Jobless Developer
Datamaran logo

Posted 9 days ago

Open

AI Governance & Risk Compliance Internship

LeeuwardenHybrid

AI Summary

Supports the Cybersecurity & Risk Governance team by mapping generative AI usage, drafting AI governance policies, maintaining compliance evidence for SOC 2 and ISO audits, and running vendor risk reviews.

About this role

About the internship
Datamaran is building its AI governance framework and strengthening its compliance operations at the same time, and you'll be part of both. You'll join our Cybersecurity & Risk Governance team to map how teams use generative AI, draft the policies that govern it, and keep our audit evidence ready for our SOC 2 Type 2 and ISO audits. This is the foundation of how the company manages AI risk, and every deliverable is reviewed and put to use.

In this role, you will:

  • Interview departments about their use of generative AI, and build and maintain our Shadow AI risk registry

  • Draft acceptable use policies and gap analyses against NIST AI RMF, ISO/IEC 42001 and the EU AI Act, and support AI impact assessments

  • Collect and organise compliance evidence in Drata for our SOC 2 Type 2 and ISO audits

  • Run third-party vendor risk reviews, update security questionnaires and maintain the operational risk register

What you'll learn
You'll get hands-on experience with enterprise GRC workflows and compliance tooling like Drata in a specialised, international team. Every policy draft and gap analysis you write gets direct feedback before it's put to use.

Who we're looking for
You will thrive here if you:

  • Are following an HBO or WO programme, in cybersecurity, risk management, law, ESG, compliance, technology policy or a related field

  • Are organised and analytical, with sharp attention to detail and strong policy writing skills

  • Speak and write fluent English

  • Have an interest in or knowledge of frameworks such as ISO 27001, GDPR, SOC 2, ISO/IEC 42001 or NIST AI RMF

Skills

DrataEU AI ActGap AnalysisGDPRGRC WorkflowsISO 27001ISO/IEC 42001NIST AI RMFPolicy WritingRisk RegisterSOC 2 Type 2Vendor Risk Review

Explore related jobs

Browse these categories

Market data for this role

All reports →