Posted 10 August, 2026
Training Specialist (AI Risk & Controls)
Intelix.AI
Greater London, ENG, GB
Full Time
Job Description
AI Control Trainer (Data, Technology & Cyber)
\nLondon or Remote · Contract · Inside IR35 · August 2026
\nA major Design & Digital Agency is putting agentic AI into live processes inside a regulated financial services business.
\nThe technology organisation already runs a control framework. It was written for deterministic software. A model does not diff like code, a prompt change alters behaviour without a release, and an agent picks its own path. Every control that assumes a reviewable change, a testable output and a named human actor now has a gap in it.
\nYou find those gaps and teach the people who own the controls what to do about them. You already own most of the material.
\nTHE ROLE
\n- \n
- Map AI onto the client's existing control library and name the gaps. \n
- Rework change control for systems whose behaviour shifts without a code change. \n
- Answer the identity question. An agent acts under a credential, and someone decides whose, with what scope, and how it gets revoked. \n
- Set what testing and audit evidence look like when output is non-deterministic. \n
- Cover the attack surface at a level a SOC can act on. Prompt injection, tool abuse, exfiltration through output, poisoning. \n
- Train the assessors. The people who challenge and sign off need a question set they can use on Monday. \n
REQUITMENTS:
\n- \n
- Risk and controls held inside a technology organisation, covering data, tech and cyber. \n
- Secure SDLC, IAM, cloud and data controls, audit evidence, third-party risk, NIST or ISO 27001, ICO and GDPR, EU AI Act. \n
- Real depth in generative and agentic systems. Evaluation, guardrails, adversarial testing, agent identity. \n
- A teaching record, and credibility with a technical room. \n
- Available in August 2026. \n
NICE TO HAVE
\n- \n
- CISSP, ISO/IEC 27001 or ISO/IEC 42001. \n
- ISACA Advanced in AI Audit. \n
- Internal audit, second-line technology risk, or time inside a SOC. \n
