Rhox

This position is no longer accepting applications.

Senior AI IT Risk, Compliance & Operational Resilience

Closes on 07/09/2026
Brussels
Remuneration: 2.600 - 3.200 EUR/mo gross + extralegal advantagesFreelance also possible

This position has closed

Explore other opportunities on our platform

Browse Opportunities

A Belgian insurance organisation is extending its AI-enabled IT model across cloud solutions, generative AI, and IT process automation. The Senior AI IT Risk, Compliance & Operational Resilience Consultant will act as an AI risk consultant, strengthening AI risk management and operational resilience while working with IT, architecture, cybersecurity, data, and digital teams to assess AI models, LLMs, training data, and third-party AI services against the European AI Act and related controls.

The mission

The organisation is integrating AI adoption into a broader ICT risk and governance framework covering cloud environments, outsourced services, critical suppliers, and automated IT processes. The work connects the European AI Act, DORA, GDPR, the Cyber Resilience Act, cybersecurity, fraud prevention, and National Bank of Belgium expectations, so that AI solutions are assessed through operational, regulatory, contractual, and resilience lenses. The programme includes an AI Governance Framework, risk registers, regulatory impact assessments, and executive monitoring dashboards.

You will work across IT, Application Technologies and Architecture, Cybersecurity, Data, Digital Technologies, and AI teams. Your scope will run from Business Risk Assessments and risk identification through remediation tracking, control strengthening, supplier oversight, and audit or regulatory inspection support. The initial mission is planned around a 12-month transformation period, with deliverables that inform decisions on AI solutions, cloud services, exit strategies, and strategic suppliers.

Your responsibilities

  • Strengthen the ICT and AI risk management framework by translating regulatory expectations into usable governance and control requirements.
  • Lead risk assessments for AI solutions and technology initiatives, documenting operational, cyber, regulatory, contractual, fraud, and ICT risks in clear risk registers.
  • Define and monitor remediation and control-strengthening plans with business and technology stakeholders.
  • Evaluate AI models, training data, LLMs, cloud services, and third-party AI providers, including resilience, cybersecurity, outsourcing, critical-supplier, and exit-strategy considerations.
  • Build risk indicators and executive dashboards that provide traceable monitoring of AI and ICT risk exposure.
  • Prepare opinions, recommendations, and evidence for internal audits, external audits, and regulatory inspections.

Your profile

Essential skills

  • Bring at least 10 years of senior experience in IT risk and IT governance, with a background in operational risk, compliance, audit, internal control, or risk management.
  • Apply this experience in the financial or insurance sector, where regulatory obligations and third-party dependencies are material.
  • Understand AI and Generative AI technologies, including risks related to AI models, training data, LLMs, and AI services provided by third parties.
  • Interpret and apply the European AI Act, DORA, GDPR, and third-party management frameworks, with awareness of the Cyber Resilience Act.
  • Assess operational resilience and cybersecurity challenges in AI systems, cloud environments, outsourced services, and wider ICT landscapes.
  • Work effectively with IT, Architecture, Cybersecurity, Data, and Digital teams, and communicate clear risk opinions to technical and senior stakeholders.
  • Use Microsoft Word, Excel, and PowerPoint to produce assessments, control plans, reporting packs, and management dashboards.

Languages

  • English: C1 or above, fluent in speaking, reading, and writing.
  • Dutch: approximately A2 to C1, from basic to fluent depending on the communication context.
  • French: approximately A2 to C1, from basic to fluent depending on the communication context.