Senior Associate, Security, Governance, Risk & Compliance (AI), GESS - Global Capability Center

Alvarez & Marsal

Gurugram District

On-site

INR 2,400,000 - 4,200,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Alvarez & Marsal is seeking a Senior Associate for AI Security Governance to support security governance and assurance for the AI Management System. You will assess AI security risks, perform ISO/IEC 42001 related audits, and coordinate with GRC, Privacy, Legal and Compliance teams across the firm.

The role emphasizes documenting non-conformities, tracking corrective actions, and communicating risks to both technical and non‑technical stakeholders within a global professional services

Qualifications

  • 4+ years in information security, governance, risk management or auditing.
  • Practical understanding of AI security risks and AI system lifecycles.
  • Experience with ISO 42001 and ISO 27001 audit activities.

Responsibilities

  • Plan and execute AI security assurance and audits aligned with ISO 42001.
  • Support ISO 42001 certification, surveillance and internal audits.
  • Assess AI security risks across models, data, access and third parties.
  • Report risk findings to technical and non-technical stakeholders.
  • Coordinate with Privacy, Legal and Compliance teams on regulatory concerns.
  • Maintain audit documentation and track corrective actions to closure.

Skills

Information security
Governance
Risk management
Audit
ISO 42001
ISO 27001
CISA
CISSP
NIST
GRC tools

Education

Lead Auditor ISO 42001
Lead Auditor ISO 27001
CISA Certification

Tools

GRC platforms
Audit management tools

Job description

About Alvarez & Marsal

Alvarez & Marsal (A&M) is a global consulting firm with over 10,000 entrepreneurial, action and results-oriented professionals in over 40 countries. We take a hands-on approach to solving our clients' problems and assisting them in reaching their potential. Our culture celebrates independent thinkers and doers who positively impact our clients and shape our industry. The collaborative environment and engaging work—guided by A&M's core values of Integrity, Quality, Objectivity, Fun, Personal Reward, and Inclusive Diversity - are why our people love working at A&M.

Description

Alvarez & Marsal (A&M) is a global consulting firm with over 10,000 entrepreneurial, action and results-oriented professionals in over 40 countries. We take a hands‑on approach to solving our clients' problems and assisting them in reaching their potential. Our culture celebrates independent thinkers and doers who positively impact our clients and shape our industry. The collaborative environment and engaging work—guided by A&M's core values of Integrity, Quality, Objectivity, Fun, Personal Reward, and Inclusive Diversity - are why our people love working at A&M.

The Team

The Security Governance, Risk and Compliance Senior Associate (AI) will play a key role in supporting the security governance and assurance activities associated with Alvarez & Marsal’s Artificial Intelligence Management System (AIMS). The role will primarily focus on the security aspects of AI governance, including ISO/IEC 42001 assurance, AI security risk and control assessments, audit activities, evidence gathering, risk reporting and corrective action followup. The role will also support the GRC Lead with relevant ISO/IEC 27001 surveillance and certification audit activities. The successful candidate will require a strong understanding of information security controls and AI-related security risks, with the ability to assess technical and procedural evidence and effectively communicate security requirements and identified risks to technical and non‑technical stakeholders across the firm. The role provides independent security assurance over relevant aspects of the AIMS and does not own the implementation or operation of the controls it assesses.

How You Will Contribute

Management

  • Develop rationale for prioritizing assurance activities, audit requests and workload based on risk and business requirements.
  • Provide proactive updates and reporting on audit, assessment and remediation progress.
  • Provide excellent and timely communication and service to business and technical stakeholders.

AI Security Governance & Risk

  • Support the ongoing operation and continuous improvement of security governance activities within A&M’s AIMS.
  • Assess AI‑specific security risks and controls across relevant stages of the AI system lifecycle, including those associated with areas such as AI models, data, access, third‑party services, sub‑processors and emerging AI technologies.
  • Contribute security and assurance input to AI risk assessments and gap analyses, identifying where controls may not adequately address applicable ISO/IEC 42001 requirements.
  • Support the maintenance, monitoring and reporting of AI security risks through relevant GRC and risk management processes.

ISO/ IEX 42001 Audit & Assurance

  • Plan and execute AI security assurance and audit activities aligned with ISO/IEC 42001.
  • Support ISO/IEC 42001 certification, surveillance and internal audit activities.
  • Evaluate applicable AI security and Annex A controls against organisational requirements and technical evidence.
  • Conduct stakeholder interviews, review documentation and gather evidence relating to AI systems and supporting processes.
  • Document non‑conformities, control gaps and opportunities for improvement, and track corrective actions through to verified closure.

