AI GRC Consulting Partner

Hace 1 semana

monterrey, nuevo león, México Nearshore Cyber Jornada completa

AI GRC Consultant — Virtual Bench (Mexico)

Location: 100% remote; candidates must reside in the Mexico, preferably in CDMX or Guadalajara
Opportunity type: Six-month development programme and non-exclusive consultant bench
Employment status: Bench membership is not employment and does not guarantee assignments or hours
Work authorization: Candidates must already be legally authorized to work in the Mexico. True Aleph cannot sponsor or assist with visas, work permits, or employment authorization.


About True Aleph

True Aleph (true-aleph.ai) is the AI governance and advisory division of Nearshore Cyber USA, LLC. We help organizations govern, secure, and operate artificial intelligence in line with business requirements, risk tolerances, and applicable obligations.


We are building a virtual bench of experienced consultants for client work in AI governance, risk, compliance, security, privacy, and assurance. The bench combines assessed practitioner readiness, common delivery methods, and independent quality review.


Follow True Aleph on LinkedIn at https://www.linkedin.com/showcase/true-aleph/


The opportunity

We are recruiting senior AI GRC consultants for an initial six-month development programme and virtual delivery bench.


This opportunity is intended for established security and GRC consultants who already have substantial client-delivery experience and demonstrable hands-on experience with AI. The programme develops and assesses the additional capabilities required to lead AI governance work. It is not an introductory cybersecurity or GRC course.


Selected candidates will complete structured learning, workshops, group projects, simulations, assessed work, and a capstone. Practitioners who demonstrate readiness may be considered for paid client engagements suited to their approved roles, availability, experience, and location.


Admission, participation, or graduation does not guarantee employment, certification, paid work, placement, or a minimum number of hours.


Work you may perform

Assignments will vary, but a senior consultant on the bench may be asked to:



  • Lead AI governance and GRC engagements from discovery and scoping through assessment, roadmap development, implementation support, and executive reporting.
  • Help clients establish AI governance models, decision rights, accountability, policies, risk tolerances, and review structures.
  • Resolve conflicts among laws, regulations, contracts, policies, standards, risk tolerances, and operating requirements.
  • Apply NIST AI RMF, ISO/IEC 42001, the EU AI Act, and related security, privacy, and assurance practices to actual AI systems and use cases.
  • Assess AI inventories, system boundaries, data flows, model and provider dependencies, agents, tools, permissions, and human-oversight arrangements.
  • Translate business and operational requirements into proportionate security, privacy, risk, and compliance controls.
  • Assess control design and operating effectiveness, identify evidence gaps, and recommend remediation priorities.
  • Develop risk, compliance, assurance, testing, and monitoring strategies.
  • Advise executives and boards on material AI exposures, available options, residual risk, and the evidence supporting a recommendation.
  • Lead third-party AI and model-provider assessments, including supply-chain, concentration, contractual, security, privacy, and operational risks.
  • Evaluate certification readiness and support clients preparing for audits without misrepresenting advisory work as independent certification.
  • Develop risk assessments, decision records, policies, control libraries, monitoring plans, remediation roadmaps, and executive reports.
  • Establish and maintain effective communication among technical, legal, privacy, security, audit, risk, compliance, and business stakeholders.
  • Mentor other consultants, review their work, and provide specific, evidence-based feedback.
  • Help develop True Aleph methods, templates, quality standards, reusable artifacts, and professional guidance.
  • Use approved AI tools responsibly while verifying material outputs and protecting client information.

Nearshore Cyber remains accountable for services delivered under its name. Consultants must follow the methods, review requirements, security controls, and engagement terms applicable to each assignment.


Required experience

You must have:



  • Ten or more years of professional experience in information technology or cybersecurity.
  • At least five years of client-facing GRC consulting experience with demonstrable depth in risk, controls, compliance, audit, or assurance.<