional Spanish for cross-border engagements.

English proficiency

Advanced professional English is required. Candidates must provide EF SET C1 or higher, or equivalent evidence of proficiency.

Programme commitment

The six-month programme requires:

  • One facilitated two-hour workshop each week.
  • Approximately 10--15 additional hours of independent and group work each week.
  • Up to 20 hours during some capstone and simulation weeks.
  • Participation in lectures, workshops, group projects, simulations, peer review, document production, and assessed exercises.
  • Compliance with programme confidentiality, intellectual-property, data-handling, professional-conduct, and approved-tool requirements.

The initial cohort carries no programme fee. Learning, simulation, and assessment activities are unpaid. Participants may be responsible for approved AI-tool subscriptions and examination fees. All expected participant-funded costs will be disclosed before acceptance.

Selection process

Every applicant must complete:

  • An application and eligibility review.
  • The 200-question AI GRC Consultant assessment in Aramis:Insight. The assessment is free to candidates.
  • Interviews covering GRC depth, AI experience, consulting judgment, communication, and ability to meet the programme commitment.
  • A final review based on the complete body of evidence.

Before the assessment, candidates will receive written information about its purpose, expected duration, permitted tools, integrity requirements, role in selection, retakes, result visibility, data handling, and retention.

Client engagements and compensation

Commercial client work is paid under a separate written agreement. Rates are established for each opportunity based on the role, scope, delivery responsibility, risk, market, location, and contracting entity. Compensation and payment terms are disclosed before the consultant accepts an engagement.

Bench participation is non-exclusive. Consultants may pursue other work and may decline any opportunity.

Graduates receive first consideration among comparably qualified practitioners for suitable engagements. Assignment decisions remain subject to demonstrated readiness, role fit, availability, conflicts, client requirements, budget, and an executed agreement.


Preview 2: Mexico

Senior AI GRC Consultant --- Virtual Bench (Mexico)

Location: 100% remote; candidates must reside in Mexico

Opportunity type: Six-month development programme and non-exclusive consultant bench

Employment status: Bench membership is not employment and does not guarantee assignments or hours

Work authorization: Candidates must already be legally authorized to work in Mexico. True Aleph and Nearshore Cyber cannot sponsor or assist with visas, work permits, or employment authorization.

About the programme

Nearshore Cyber, S.A. de C.V. recruits and staffs the Mexico-based members of the shared True Aleph AI GRC Virtual Bench.

True Aleph helps organizations govern, secure, and operate artificial intelligence in line with business requirements, risk tolerances, and applicable obligations. The virtual bench provides experienced consultants for work in AI governance, risk, compliance, security, privacy, and assurance across Mexico, the United States, and the wider Americas.

The bench combines assessed practitioner readiness, common delivery methods, regional knowledge, and independent quality review.

The opportunity

We are recruiting senior AI GRC consultants based in Mexico for an initial six-month development programme and virtual delivery bench.

This opportunity is intended for established security and GRC consultants who already have substantial client-delivery experience and demonstrable hands-on experience with AI. The programme develops and assesses the additional capabilities required to lead AI governance work. It is not an introductory cybersecurity or GRC course.

Selected candidates will complete structured learning, workshops, group projects, simulations, assessed work, and a capstone. Practitioners who demonstrate readiness may be considered for paid client engagements suited to their approved roles, availability, experience, language capabilities, and location.

Admission, participation, or graduation does not guarantee employment, certification, paid work, placement, or a minimum number of hours.

Work you may perform

Assignments will vary, but a senior consultant on the bench may be asked to:

  • Lead AI governance and GRC engagements from discovery and scoping through assessment, roadmap development, implementation support, and executive reporting.
  • Help clients establish AI governance models, decision rights, accountability, policies, risk tolerances, and review structures.
  • Resolve conflicts among laws, regulations, contracts, policies, standards, risk tolerances, and operating requirements.
  • Apply NIST AI RMF, ISO/IEC 42001, the EU AI Act, and related security, privacy, and assurance practices to actual AI systems and use cases.
  • Assess AI inventories, system boundaries, data flows, model and provider dependencies, agents, tools, permissions, and human-oversight arrangements.
  • Translate business and operational requirements into proportionate security, privacy, risk, and compliance controls.
  • Assess control design and operating effectiveness, identify evidence gaps, and recommend remediation priorities.
  • Develop risk, compliance, assurance, testing, and monitoring strategies.
  • Advise executives and boards on material AI exposures, available options, residual risk, and the evidence supporting a recommendation.
  • Lead third-party AI and model-provider assessments, including supply-chain, concentration, contractual, security, privacy, and operational risks.
  • Evaluate certification readiness and support clients preparing for audits without misrepresenting advisory work as independent certification.
  • Develop risk assessments, decision records, policies, control libraries, monitoring plans, remediation roadmaps, and executive reports.
  • Establish and maintain effective communication among technical, legal, privacy, security, audit, risk, compliance, and business stakeholders.
  • Mentor other consultants, review their work, and provide specific, evidence-based feedback.
  • Help develop True Aleph methods, templates, quality standards, reusable artifacts, and professional guidance.
  • Use approved AI tools responsibly while verifying material outputs and protecting client information.

Nearshore Cyber remains accountable for services delivered under its name. Consultants must follow the methods, review requirements, security controls, and engagement terms applicable to each assignment.

