Skip to main content
risk3sixty logo

AI Governance Associate (2027 Summer Internship)

risk3sixty
2 hours ago
Full-time
On-site
Cobb County, Georgia, United States
AI Governance

Description

Who We Are

risk3sixty is a bootstrapped, U.S.-based security and compliance firm that has run thousands of implementations and holds an 89 NPS in an industry that averages 57. No outside investors, no board, no PE exit pressure. The people our clients meet are the people doing the work. We help CISOs and GRC teams turn security and compliance from a scramble into a program they can stand behind.


The Role

This is a build-focused internship inside a growing practice. ISO 42001 implementation is one of our core advisory offerings, and the AI governance practice is expanding into similar frameworks faster than current capacity supports. You will help build the structure behind the next wave of the practice: defined offerings across the AI governance landscape, backed by materials that actually support delivery to clients.


The work runs in two directions:

1. Developing new offerings: NIST AI RMF assessments, EU AI Act readiness, and emerging agentic AI governance frameworks like AIUC-1 each need the same defined scope, methodology, and client-facing materials that ISO 42001 already has.


2. Building out the ethOS consulting team template library so consultants can serve a broader client base with less setup time. You will also sit on live engagements, which means the improvements you make reflect what actually happens with clients, not just what the standard requires.

  

What You'll Work On

• Research AI governance frameworks (NIST AI RMF, EU AI Act, AIUC-1) and map their requirements against existing risk3sixty methodology to find the gaps.

• Build initial templates and scoping tools to take each new offering to a client.

• Expand the ethOS consulting team template library across AI governance policies, risk management documentation, assessment toolkits, and scoping guides.

• Add customization guidance to documentation templates based on AI system lifecycle role (Provider, Developer, User), scope, and applicable framework.

• Support live AI governance consulting engagements and feed real client experience back into the materials.


How You'll Grow

This internship is built to develop you in three directions: translating normative standards into deliverable services, working inside live consulting engagements from the inside out, and building practical fluency across the AI governance frameworks driving enterprise demand today.


What You'll Gain

• Working knowledge of ISO 42001: its structure, how it plays out differently across the AI system lifecycle roles, and what auditors look for at Stage 1 and Stage 2.

• Consulting delivery experience, seeing an engagement run from the inside, from evidence-gathering and audit testing to how findings get documented and client interactions are managed.

• Practical fluency in the NIST AI RMF and the EU AI Act, including where they overlap with ISO 42001 and what it takes to build an advisory offering around each.

• New offering development experience: taking a regulatory framework and turning it into a deliverable service.

• The core consulting skill of standards-to-practice translation, reading normative language and producing something an organization can implement and audit against.

• A real view of where AI governance is heading and what is driving enterprise demand, from a firm that works in this space every day.

Requirements

Education and Experience

  

• Strong research skills and comfort reading dense technical standards, with the ability to pull out what matters and turn it into something practitioners can use.

• Clear, organized writing, clean enough to go to clients with minimal editing.

• Basic familiarity with core AI/ML concepts (how models are built, deployed, and monitored) enough to follow technical conversations.

• Basic familiarity with AI risk and governance concepts, including the AI system lifecycle, enough to discuss AI governance without getting lost.

• Some exposure to GRC, compliance, risk management, or consulting, through coursework, prior work, or genuine self-directed interest.

• Comfort in Microsoft 365 (Word, Excel, SharePoint).

• Detail-oriented and self-directed, since much of the materials work requires careful reading of how framework requirements connect.


Bonus Points:

  

• Prior exposure to ISO standards (ISO 27001, ISO 42001, ISO 27701, ISO 9001, or similar).

• Familiarity with the EU AI Act or NIST AI RMF.

• Exposure to AI ethics or governance coursework.

• Interest in cybersecurity policy


Physical Requirements

  • Prolonged periods sitting at a desk and working on a computer
  • Must be able to lift up to 10 pounds at times

  

risk3sixty is an Equal Opportunity Employer. We are committed to building a team that reflects a range of backgrounds, perspectives, and experiences. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, veteran status, pregnancy, or any other characteristic protected by applicable federal, state, or local law.


risk3sixty provides reasonable accommodations to qualified individuals with disabilities throughout the application and employment process. If you need an accommodation to participate in the application or interview process, please contact us and we will work with you to meet your needs.