← jamesgrc.com Download PDF

James Gerrior

Information Security & AI Governance Leader

Email: james@jamesgrc.com

LinkedIn: James Gerrior| Website: jamesgrc.com| GitHub: github.com/jamesgrcghub

Professional Profile

Information Security and AI Governance Leader with 11 years leading enterprise ISMS programs, and 3 years building and directing corporate AI Management Systems (AIMS) in an AI company.

Experienced CISO-level leader with a record of translating complex requirements — ISO 27001, ISO 42001, EU GDPR, EU NIS 2 Directive, EU AI Act, NIST AI RMF — into fully customized and measurable programs. I have designed and managed security and governance programs in North America, EU, East Africa, and Asia for multinational organizations, transforming management systems into KPI-driven models with current posture measurements and maturity forecasting.

Open to Information Security and AI Governance leadership roles.

Core Competencies

Governance: Information Security Management Systems (ISMS) | AI Governance / AI Management Systems (AIMS) | GRC Strategy & Leadership | Enterprise Risk Management | Compliance Program Management | Board & Executive Reporting

Risk & Privacy: Data Privacy & EU GDPR Compliance | AI Ethics & Responsible AI | Third-Party Risk Management

Operations: Incident Management | Security Awareness Programs | Agentic AI Implementation | Threat & Vulnerability Management

International Program Leadership: North America | EU | East Africa | Asia

Domain Expertise

Information Security: ISO 27001 | NIST Cybersecurity Framework (CSF) | EU NIS 2 Directive | TISAX | OWASP Projects and Top 10s | OWASP AI Exchange

AI Governance: ISO 42001 | NIST AI RMF | EU AI Act | OECD AI Principles

Risk & Compliance: ISO 31000 | ISO 9001 | ISO 22301 | EU GDPR

Emerging & Specialized: Agentic AI Governance & Security | Non-Human Identity (NHI) | Post-Quantum Cryptography (PQC) | AI Trust, Risk, and Security Management (AI TRiSM) | Continuous Threat Exposure Management (CTEM)

Public Work

Live Demo Governance Dashboards: Controls, KPI scoring, trends, forecasting, compliance tracking, and management system data analysis — using synthetic data

ISMS & AIMS Control Libraries: Customized, multi-framework-mapped control libraries as used in the above Dashboards — versioned and open on GitHub — github.com/jamesgrcghub

Employment History

Director of Information Security & GRC — Sama

March 2023 — Present

Information Security Director — One Acre Fund

December 2016 — March 2023

IT Operations Director — One Acre Fund

December 2014 — December 2016

Technical Director — NetIQ – Novell Africa

December 2012 — November 2013

Earlier career (2001 – 2012): IT operations roles across enterprise environments

Certifications

ISACA CISM — Certified Information Security Manager

IAPP AIGP — AI Governance Professional (Expected Q3 2026)