Security Governance & Policy Lead - 12 Months - Inside IR35 - Hybrid in Sheffield
Security Governance & Policy Lead - 12 Months - Inside IR35 - Hybrid in Sheffield
Role Overview
A senior Security Governance & Policy Lead specialising in AI. The position is responsible for owning the policy, governance, and compliance framework surrounding the deployment of an AI coding assistant (Claude Code) within a large, regulated enterprise. The role ensures the deployment meets regulatory obligations, manages vendor risk, and drives user awareness and accountability across the organisation.
Key Responsibilities
- Draft, maintain, and enforce key AI-related security policies including Acceptable Use, Data Classification, and Agentic Action policies for Claude Code.
- Lead regulatory compliance assessments for the AI deployment, covering GDPR, EU AI Act obligations, and sector-specific requirements.
- Manage third-party risk assessment and ongoing monitoring of the AI vendor, ensuring robust supplier governance is maintained throughout the engagement.
- Develop and deliver mandatory security awareness training for Claude Code users, ensuring responsibilities are clearly understood across the organisation.
- Report on AI security risk posture to the CISO and AI Governance Committee, coordinating annual policy reviews and incorporating lessons from incidents and audits.
Top 5 Skills
- Information security GRC expertise - 6+ years in information security governance, risk, and compliance, with proven experience writing and managing enterprise security policies throughout their life cycle.
- Regulatory & AI compliance knowledge - Deep knowledge of GDPR and awareness of EU AI Act obligations, with experience conducting compliance assessments for emerging technology deployments in regulated environments.
- AI governance frameworks - Familiarity with AI governance frameworks such as NIST AI RMF, with the ability to apply structured governance approaches to AI tool deployments and agentic systems.
- Third-party risk management - Proven experience applying third-party risk management methodologies to technology vendors, including ongoing monitoring and governance of AI or cloud-based suppliers.
- Stakeholder engagement & certifications - Strong communication and stakeholder management skills with the ability to engage at CISO and board level; CISM, CRISC, or ISO 27001 Lead Implementer certification is strongly preferred.
Contract Details
- Rate: £600 per day Inside IR35
- Location: Hybrid (2x a week) in Sheffield
- Duration: 12- Month Initial Contract