Technical Expert – AI & Information Security Systems (Contract)
$100.00/hr
Sign in to apply
New here? Create a free account in under a minute.
Technical Expert – AI and Information Security Systems (Contract)
ascio is hiring a Technical Expert in Artificial Intelligence and Information Security Systems to support our audit, assessment and assurance work.
This role provides specialist technical expertise across AI systems, cybersecurity, cloud environments, data, machine learning and information security controls. The Technical Expert supports audit and assessment teams by interpreting complex technical environments, reviewing technical evidence and helping determine whether implemented technologies and controls meet applicable requirements.
The Technical Expert works under the direction of the audit or assessment lead and does not act as the auditor.
Responsibilities
- Provide technical expertise to audit and assessment teams across AI, machine learning, information security and cloud environments.
- Review AI system architectures, machine learning lifecycles, data flows, model development processes and supporting technologies.
- Review security architectures, identity and access management, network security, application security, cloud security and operational controls.
- Support assessment of AI data quality, bias, fairness, model validation, monitoring, impact assessment and risk treatment.
- Review implementation of information security controls, including relevant ISO/IEC 27001 Annex A controls.
- Assess technical evidence and explain whether it appropriately demonstrates implementation of applicable requirements.
- Review software development, DevSecOps and MLOps processes.
- Review vulnerability management, logging, monitoring and security operations practices.
- Support assessment teams in understanding complex technical systems and identifying areas requiring further evidence or investigation.
- Prepare clear technical notes and supporting documentation for audit and assessment records.
- Participate in remote or onsite audit and assessment activities as required.
- Maintain current technical knowledge, continuing professional development records, confidentiality and impartiality requirements.
Required Skills and Experience
- Significant practical professional experience across Artificial Intelligence, machine learning, information technology and information security.
- Hands-on experience with AI or machine learning system development, deployment, validation or operation.
- Experience with machine learning lifecycle processes, including model development, testing, deployment, monitoring and change management.
- Strong understanding of data quality, bias, fairness, explainability and AI risk management.
- Experience with software development, MLOps, DevOps or DevSecOps practices.
- Strong information security experience covering security architecture, identity and access management, cloud security, network security or application security.
- Experience reviewing security control implementation in Microsoft Azure, AWS, SaaS or comparable environments.
- Knowledge of vulnerability management, logging, monitoring and security operations.
- Ability to review technical evidence objectively and relate implementation evidence to defined requirements.
- Ability to explain complex AI and cybersecurity concepts clearly to auditors, assessors and non-specialist audiences.
- Strong written communication skills suitable for formal assessment and audit records.
Standards and Framework Knowledge
Candidates should have practical knowledge of relevant standards and frameworks including:
- ISO/IEC 42001 – Artificial Intelligence Management Systems.
- ISO/IEC 22989 – Artificial Intelligence Concepts and Terminology.
- ISO/IEC 5338 – AI System Lifecycle Processes.
- ISO/IEC 23894 – Artificial Intelligence Risk Management.
- ISO/IEC 42005 – AI System Impact Assessment.
- ISO/IEC 27001:2022 – Information Security Management Systems.
- ISO/IEC 27002:2022 – Information Security Controls.
Qualifications
- Professional education or training equivalent to university level in computer science, data science, Artificial Intelligence, engineering, cybersecurity, information systems or a related discipline, or equivalent professional experience.
- Relevant current professional or technical certifications in Artificial Intelligence, cloud technologies or information security.
- Applicants must be able to provide certification status and expiry or renewal dates, where applicable.
- Relevant certifications may include CISSP, CCSP, Microsoft, AWS or Google Cloud certifications, AI or machine learning certifications, ISO/IEC 27001 Lead Auditor or Lead Implementer, or ISO/IEC 42001 Lead Auditor or Lead Implementer.
Preferred Experience
- Experience supporting certification audits, independent assessments or technical assurance reviews.
- Generative AI and large language model systems.
- Natural language processing, computer vision or other advanced machine learning technologies.
- AI governance and responsible AI.
- Penetration testing, security engineering or security operations.
- Operational technology or industrial control system security.
- Research or publication experience in Artificial Intelligence or cybersecurity.
- Regulatory, ethics or technical review experience.
- Experience in regulated or critical sectors such as healthcare, financial services, government, utilities or critical infrastructure.
Location and Work Arrangement
- Remote within Canada.
- Some assignments may require occasional onsite work or travel within Canada.
- Applicants must be based in Canada and legally entitled to work in Canada.
- A criminal record check may be required before access to sensitive systems, information or environments.