The successful candidate uses ISO/IEC 27001, 27017, 27018, 42001, and 27019 as the frameworks that shape control selection and design rationale, then works alongside engineering teams to make those controls real in configuration, code, and network design. Design controls against recognized AI threat models - prompt injection, training and inference data poisoning, model and data exfiltration, insecure output handling, and excessive agency (OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF).