Position Overview
Role: Security Governance & Policy Lead - AI
Location: Remote role in UK
Type of employment: Inside IR35
Role Purpose
Own the policy, governance, and compliance framework for Claude Code.
Ensure the deployment meets regulatory obligations and that users understand and follow their responsibilities.
Draft, maintain, and enforce Claude Code Acceptable Use Policy, Data Classification Policy (AI), and Agentic Action Policy.
Lead regulatory compliance assessments (GDPR, EU AI Act, sector-specific requirements) for Claude Code.
Manage third-party risk assessment and ongoing monitoring of Anthropic as a vendor.
Develop and deliver mandatory security awareness training for Claude Code users.
Report on AI security risk posture to CISO and AI Governance Committee.
Coordinate annual policy reviews and incorporate lessons learned from incidents and audits.
Requirements
6+ years in information security governance, risk, and compliance (GRC).
Deep knowledge of GDPR, and awareness of EU AI Act obligations.
Experience writing enterprise security policies and managing their lifecycle.
Third-party risk management methodology.
Strong communication and stakeholder management skills.
CISM, CRISC, or ISO 27001 Lead Implementer certification.
Experience with AI governance frameworks (NIST AI RMF).
Background in a regulated industry (financial services, healthcare, defence).