Principal Consultant, AI Security & Governance (SME)
You will be Enablis's senior authority on safe, secure and governed AI delivery — a billable, Principal-level individual contributor with no line-management load. You drop into our Assess and Build pods alongside a Delivery Lead and Forward Deployed AI Engineer when an engagement needs sign-off unblocked, and you carry the same rigour into our established delivery book, where conventional builds also need security assurance. AI has become a board-level risk before most organisations have made it a production capability — and the blockers are rarely the models. They are un-evidenced governance, ungoverned data access, shadow AI, unsecured agents, and pilots that were never designed for production. This role closes that gap: giving boards the confidence to say yes to the next gate, and engineering teams the guardrails to ship. You operate credibly at two altitudes. In the boardroom, you translate AI risk into decisions, metrics and evidence that directors can stand behind at each gate of an engagement. Alongside engineers, you threat-model agent architectures, review guardrails and data access, and make security and privacy sign-off an achievable step rather than a blocker.
What you'll do
- Give client boards, audit and risk committees the evidence to approve each step of an engagement — POC to MVP to Pilot to production — by designing the governance side of the gates the engagement already runs
- Design and implement practical AI governance operating models: policies and standards, AI system inventories, use-case intake and risk-tiering, governance forums, escalation routes and training
- Map client obligations across the EU AI Act, UK ICO expectations (DPIAs), NIST AI RMF and ISO/IEC 42001 — and for financial-services clients, SM&CR, Consumer Duty and model-risk expectations — translated into proportionate controls, not paperwork
- Assure and standardise what our pods build: turn the engineering team's evals, human-in-the-loop controls, model documentation and audit trails into evidence that passes internal audit and second-line review first time
- Threat-model GenAI and agentic architectures — prompt injection, jailbreaks, data leakage, tool-use escalation, model extraction and poisoning — mapped to OWASP LLM Top 10, OWASP agentic guidance and MITRE ATLAS
- Diagnose and remediate the data-exposure blockers that freeze rollouts — oversharing, permission sprawl and unlabelled data — and design least-privilege access patterns for AI systems and non-human identities
- Rescue "pilot purgatory": consolidate siloed POCs into a governed portfolio with shared platform patterns, reusable controls and a paved road to production
- Act as the SME in pre-sales: shape proposals, scopes and estimates, lead client workshops, and build reusable Enablis assets — assessment frameworks, governance accelerators, board-pack templates and reference architectures
What we're looking for
- Extensive experience across security, risk, data or AI engineering, including hands-on with LLM/GenAI systems in production settings
- Demonstrated hybrid depth: you have designed governance frameworks (policy, risk assessment, controls, forums) AND worked technically with AI systems (threat modelling, security review, evaluation, guardrails) — and can evidence both
- Working fluency in the regulatory landscape: EU AI Act, UK GDPR / ICO expectations and DPIAs, NIST AI RMF and ISO/IEC 42001 — translated into proportionate controls, not paperwork
- Understanding of LLM and agentic architectures (RAG, tool use, orchestration, agent identity) deep enough to hold your own in design reviews — including the failure modes: prompt injection, data leakage, excessive agency, hallucination
- Board-credible communication: you can write a risk paper a NED will actually read and defend it in the room — and brief a delivery team on Monday morning
- Consulting instincts: comfortable being billable, running discovery, handling ambiguity and building trust quickly inside someone else's organisation — at the pace of short, evidence-gated engagements, in lean pods of two or three
- Experience in regulated environments; financial services strongly preferred
Nice to have
- Scripting or engineering ability (Python) — enough to prototype checks and stay credible with engineers; familiarity with evals and red-team tooling (e.g. PyRIT, garak, promptfoo)
- Cloud security depth on at least one of AWS / Azure / GCP, including IAM and network controls for AI workloads; M365 Copilot / Purview data-governance remediation experience
- Model risk management exposure (SS1/23 or SR 11-7-style validation) or second-line risk experience
- Familiarity with AI governance and data-security tooling (e.g. Credo AI, OneTrust, Purview, Varonis, BigID)
- Relevant certifications as signal, not gatekeep: IAPP AIGP or CIPP/E, ISO/IEC 42001 Lead Implementer / Lead Auditor, CISSP / CISM / CRISC, ISACA AAIA / AAIR
- Eligibility for UK SC clearance (an advantage for public-sector engagements)
Tech & skills
Role details
What you'll get
- 30 days holiday + bank holidays
- Competitive salary
- Pension matched up to 5%
- Private healthcare (Bupa)
- £2k learning budget
- AI tooling: Claude, Copilot and more
- Flexible hybrid working
Interested in
this role?
Drop us your details and we'll be in touch.
Other open positions
Senior / Lead AI Engineer
Build production-ready AI solutions, including RAG pipelines, agent architectures and LLM integrations, for clients and internal tooling. Not proof-of-concept work.
Consultant AI Engineer
Hands-on AI engineering at consultant grade. Build production-ready AI — RAG pipelines, agent architectures and LLM integrations — for clients and internal tooling, working as part of a delivery pod. Not proof-of-concept work.
Senior / Lead Deployed AI Engineer
The technical spearhead of our forward-deployed work. Embed inside client environments to scope, design, build and ship production AI — RAG, agents and LLM integrations — on real data. Not a research role.
Convince us
we need you.
If none of our listed roles are quite right but you think you'd thrive here, tell us. No cover letter template. Just what you're great at and what you want to build.