AI Security Senior Consultant
Deloitte
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
As a Senior Consultant, Strategy, Growth & Transformation in Deloitte Cyber's Cyber for AI practice, you will own and deliver work that helps clients understand and mitigate/monitor the risks of adopting AI across the enterprise and define the cybersecurity controls, governance, policy and risk management approaches needed to deploy AI securely and safely. You will combine client advisory with structured cyber risk and governance work, turning business and regulatory requirements into frameworks, roadmaps and recommendations, and you will work closely with the practice's Data, Infrastructure, Identity, Security Operations and Application Security teams to make sure strategy translates into implementable requirements. You will guide junior practitioners, lead project activities and client interactions and help identify, win and deliver new work.
Recruiting for this role ends on 05/31/2027.
Work you'll do
As a Senior Consultant, Strategy, Growth & Transformation on the Cyber Strategy & Transformation team, you will be responsible for:
- Lead discovery and current-state assessments of client AI cybersecurity controls governance, risk management and security practices across business units and AI use cases.
- Facilitate stakeholder workshops with security, risk, data science, legal and business leaders to surface AI risk concerns and gather requirements.
- Develop AI risk registers, control frameworks and maturity assessments aligned to standards such as the NIST AI RMF, ISO/IEC 42001, the OWASP LLM Top 10 and MITRE ATLAS.
- Translate strategic recommendations into workstream-level roadmaps, coordinating with Data, Infrastructure, Identity and Application Security practitioners on technical implementation details.
- Draft governance artifacts, including AI use-case intake processes, policy templates, model risk tiering approaches and AI security awareness materials.
- Own a workstream within a broader engagement, manage dependencies and milestones, provide day-to-day guidance to consultants, and support client demonstrations, executive readouts, and research, benchmarking, and estimation inputs to pursuits.
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments.
Qualifications
Required:
- Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or Risk Management
- 4+ years of experience in cybersecurity, risk, or technology consulting, including experience with artificial intelligence or machine learning systems, data governance, or emerging technology risk.
- Experience working with artificial intelligence and machine learning concepts, including model development, training, fine-tuning, retrieval-augmented generation, and agentic architectures.
- Experience applying artificial intelligence risk and security frameworks or regulations, including the National Institute of Standards and Technology Artificial Intelligence Risk Management Framework (NIST AI RMF), International Organization for Standardization/International Electrotechnical Commission 42001 (ISO/IEC 42001), Open Worldwide Application Security Project Large Language Model Top 10 (OWASP LLM Top 10), MITRE Adversarial Threat Landscape for Artificial-Intelligence Systems (MITRE ATLAS), or the European Union Artificial Intelligence Act.
- Experience conducting risk assessments, gap analyses, or maturity assessments in cybersecurity, privacy, or governance and developing strategy documents, governance frameworks, and executive presentation materials.
- Ability to travel 25-50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Experience in consulting, client delivery, or client-facing advisory roles and experience building or customizing prompts, templates, or lightweight artificial intelligence workflows to standardize recurring deliverables, including risk registers, maturity assessments, or policy drafts.
- Experience with artificial intelligence governance platforms, governance, risk, and compliance tools, or model risk management systems.
- Experience with the machine learning lifecycle and technologies such as PyTorch, TensorFlow, or MLflow.
- Experience developing reusable strategy assets, reviewing work products of junior consultants, or contributing to methodologies and frameworks.
- Experience in regulated industries such as financial services, healthcare, life sciences, or the public sector.
- Certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Data Privacy Solutions Engineer (CDPSE), Artificial Intelligence Governance Professional (AIGP), or ISO/IEC 42001 Foundation or Lead Implementer.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.