What you will do
Map EU AI Act, NIST AI RMF and sector rules onto concrete platform controls.
Own the evidence pack clients hand to their own auditors.
Review new product work for governance impact before it ships, not after.
Advise client risk teams on what a defensible AI deployment looks like in their context.
What we are looking for
Regulatory depthPractical familiarity with AI, privacy and sector regulation, and where they overlap.
Technical fluencyYou can read a system architecture and tell where the control has to sit.
Audit experienceISO 27001, SOC 2 or equivalent, from the inside.
JudgementYou know the difference between a real risk and a box someone wants ticked.
Technology stack
FrameworksEU AI Act · NIST AI RMF · ISO/IEC 42001 · ISO/IEC 27001 · SOC 2
ToolingPolicy engines · Audit logging · Evaluation harnesses
Send a CV and a short note on something you built and had to keep running to jobs@zitrino.com. Put the role title in the subject line. We read every application ourselves and reply either way, usually within a week.