Skip to main content
Dotmatics

Head of AI Governance

RemoteUnited Kingdom only
Published
Role
Security
Experience
C-Level
Company size
Enterprise
£98.5k–£133.3k/yr
Check eligibility

Open to GB only. Set where you work from to check your eligibility.

No BS summary

Senior Head of AI Governance to lead and mature Dotmatics' AI governance program and cross-functional council. Requires 15–20 years in information security/tech risk/data governance with 5–8 years specifically in AI/ML governance; experience with AI regulatory frameworks (EU AI Act, NIST AI RMF, ISO 42001) and life-sciences (GxP) is an advantage. Remote role restricted to the United Kingdom.

Core skills

AI governancemodel risk managementlarge language models

Required skills

EU AI ActISO/IEC 42001NIST AI RMFISO/IEC 27001ISO 9001GxPGDPRAI agentsAPIsdata pipelinesinformation securitydata privacy

Optional skills

Experience in Life Sciences (GxP)scientific informatics or cheminformatics domain knowledgeAIGPCIPPCISMCRISC

What you'll do

  • Lead the development and ongoing improvement of a comprehensive AI Governance Framework aligned with Dotmatics' risk appetite and regulatory obligations, including the EU AI Act, ISO 42001, and NIST AI RMF
  • Maintain an AI use case registry, establish risk tiering and oversight levels for AI systems, and provide subject matter expertise to evaluate AI tools, models, and applications proposed by business and product teams
  • Partner with leadership and functional teams to assess AI use cases across model behaviour, data usage, privacy, and operational risk; ensuring alignment with the company's ISO/IEC 27001 ISMS, ISO 9001 QMS, and GxP requirements
  • Serve as program lead for the Dotmatics AI Governance Council, coordinating agendas, workflows, and decision-ready materials for Council and executive review
  • Act as the primary Dotmatics liaison to the Siemens AI Governance Consortium, representing the company in cross-portfolio working groups and contributing to joint frameworks and maturity models
  • Provide AI governance responses to customer RFIs, security questionnaires, and due diligence inquiries
  • Embed governance checkpoints into the SDLC alongside Product and Engineering; align AI controls with the broader security posture and incident response procedures
  • Lead the creation and maintenance of AI governance policies, SOPs, and supporting documentation; and develop and deliver AI governance training across the organization
  • Produce management reporting, metrics, and dashboards to keep senior leadership informed of program status, risk exposure, and control effectiveness
  • Drive continuous improvement by incorporating lessons learned, evolving standards, and regulatory developments

What they require

  • Bachelor's degree in Computer Science, Information Systems, Risk Management, Engineering, Business, or a related discipline (or equivalent experience)
  • 15-20 years in information security, technology risk management, data governance, or compliance in a regulated industry
  • 5-8 years of progressive experience specifically in AI/ML governance
  • Experience in the Life Sciences (GxP) sector and knowledge of the scientific informatics or cheminformatics space is a strong advantage
  • Demonstrated experience designing or operating AI governance programs, model risk management frameworks, or technology risk management processes
  • Deep understanding of the AI risk landscape, including generative AI, large language models, AI agents, and associated regulatory expectations
  • Working knowledge of global AI and privacy regulatory frameworks, including the EU AI Act, GDPR, NIST AI RMF, and ISO/IEC 42001
  • Proven ability to work across and influence cross-functional stakeholder groups, including HR, Product, Engineering, Legal, Compliance, Finance, and Executive leadership, without direct line authority
  • Experience managing or contributing to governance councils, steering committees, or similar oversight bodies
  • In-depth knowledge of AI/ML technologies, including large language models, AI-enabled applications, APIs, and data pipelines, sufficient to assess technical feasibility and risk
  • Implementation-level understanding of information security principles, data privacy controls, and life science compliance frameworks (e.g., ISO 27001, NIST 800-53, ISO 9001, GxP, GDPR, CCPA)
  • Strong project management discipline with a track record of building programs and processes from the ground up
  • Excellent written and verbal communication skills, including the ability to prepare executive-ready materials and governance documentation
  • Relevant professional certifications desirable: AIGP, CIPP, CISM, CRISC, or equivalent

Benefits

  • Private Medical Wellness Benefits (Mental Health Apps and Fitness Perks)
  • Company-paid Life cover
  • EAP (Employee Assistance Program)
  • Pension/Retirement Plan
  • Certain positions are eligible for variable pay
  • Total rewards package (compensation, benefits and recognition)

R&D scientific software company in the US

🇲🇽 MexicoLife SciencesEnterprisedotmatics.com
£98.5k–£133.3k/yr