Security Governance & Policy Lead - AI

Vbeyond

Greater London

On-site

GBP 110,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Vbeyond is seeking an experienced Security Governance & Policy Lead - AI to own the security policy, governance and compliance framework for the organisation's AI development environment. You will lead AI security policy development, third-party risk management and regulatory compliance across GDPR and the EU AI Act, providing senior leadership with visibility of risk posture.

The role requires 6+ years in Information Security GRC, strong policy lifecycle expertise and the ability to translate

Qualifications

  • 6+ years' experience in Information Security Governance, Risk & Compliance (GRC).
  • Strong enterprise security policy development and lifecycle management experience.
  • Strong knowledge of GDPR.
  • Practical understanding of AI governance and security risks.
  • Awareness of EU AI Act obligations.
  • Experience conducting regulatory or compliance assessments.
  • Strong third-party risk management experience.
  • Experience developing and implementing security governance frameworks.
  • Strong stakeholder management and communication skills.
  • Experience working in regulated industries such as financial services, healthcare or defence.

Responsibilities

  • Own and maintain the security governance framework for the AI development environment.
  • Develop, maintain and enforce AI-specific security policies and standards.
  • Draft and manage AI policies such as AI Acceptable Use Policy, AI Data Classification Policy, Agentic Action Policy.
  • Ensure policies clearly define user responsibilities and security requirements.
  • Establish governance controls for AI-assisted and agentic workflows.
  • Coordinate policy reviews and incorporate lessons from incidents and audits.
  • Lead regulatory and compliance assessments relating to AI usage.
  • Assess requirements under GDPR, EU AI Act and sector-specific regulations.
  • Translate regulatory requirements into practical security controls and policies.
  • Maintain evidence and documentation required for compliance assessments and audits.
  • Monitor regulatory developments affecting AI security and governance.
  • Lead third-party security and risk assessments for AI technology providers.
  • Manage ongoing security monitoring of critical AI vendors.
  • Assess vendor security controls, risks and compliance posture.
  • Track remediation activities and elevate significant third-party risks.
  • Maintain appropriate third-party risk documentation and governance records.
  • Develop and deliver mandatory security awareness training for AI users.
  • Ensure users understand acceptable use, data handling and security responsibilities.
  • Promote secure and responsible use of AI technologies.
  • Monitor compliance with relevant policies and identify areas requiring further awareness or training.
  • Assess and monitor AI security risks across the organisation.
  • Prepare security risk reporting for the CISO and AI Governance Committee.
  • Communicate security risks, control gaps and remediation recommendations to senior stakeholders.
  • Coordinate with Security, Legal, Compliance, Privacy, Technology and business teams.
  • Support security investigations, audits and governance reviews.

Skills

GRC experience
Policy development
GDPR knowledge
AI governance
EU AI Act
Regulatory assessments
Third-party risk
Stakeholder management
Regulated industry

Job description

Role Overview

We are seeking an experienced Security Governance & Policy Lead - AI to own the security policy, governance and compliance framework for the organisation's AI coding and agentic development environment.

The role will be responsible for establishing appropriate security policies and governance controls, assessing regulatory obligations, managing third-party AI vendor risk, delivering security awareness training and providing senior leadership with visibility of the organisation's AI security risk posture.

The successful candidate will have strong experience in Information Security Governance, Risk & Compliance (GRC), enterprise security policy development and regulatory compliance, with practical knowledge of GDPR and AI governance.

Key Responsibilities
AI Security Governance & Policy
  • Own and maintain the security governance framework for the AI development environment.
  • Develop, maintain and enforce AI-specific security policies and standards.
  • Draft and manage:
  • AI Acceptable Use Policy
  • AI Data Classification Policy
  • Agentic Action Policy
  • Ensure policies clearly define user responsibilities and security requirements.
  • Establish appropriate governance controls for AI-assisted and agentic workflows.
  • Coordinate regular policy reviews and incorporate lessons learned from incidents and audits.
Regulatory Compliance
  • Lead regulatory and compliance assessments relating to AI usage.
  • Assess requirements under GDPR, EU AI Act and relevant sector-specific regulations.
  • Translate regulatory requirements into practical security controls and policies.
  • Maintain evidence and documentation required for compliance assessments and audits.
  • Monitor regulatory developments affecting AI security and governance.
Third-Party Risk Management
  • Lead third-party security and risk assessments for AI technology providers.
  • Manage ongoing security monitoring of critical AI vendors.
  • Assess vendor security controls, risks and compliance posture.
  • Track remediation activities and elevate significant third-party risks.
  • Maintain appropriate third-party risk documentation and governance records.
Security Awareness & User Responsibilities
  • Develop and deliver mandatory security awareness training for AI users.
  • Ensure users understand acceptable use, data handling and security responsibilities.
  • Promote secure and responsible use of AI technologies.
  • Monitor compliance with relevant policies and identify areas requiring further awareness or training.
Risk Reporting & Stakeholder Management
  • Assess and monitor AI security risks across the organisation.
  • Prepare security risk reporting for the CISO and AI Governance Committee.
  • Communicate security risks, control gaps and remediation recommendations to senior stakeholders.
  • Coordinate with Security, Legal, Compliance, Privacy, Technology and business teams.
  • Support security investigations, audits and governance reviews.
Required Experience & Skills
Mandatory
  • 6+ years' experience in Information Security Governance, Risk & Compliance (GRC).
  • Strong enterprise security policy development and lifecycle management experience.
  • Strong knowledge of GDPR.
  • Practical understanding of AI governance and security risks.
  • Awareness of EU AI Act obligations.
  • Experience conducting regulatory or compliance assessments.
  • Strong third-party risk management experience.
  • Experience developing and implementing security governance frameworks.
  • Strong stakeholder management and communication skills.
  • Experience working within a regulated industry such as financial services, healthcare or defence.
Desirable
  • Experience with NIST AI Risk Management Framework (AI RMF).
  • Experience with AI governance frameworks and controls.
  • CISM certification.
  • CRISC certification.
  • ISO 27001 Lead Implementer certification.
  • Experience governing AI coding assistants or agentic AI technologies.
  • Experience managing AI-specific policies and acceptable-use frameworks.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI Security Architect
AI Security Architect

Polo • Cheltenham

Hybrid
GBP 75,000 - 85,000
AI Security Architect
AI Security Architect

Polo • Greater London

On-site
GBP 75,000 - 85,000
Security Architect - AI Platform
Security Architect - AI Platform

Vbeyond • Greater London

On-site
GBP 120,000 - 150,000
AI Security Policy & Governance Lead
AI Security Policy & Governance Lead

Vbeyond • Greater London

On-site
GBP 110,000 - 150,000
AI Governance SME
AI Governance SME

10Pearls • Greater London

On-site
GBP 90,000 - 130,000
AI Governance SME
AI Governance SME

10Pearls, LLC • Greater London

On-site
GBP 110,000 - 165,000
AI Security & Governance Workstream Lead
AI Security & Governance Workstream Lead

TEC Partners - Technical Recruitment Specialists • Reading

On-site
GBP 90,000 - 120,000
AI Security Engineer
AI Security Engineer

Norton Blake • Greater London

On-site
GBP 150,000 - 180,000
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
Senior Cyber Risk & AI Governance Consultant
Senior Cyber Risk & AI Governance Consultant

Bestman Solutions • Guildford

On-site
GBP 90,000 - 120,000