Security Governance & Policy Lead - 12 Months - Inside IR35 - Hybrid in Sheffield

Security Governance & Policy Lead - 12 Months - Inside IR35 - Hybrid in Sheffield

Role Overview

A senior Security Governance & Policy Lead specialising in AI. The position is responsible for owning the policy, governance, and compliance framework surrounding the deployment of an AI coding assistant (Claude Code) within a large, regulated enterprise. The role ensures the deployment meets regulatory obligations, manages vendor risk, and drives user awareness and accountability across the organisation.

Key Responsibilities

  • Draft, maintain, and enforce key AI-related security policies including Acceptable Use, Data Classification, and Agentic Action policies for Claude Code.
  • Lead regulatory compliance assessments for the AI deployment, covering GDPR, EU AI Act obligations, and sector-specific requirements.
  • Manage third-party risk assessment and ongoing monitoring of the AI vendor, ensuring robust supplier governance is maintained throughout the engagement.
  • Develop and deliver mandatory security awareness training for Claude Code users, ensuring responsibilities are clearly understood across the organisation.
  • Report on AI security risk posture to the CISO and AI Governance Committee, coordinating annual policy reviews and incorporating lessons from incidents and audits.

Top 5 Skills

  • Information security GRC expertise - 6+ years in information security governance, risk, and compliance, with proven experience writing and managing enterprise security policies throughout their life cycle.
  • Regulatory & AI compliance knowledge - Deep knowledge of GDPR and awareness of EU AI Act obligations, with experience conducting compliance assessments for emerging technology deployments in regulated environments.
  • AI governance frameworks - Familiarity with AI governance frameworks such as NIST AI RMF, with the ability to apply structured governance approaches to AI tool deployments and agentic systems.
  • Third-party risk management - Proven experience applying third-party risk management methodologies to technology vendors, including ongoing monitoring and governance of AI or cloud-based suppliers.
  • Stakeholder engagement & certifications - Strong communication and stakeholder management skills with the ability to engage at CISO and board level; CISM, CRISC, or ISO 27001 Lead Implementer certification is strongly preferred.

Contract Details

  • Rate: £600 per day Inside IR35
  • Location: Hybrid (2x a week) in Sheffield
  • Duration: 12- Month Initial Contract

Job Details

Company
Hamilton Barnes
Location
Sheffield, Yorkshire, United Kingdom S5 9
Hybrid / Remote Options
Employment Type
Contract
Salary
GBP Daily
Posted