VS
AI Governance Advisor - COBIT , PCI DSS, SOX ITGC & GDPR compliance || Hybrid-Calgary/Edmonton, Canada
- Hiring from
- Canada
- Work type
- Hybrid
- Posted
- Oct 1, 2026
Is this job info correct?
AI Governance Advisor - COBIT , PCI DSS, SOX ITGC & GDPR compliance
Hybrid-Calgary/Edmonton, Canada
Long Term Contract
2 INTERVIEWS
Must-Have Skills
- 10+ years GRC & Governance experience
- Deep COBIT framework knowledge and implementation
- AI Governance & Risk Management
- PCI DSS, SOX ITGC & GDPR compliance
- Canadian Privacy: PIPA, PIPEDA & FOIP
- AI/Agent Governance: promotion, approval, version control & repositories
- CI/CD Compliance Integration and automated governance controls
- Power BI / Microsoft Fabric dashboard and reporting experience
- AI Cost & Spend Monitoring
- Risk Assessment & Mitigation
- Policy Development & Governance Framework Design
- Board/Committee Advisory experience
- Risk-Benefit Analysis & Decision Support
- Ability to balance AI innovation with security, privacy and regulatory risk
Project Overview:
- looking to transform how its Technology and Data organization delivers software by embedding AI across requirements, design, development, testing, release, and sustainment.
- This is not simply an AI-tool rollout. It is an operating-model and delivery transformation focused on improving speed, quality, and consistency while maintaining strong governance, auditability, and human accountability.
- The initiative is a multi-phase transformation program designed to embed AI capabilities across the Software Development Life Cycle (SDLC) while maintaining strong governance, privacy, security, and regulatory compliance.
- The objective is not simply to deploy AI tools, but to redesign how technology teams work by integrating AI into workflows, decision-making, documentation, testing, architecture, data, and delivery processes.
- The engagement is structured around helping progress from a relatively early AI maturity state ("Stage 2 - Off the Shelf") toward more integrated and governed AI adoption ("Stage 3 - Task-Level Integration"), with a longer-term path toward workflow orchestration and enterprise-scale AI-enabled delivery.
- The Governance Advisor designs and implements the governance framework that makes enterprise-scale AI adoption measurable, safe, and compliant — turning "we trained people" into "here's the dashboard showing velocity improvement, acceptance rates, spend-to-output ratios, and compliance agents running in the delivery pipeline. Designs and operationalizes AI governance frameworks that align with COBIT-based governance model and regulatory requirements. Ensures AI adoption remains compliant, secure, and auditable.
- Design governance frameworks with all six components operational before program go-live
- Develop AI usage policies: tool-to-data-environment mapping, permission scoping per team, zero-retention configurations for regulated workflows
- Design agent promotion board structures: review cadence, promotion criteria, evaluation rubrics, three-tier repository classification
- Design compliance agent integration with CI/CD pipelines (compliance checks as pipeline gates, not separate processes)
- Design PCI-active agent frameworks (run on every commit touching PCI-scope code, flag issues at commit time)
- Design SOX audit trail generation (AI-assisted changes tagged at commit level with traceable attribution)
- Design GDPR data classification layers across AI tool call chains
- Integrate governance dashboards with client BI platforms (Microsoft Fabric, Power BI, or equivalent)
- Plan passive-to-active compliance transitions for regulated clients
- AI governance model design aligned to COBIT framework
- Policy development and governance playbook creation
- AI review board structure and approval workflow design
- Risk assessment and mitigation strategy for AI-assisted workflows
- Compliance integration (PIPA, PIPEDA, FOIP)
- Governance framework validation during pilot
- Governance scaling strategy for enterprise Phase 3 deployment
- Training governance participants and decision-makers
Required:
- Experience with regulatory compliance frameworks: PCI DSS, SOX IT General Controls, GDPR
- Experience with BI/dashboard platforms (Microsoft Fabric, Power BI, or equivalent)
- Experience designing agent governance: promotion processes, version control, repository structures
- Understanding of CI/CD pipeline integration for automated compliance checks
- Knowledge of AI tool cost structures and spend monitoring
- Governance, Risk, Compliance (GRC) background (10+ years)
- Deep COBIT framework knowledge and implementation
- Canadian privacy regulations (PIPA, PIPEDA, FOIP)
- AI governance and risk frameworks
- Board and committee advisory experience
- Policy development and institutional design
- Risk/benefit analysis and decision support
- Ability to balance innovation with risk management
Nice to Have:
- Experience with enterprise-scale AI or DevOps transformations
- Familiarity with the IIOS Stage Framework and DLP program structure
- Experience designing audit-ready artifact generation systems
- Privacy, legal, or compliance background
- Experience with healthcare regulations and privacy legislation
- Responsible AI framework implementation experience
- COBIT, NIST, ISO 27001, or SOC2 experience
- Risk management certifications
- Experience establishing AI review boards
- Change governance and policy development experience
For specifically, their concern around guardrails, accountability, and healthcare privacy makes this role particularly valuable.
– Theodore Roosevelt
Sayantan Das | Senior Tech Recruiter
E: sayantan@veritosolutions.com