Security Governance & Policy Lead - AI


Company 

Vbeyond

Location 

London

Employment Hours 

Full Time

Employment Type 

Permanent

Salary 

Job Requirements/Description

Role Overview

We are seeking an experienced Security Governance & Policy Lead - AI to own the security policy, governance and compliance framework for the organisation's AI coding and agentic development environment.

The role will be responsible for establishing appropriate security policies and governance controls, assessing regulatory obligations, managing third-party AI vendor risk, delivering security awareness training and providing senior leadership with visibility of the organisation's AI security risk posture.

The successful candidate will have strong experience in Information Security Governance, Risk & Compliance (GRC), enterprise security policy development and regulatory compliance, with practical knowledge of GDPR and AI governance.

Key ResponsibilitiesAI Security Governance & Policy

  • Own and maintain the security governance framework for the AI development environment.
  • Develop, maintain and enforce AI-specific security policies and standards.
  • Draft and manage:
  • AI Acceptable Use Policy
  • AI Data Classification Policy
  • Agentic Action Policy
  • Ensure policies clearly define user responsibilities and security requirements.
  • Establish appropriate governance controls for AI-assisted and agentic workflows.
  • Coordinate regular policy reviews and incorporate lessons learned from incidents and audits.

Regulatory Compliance

  • Lead regulatory and compliance assessments relating to AI usage.
  • Assess requirements under GDPR, EU AI Act and relevant sector-specific regulations.
  • Translate regulatory requirements into practical security controls and policies.
  • Maintain evidence and documentation required for compliance assessments and audits.
  • Monitor regulatory developments affecting AI security and governance.

Third-Party Risk Management

  • Lead third-party security and risk assessments for AI technology providers.
  • Manage ongoing security monitoring of critical AI vendors.
  • Assess vendor security controls, risks and compliance posture.
  • Track remediation activities and escalate significant third-party risks.
  • Maintain appropriate third-party risk documentation and governance records.

Security Awareness & User Responsibilities

  • Develop and deliver mandatory security awareness training for AI users.
  • Ensure users understand acceptable use, data handling and security responsibilities.
  • Promote secure and responsible use of AI technologies.
  • Monitor compliance with relevant policies and identify areas requiring further awareness or training.

Risk Reporting & Stakeholder Management

  • Assess and monitor AI security risks across the organisation.
  • Prepare security risk reporting for the CISO and AI Governance Committee.
  • Communicate security risks, control gaps and remediation recommendations to senior stakeholders.
  • Coordinate with Security, Legal, Compliance, Privacy, Technology and business teams.
  • Support security investigations, audits and governance reviews.

Required Experience & SkillsMandatory

  • 6+ years' experience in Information Security Governance, Risk & Compliance (GRC).
  • Strong enterprise security policy development and lifecycle management experience.
  • Strong knowledge of GDPR.
  • Practical understanding of AI governance and security risks.
  • Awareness of EU AI Act obligations.
  • Experience conducting regulatory or compliance assessments.
  • Strong third-party risk management experience.
  • Experience developing and implementing security governance frameworks.
  • Strong stakeholder management and communication skills.
  • Experience working within a regulated industry such as financial services, healthcare or defence.

Desirable

  • Experience with NIST AI Risk Management Framework (AI RMF).
  • Experience with AI governance frameworks and controls.
  • CISM certification.
  • CRISC certification.
  • ISO 27001 Lead Implementer certification.
  • Experience governing AI coding assistants or agentic AI technologies.
  • Experience managing AI-specific policies and acceptable-use frameworks.
Company 

Vbeyond

Location 

London

Employment Hours 

Full Time

Employment Type 

Permanent

Salary 

An unhandled error has occurred. Reload 🗙