GRC and AI Governance
Job description
About the role
Cfgi is seeking a Cybersecurity GRC & AI Governance Subject Matter Expert to lead and deliver strategic advisory engagements that strengthen clients' security governance, risk management, compliance posture, AI governance programs, and privacy programs. This role blends hands-on delivery, executive communication, and practice leadership. You will work directly with CISOs, CIOs, CFOs, General Counsel/Privacy Counsel, Risk Leaders, and PE deal teams to design pragmatic programs, build operating models, and drive measurable outcomes. The position requires deep consulting instincts, the ability to translate complex requirements into business-oriented recommendations, and a commitment to quality and delivery rigor. You will be expected to mentor and develop consultants while contributing to the development of the firm's go-to-market offerings and methodologies.
Key facts
What you'll do
- Lead end-to-end GRC and privacy engagements, including scoping, planning, execution, and executive reporting, ensuring alignment with client objectives and regulatory expectations.
- Design and operationalize cybersecurity governance models, including the development of policies, standards, risk appetite statements, governance committees, and key risk and performance indicators.
- Build and mature enterprise risk programs by conducting risk assessments, maintaining risk registers, curating control libraries, and designing control testing approaches that are practical and measurable.
- Lead AI governance and compliance engagements by designing and operationalizing AI governance frameworks, conducting AI risk and impact assessments, and building and maintaining model inventories.
- Establish AI use-case classification and tiering mechanisms to ensure appropriate levels of scrutiny and control based on risk and impact.
- Advise clients on responsible AI principles and guide them through compliance with the EU AI Act, NIST AI RMF, and ISO 42001 requirements in a practical and business-aligned manner.
- Develop, implement, and maintain security policies, standards, and procedures aligned to common frameworks such as NIST CSF, ISO 27001/27002, CIS, SOC 2, CMMC, FedRAMP, NIST AI RMF, and ISO 42001.
- Support regulatory readiness and compliance initiatives, including SEC cyber disclosure support, NYDFS 500, GDPR and UK GDPR, CCPA and CPRA, HIPAA, GLBA, PCI DSS, SOX ITGC, the EU AI Act, CMMC, and FedRAMP where applicable.
- Stand up or enhance privacy programs by leading data mapping and inventory exercises, conducting DPIAs and PIAs, establishing DSAR processes, managing retention schedules, overseeing consent management, and ensuring third-party privacy risk is addressed.
- Perform vendor and third-party risk assessments and implement scalable TPRM operating models to ensure ongoing oversight and control across the enterprise.
- Coordinate cross-functional stakeholders, including Legal, IT, Security, Compliance, Product, and HR, to drive outcomes, remove obstacles, and ensure successful adoption of programs and controls.
- Translate complex technical, regulatory, privacy, and AI governance requirements into clear, business-oriented recommendations that resonate with executive leadership and operational teams.
- Help clients communicate AI risk posture and governance maturity to boards, regulators, and executive leadership, including detailed briefings on EU AI Act compliance status and NIST AI RMF alignment.
- Deliver executive-ready artifacts such as board and audit committee materials, multi-year roadmaps, operating models, heatmaps, and risk dashboards that support decision-making.
- Serve as a trusted advisor to senior leadership by presenting findings confidently, influencing strategic decisions, and demonstrating the business value of robust governance, risk, and compliance programs.
- Support business development activities through proposal writing, statement of work development, client presentations, and solution shaping that positions Cfgi as a trusted advisor.
- Contribute to the development of go-to-market offerings, including templates, accelerators, methodologies, and points of view that enhance the firm's capabilities and market differentiation.
- Mentor and develop consultants and managers by providing guidance, feedback, and leadership during engagements, ensuring consistent delivery quality.
- Partner with other Cfgi service lines, such as Accounting Advisory and CFO Advisory, to deliver integrated solutions that address complex client challenges.
Requirements
- Eight plus years of relevant experience in cybersecurity GRC, privacy, governance, risk management, compliance, or consulting at a level that maps to experience.
- A Bachelor's degree in a related field is required as a foundational credential for the role.
- Demonstrated expertise in implementing and operationalizing cybersecurity frameworks and control programs, including hands-on experience with NIST CSF, NIST 800-53, ISO 27001, ISO 27002, SOC 2, CIS, NIST AI RMF, ISO 42001, CMMC, and FedRAMP.
- Strong privacy fundamentals and direct experience with privacy program build-out and operations, including GDPR and UK GDPR, CCPA and CPRA, and familiarity with HIPAA or GLBA where applicable.
- Demonstrated expertise in AI governance and compliance frameworks, including NIST AI RMF, the EU AI Act, and ISO 42001, covering AI risk classification, algorithmic impact assessments, responsible AI principles, and practical enterprise applications.
- Prior exposure to CMMC or FedRAMP readiness activities is noted as a plus but is not a mandatory requirement for eligibility.
- Experience performing or leading enterprise and security risk assessments, control design and testing, policy and standards development, third-party and vendor risk management programs, compliance and regulatory readiness programs, and AI governance program design and implementation.
- Exceptional written and verbal communication skills with a documented track record of producing high-quality, executive-level deliverables that influence decision-making.
- Proven ability to lead teams, manage multiple concurrent workstreams, and maintain rigorous delivery standards across complex client engagements.
- Willingness to travel within the United States as required by client needs and project demands, and to adhere to applicable deadlines and milestones.
- Ability to obtain and maintain necessary security clearances or compliance verifications as required by client or project scope.
Nice to have
- Preferred items from SOURCE are not specified; therefore no additional Nice to have qualifications are listed.
Practical notes
- Hours: Full-time engagement expected.
- Travel: Within the United States as required by client needs and project requirements.
- Visa: Ability to obtain and maintain necessary security clearances or compliance verifications as required by client or project scope.
- Deadlines: Must be able to meet project timelines and client-defined milestones consistently.