AI Control Trainer (Data, Technology & Cyber)
London or Remote · Contract · Inside IR35 · August 2026
A major Design & Digital Agency is putting agentic AI into live processes inside a regulated financial services business.
The technology organisation already runs a control framework. It was written for deterministic software. A model does not diff like code, a prompt change alters behaviour without a release, and an agent picks its own path. Every control that assumes a reviewable change, a testable output and a named human actor now has a gap in it.
You find those gaps and teach the people who own the controls what to do about them. You already own most of the material.
THE ROLE
- Map AI onto the client’s existing control library and name the gaps.
- Rework change control for systems whose behaviour shifts without a code change.
- Answer the identity question. An agent acts under a credential, and someone decides whose, with what scope, and how it gets revoked.
- Set what testing and audit evidence look like when output is non-deterministic.
- Cover the attack surface at a level a SOC can act on. Prompt injection, tool abuse, exfiltration through output, poisoning.
- Train the assessors. The people who challenge and sign off need a question set they can use on Monday.
REQUITMENTS:
- Risk and controls held inside a technology organisation, covering data, tech and cyber.
- Secure SDLC, IAM, cloud and data controls, audit evidence, third-party risk, NIST or ISO 27001, ICO and GDPR, EU AI Act.
- Real depth in generative and agentic systems. Evaluation, guardrails, adversarial testing, agent identity.
- A teaching record, and credibility with a technical room.
- Available in August 2026.
NICE TO HAVE
- CISSP, ISO/IEC 27001 or ISO/IEC 42001.
- ISACA Advanced in AI Audit.
- Internal audit, second-line technology risk, or time inside a SOC.
…
