Role description
Own the policy, governance, and compliance framework for Claude Code.
Ensure the deployment meets regulatory obligations and that users understand and follow their responsibilities.
Key responsibilities
- Draft, maintain, and enforce Claude Code Acceptable Use Policy, Data Classification Policy (AI), and Agentic Action Policy.
- Lead regulatory compliance assessments (GDPR, EU AI Act, sector-specific requirements) for Claude Code.
- Manage third-party risk assessment and ongoing monitoring of Anthropic as a vendor.
- Develop and deliver mandatory security awareness training for Claude Code users.
- Report on AI security risk posture to CISO and AI Governance Committee.
- Coordinate annual policy reviews and incorporate lessons learned from incidents and audits.
Key skills/knowledge/experience
- 6+ years in information security governance, risk, and compliance (GRC).
- Deep knowledge of GDPR, and awareness of EU AI Act obligations.
- Experience writing enterprise security policies and managing their lifecycle.
- Third-party risk management methodology.
- Strong communication and stakeholder management skills.
Person specification
- I.e., negotiating, client facing, communication, assertive, team leading/team member skills, supportive.
- CISM, CRISC, or ISO 27001 Lead Implementer certification.
- Experience with AI governance frameworks (NIST AI RMF).
- Background in a regulated industry (financial services, healthcare, defence).