ISO/IEC 27001 Audit Support

  • Support the GRC Lead with ISO/IEC 27001 surveillance, certification and internal audit activities.
  • Coordinate and review audit evidence with relevant control and process owners.
  • Support the tracking of non‑conformities and corrective actions through to closure.
  • Contribute to audit documentation and reporting

Risk Reporting & Stakeholder Communication

  • Communicate identified AI security risks, control deficiencies and recommendations to technical and nontechnical stakeholders.
  • Work closely with relevant stakeholders to understand AI systems, processes and associated security risks.
  • Liaise with internal and external auditors and relevant system and process owners throughout the audit lifecycle.
  • Engage Privacy, Legal and Compliance teams where assessments identify regulatory, contractual, privacy or data protection considerations requiring specialist input.
  • Participate in governance activities including metrics gathering, risk reporting and recurring assurance activities.

Stakeholder Coordination

  • Contribute to improvements in AI security governance, risk assessment and assurance processes.
  • Support the development and maintenance of AI security control assessment methodologies, audit procedures and evidence requirements.
  • Identify opportunities to integrate AI security assurance into existing GRC processes and tooling.
  • Suggest and implement appropriate process improvements, including the use of Artificial Intelligence and automation.
  • Maintain awareness of emerging AI security risks, relevant standards and industry good practice.
Qualifications
  • 4+ years of relevant experience in information security, governance, risk management, technology risk, audit or a related discipline.
  • Practical understanding of AI technologies and AI system lifecycles sufficient to assess associated security and control risks.
  • Experience performing security control assessments, technology audits or risk assessments.
  • Experience with ISO management systems, preferably ISO/IEC 42001, ISO/IEC 27001 or similar standards.
  • Good understanding of information security controls and recognised security frameworks such as ISO/IEC 27001 and NIST.
  • Strong analytical, technical writing and stakeholder communication skills.
  • Ability to assess and communicate technical security requirements and risks across technical and non‑technical teams
  • ISO/IEC 42001 Lead Auditor certification or equivalent practical ISO/IEC 42001 audit experience.
  • ISO/IEC 27001 Lead Auditor, CISA, CRISC, CISSP or equivalent certification.
  • Familiarity with GRC platforms and broader security control assessment frameworks.
  • Knowledge of AI-specific security risks including model governance, data security and residency, third‑party and sub‑processor assurance, and agentic/AI‑agent risks.
  • Experience within professional services, consulting or a similarly regulated, global environment.
Your journey at A&M

We recognize that our people are the driving force behind our success, which is why we prioritize an employee experience that fosters each person’s unique professional and personal development. Our robust performance development process promotes continuous learning, rewards your contributions, and fosters a culture of meritocracy. With top‑notch training and on‑the‑job learning opportunities, you can acquire new skills and advance your career. We prioritize your well‑being, providing benefits and resources to support you on your personal journey. Our people consistently highlight the growth opportunities, our unique, entrepreneurial culture, and the fun we have together as their favorite aspects of working at A&M. The possibilities are endless for high‑performing and passionate professionals.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Responsible AI Manager
Responsible AI Manager

Alvarez & Marsal • Delhi

Hybrid
INR 3,500,000 - 5,500,000
Azure DevOps Manager - DTS - Global Capability Center
Azure DevOps Manager - DTS - Global Capability Center

Alvarez & Marsal • Gurugram District

On-site
INR 3,500,000 - 5,500,000
Associate, Global Risk and Compliance - Global Capability Center
Associate, Global Risk and Compliance - Global Capability Center

Alvarez & Marsal • Gurugram District

On-site
INR 600,000 - 1,200,000
Senior Associate, Agentic/GenAI, DTS - Global Capability Center
Senior Associate, Agentic/GenAI, DTS - Global Capability Center

Alvarez & Marsal • Gurugram District

On-site
INR 1,800,000 - 3,000,000
Associate Director, GenAI & Data Solution Architect - Global Capability Center
Associate Director, GenAI & Data Solution Architect - Global Capability Center

Alvarez & Marsal • Gurugram District

On-site
INR 4,000,000 - 7,000,000
Senior Director - Data & AI - Platform Engineering Lead, DTS - Global Capability Center
Senior Director - Data & AI - Platform Engineering Lead, DTS - Global Capability Center

Alvarez & Marsal • Gurugram District

On-site
INR 3,500,000 - 5,600,000
Associate Director, FS Risk Consulting - Global Capability Center
Associate Director, FS Risk Consulting - Global Capability Center

Alvarez & Marsal • Gurugram District

On-site
INR 4,000,000 - 7,500,000
Responsible AI Manager
Responsible AI Manager

Athena Executive Search And Consulting • Gurugram District, Delhi

On-site
INR 3,500,000 - 6,000,000
Junior Executive Assistant, GESS - Global Capability Center
Junior Executive Assistant, GESS - Global Capability Center

Alvarez & Marsal • Gurugram District

On-site
INR 600,000 - 900,000
Senior Associate, FS Risk & Regulation - Global Capability Center
Senior Associate, FS Risk & Regulation - Global Capability Center

Alvarez & Marsal • Gurugram District

On-site
INR 1,800,000 - 3,000,000