Project Description
The AI Governance Engineer is the technical production engine behind an organization's AI standards and controls build-out. Working under the direction of the AI Governance & Controls Lead, this role drafts the standards library, engineers controls as implementable and testable requirements, builds control-to-evidence mappings, and produces the documentation and automation that make governance operational rather than aspirational.
This is a technical governance role, not a policy-writing role alone: the engineer works directly with platform capabilities (gateway policies, entitlements, logging), expresses controls in verifiable terms, contributes to policy-as-code and evidence automation where feasible, and validates that what the standard requires is what the platform enforces.
Standards & Controls Engineering
- Draft and iterate the AI standards library under the Lead's direction: model onboarding and approval, oversight tiers, logging/retention, agentic guardrails, data-classification handling, and acceptable use.
- Engineer each control as a testable requirement: definition, enforcement point, owner, evidence artifact, and validation method.
- Build and maintain obligation-to-control-to-evidence mappings against regulatory guidance and internal policy.
- Contribute to policy-as-code and controls-automation approaches with the platform team where controls can be enforced or checked mechanically.
Evidence & Assessment Production
- Produce evidence artifacts, control attestations, and assessment documentation for deviations, exceptions, and governance reviews.
- Validate platform-generated evidence (audit logs, entitlement records, quota enforcement) against control requirements; document gaps and drive fixes.
- Support deviation and exception lifecycle management: drafting, compensating-control documentation, tracking, and closure evidence.
- Assemble components of examiner-readiness and audit-response packages.
Governance Operations Support
- Support AI Control Group, working group, and committee operations with prepared materials, assessments, and documented decisions.
- Maintain the AI use case and agent registry data quality in partnership with intake and platform onboarding.
- Document governance processes, runbooks, and templates in organizational repositories for FTE handover.
- Transfer working knowledge to internal FTEs throughout the engagement.
Skills — Must Have
- Minimum of 5 years' experience in technology governance, IT risk/controls, security governance engineering, or compliance engineering in a technology environment.
- Demonstrated experience writing technical standards, control frameworks, or control documentation that maps to regulatory or policy obligations.
- Working technical knowledge of cloud platforms and modern application patterns: APIs and gateways, identity/RBAC, logging and monitoring, environment separation.
- Familiarity with AI/GenAI systems sufficient to write accurate, enforceable requirements for model access, oversight, and logging.
- Strong technical writing and documentation discipline; able to produce artifacts that survive audit and second-line challenge.
- Experience with GRC processes: exceptions, findings, evidence collection, and remediation tracking.