Principal Consultant - AI Security & Governance
- Negotiable
- London
- Permanent
Job title: Principal Consultant - AI Security & Governance (SME)
Location: London / Hybrid
Salary: Competitive market rate
If you know what it takes to navigate AI security, risk and governance within complex organisations, this is an opportunity to take that experience somewhere you can actually shape the answer.
Businesses are investing heavily in AI, but many are stuck between proving it works and proving it's safe to deploy. Boards want confidence. Engineers need practical guardrails.
We're looking for a Principal Consultant - AI Security & Governance to bridge that gap.
You'll be joining a growing, AI-native technology consultancy, with the opportunity to build the security, governance and assurance capability around its existing proposition. You'll help organisations move from AI discovery and POC through to governed, secure production.
The Role:
You'll sit at the point where AI, security, governance and engineering meet, helping clients turn AI ambition into something they can confidently build, deploy and operate.
At board and risk committee level, you'll help senior stakeholders understand AI risk, define risk appetite and make informed decisions about whether an initiative is ready to progress.
Alongside engineers, you'll get into the technical detail - threat-modelling AI and agentic architectures, assessing guardrails, data access, identity and failure modes.
From POC to production, you'll bring the two sides together - making AI safe enough for the business without making it impossible for engineers to build.
What You'll Be Doing:
- Advise boards, audit and risk committees on AI risk and governance.
- Design and implement practical AI governance frameworks, policies and controls.
- Support clients with EU AI Act, UK GDPR, DPIA, NIST AI RMF and ISO 42001 requirements.
- Threat-model GenAI and agentic AI systems.
- Assess risks including prompt injection, data leakage, excessive agency and tool-use escalation.
- Review AI architectures, guardrails, evaluations and security controls.
- Help establish governance and assurance from POC through to production.
- Address data access, permissions, IAM, DLP and non-human identity risks.
- Develop AI incident response and assurance approaches.
- Assess AI models, vendors and third-party risks.
- Lead client workshops and contribute to proposals and pre-sales.
- Develop reusable AI governance and security frameworks, tools and client materials.
- Help develop the consultancy's point of view on AI Security and Governance.
What We're Looking For
Must have:
- Experience across security, risk, data, GRC or a related field.
- A strong consulting background with significant client-facing experience.
- Experience designing governance frameworks, risk assessments, policies and controls.
- Practical understanding of how AI systems are built and secured.
- Good understanding of LLMs and agentic AI, including RAG, tool use and orchestration.
- Knowledge of AI security risks including prompt injection, data leakage and excessive agency.
- Strong understanding of relevant AI regulation and frameworks, particularly EU AI Act, UK GDPR/ICO, DPIAs, NIST AI RMF and ISO 42001.
- Experience working with regulated organisations.
- The ability to communicate equally well with senior executives and technical teams.
Nice to have:
- AWS, Azure or GCP security experience.
- IAM and cloud security experience.
- Python or scripting skills.
- Model risk management or second-line risk experience.
- Experience with AI governance/data security platforms such as OneTrust, Purview, Varonis, BigID or Credo AI.
- Experience with AI security and evaluation tooling.
- Financial services experience.
- UK SC clearance eligibility.
- Relevant professional certifications.
Why This Role?
The business already has strong AI engineering capability and client demand. The opportunity now is to build the security, governance and assurance layer around it.
You'll get the breadth that can be difficult to find in larger consultancies: board-level advisory, technical AI security, governance, delivery and pre-sales all sitting within one Principal role.
If you're an experienced consultant looking for a role where your expertise can directly shape a growing AI practice, we'd be interested in hearing from you.
We are an equal opportunities employer and welcome applications from all suitably qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age.