Required experience

You must have:

  • Ten or more years of professional experience in information technology or cybersecurity.
  • At least five years of client-facing GRC consulting experience with demonstrable depth in risk, controls, compliance, audit, or assurance.
  • Hands-on AI delivery experience in client, employer, or comparably accountable project settings. Personal projects and independent study may supplement, but do not replace, delivery evidence.
  • Experience implementing or operating security or compliance programmes.
  • Experience leading engagements and communicating with executive stakeholders.
  • Evidence that your recommendations have progressed beyond assessment into implementation, remediation, operation, or monitored production use.

Required framework and subject-matter fluency

You must be able to work at senior-consultant depth with:

  • NIST AI RMF, including Govern, Map, Measure, and Manage.
  • ISO/IEC 42001 management-system design and certification-readiness work.
  • Integration of an AI management system with an existing ISO/IEC 27001 information security management system.
  • The EU AI Act, including prohibited practices, risk classification, high-risk-system requirements, deployer obligations, technical documentation, transparency, human oversight, and post-market monitoring.
  • NIST Cybersecurity Framework, NIST SP 800-53, ISO/IEC 27001 and 27002, SOC 2, and CIS Controls.
  • Cybersecurity and privacy laws and regulations relevant to client engagements.
  • AI-system and data lifecycles, model and agent concepts, common architectures, data flows, model limitations, and emerging operating patterns.
  • AI security, including identity, access, prompt injection, data protection, third-party risk, secure development, testing, monitoring, and incident response.
  • Supply-chain and model-provider risk.
  • Risk assessment, control design, control testing, evidence evaluation, remediation planning, and assurance.
  • Cognitive bias and its effect on risk analysis and executive decision-making.

Required skills

You must be able to:

  • Define a system boundary and identify the evidence needed to support a decision.
  • Translate operational, legal, regulatory, and business requirements into implementable controls.
  • Assess security and governance controls for design and operating effectiveness.
  • Identify gaps in technical capability, evidence, accountability, and oversight.
  • Develop practical remediation and monitoring plans.
  • Evaluate vendor claims and technical documentation critically.
  • Facilitate disagreements among technical, legal, security, privacy, and business stakeholders.
  • Write concise findings, executive reports, decision records, and implementation guidance.
  • Present recommendations to clients, executives, boards, auditors, and other reviewers.
  • Lead delivery teams and review the work of other practitioners.
  • Use AI assistants and GRC tooling without delegating professional accountability to the tool.

Working-level technical literacy is required. This is not a model-building or MLOps position, but you must understand AI systems well enough to challenge vendor claims and direct appropriate technical review.

Required certifications

Both of the following are required for admission to the initial cohort:

  • ISACA Certified Information Systems Auditor (CISA).
  • ISO/IEC 27001 Implementer or Lead Implementer credential.

Preferred qualifications

The following are desirable but not required:

  • IAPP Artificial Intelligence Governance Professional (AIGP).
  • PCI Qualified Security Assessor (QSA).
  • Project Management Professional (PMP).
  • Experience with Vanta.
  • Experience with an enterprise GRC platform such as ServiceNow GRC, Archer, LogicGate, or Drata.
  • Experience evaluating or implementing an AI governance platform.
  • Familiarity with model-risk, drift-monitoring, bias-testing, fairness, or explainability tools.
  • Experience with Python, Microsoft Purview, or cloud AI platforms.
  • Active participation in relevant professional associations.
  • A record of speaking, teaching, publishing, or contributing to professional communities.
  • Professional Spanish and the ability to deliver client work in both English and Spanish.

Language requirements

Advanced professional English is required. Candidates must provide EF SET C1 or higher, or equivalent evidence of proficiency.

Professional Spanish is strongly preferred for Mexico-facing engagements. Bilingual delivery capability may be considered when consultants are matched to assignments.

Programme commitment

The six-month programme requires:

  • One facilitated two-hour workshop each week.
  • Approximately 10--15 additional hours of independent and group work each week.
  • Up to 20 hours during some capstone and simulation weeks.
  • Participation in lectures, workshops, group projects, simulations, peer review, document production, and assessed exercises.
  • Compliance with programme confidentiality, intellectual-property, data-handling, professional-conduct, and approved-tool requirements.

The initial cohort carries no programme fee. Learning, simulation, and assessment activities are unpaid. Participants may be responsible for approved AI-tool subscriptions and examination fees. All expected participant-funded costs will be disclosed before acceptance.

Selection process

Every applicant must complete:

  • An application and eligibility review.
  • The 200-question AI GRC Consultant assessment in Aramis:Insight. The assessment is free to candidates at https://www.project-aramis.com. Take the AI GRC Consultant assessment.
  • Interviews covering GRC depth, AI experience, consulting judgment, communication, and ability to meet the programme commitment.
  • A final review based on the complete body of evidence.

Before the assessment, candidates will receive written information about its purpose, expected duration, permitted tools, integrity requirements, role in selection, retakes, result visibility, data handling, retention, and cross-border processing.

Client engagements and compensation

Commercial client work is paid under a separate written agreement with the applicable Nearshore Cyber entity. Rates are established for each opportunity based on the role, scope, delivery responsibility, risk, market, location, and contracting entity. Compensation, currency, invoicing, payment timing, expenses, and applicable withholding terms are disclosed before the consultant accepts an engagement.

Bench participation is non-exclusive. Consultants may pursue other work and may decline any opportunity.

Graduates receive first consideration among comparably qualified practitioners for suitable engagements. Assignment decisions remain subject to demonstrated readiness, role fit, availability, conflicts, client requirements, budget, and an executed agreement.