Be at the heart of actionFly remote-controlled drones into enemy territory to gather vital information.

Apply Now

Governance, Risk and Compliance Manager

Digital Waffle
Birmingham
9 months ago
Applications closed

Related Jobs

View all jobs

Information Security and Compliance Manager

Cyber Security Risk Manager

Third Party Risk Manager

Cyber Security GRC Manager - London

Senior InfoSec Advisor (IRM Manager)

Information Security Manager

Job Title: Governance, Risk and Compliance Manager
Location: Birmingham (90% Remote)
Salary: £75k + Bonus

We are seeking a skilled Governance, Risk, and Compliance Manager to join our Compliance team. In this pivotal role, you will ensure our organisation’s adherence to global regulations and standards, while developing and managing comprehensive risk management strategies. You will work closely with senior leaders, supporting them in meeting their compliance obligations and managing risks across the business and its subsidiaries.
Key Skills:

  • Strong knowledge of regulations and standards (e.g., GDPR, PECR, HIPAA, PCI, SOC2, NIST, DORA, ISO27001), with experience in implementation and monitoring.
  • Building frameworks.
  • Setting up controls and policies.
  • Building best practices for each territory (multi-country).


Key Responsibilities:

  • Design and implement governance frameworks to ensure that risks and compliance matters are identified and escalated appropriately.
  • Guide stakeholders through regulatory requirements, ensuring compliant and effective outcomes.
  • Oversee risk identification, evaluation, and mitigation processes, helping senior management understand their risk profile and mitigation strategies.
  • Manage and maintain the global Risk Register to ensure accurate and up-to-date information is readily available.
  • Maintain a central repository of regulations and certifications, ensuring clarity on compliance requirements in every region we operate.
  • Collaborate with stakeholders to address any issues affecting regulatory compliance.
  • Coordinate attestations and regulatory audits across our global operations.
  • Lead training initiatives to improve staff understanding of compliance obligations, policies, and regulations.
  • Continuously monitor the regulatory environment to identify and prepare for potential changes.
  • Keep up to date with the latest compliance regulations and industry best practices.


Person Specification:

  • Significant experience in governance, risk, and compliance, ideally in industries such as SaaS, technology, telecommunications or similar.
  • Experience managing risk frameworks across multiple regions and entities, including risk appetite calibration and impact assessment.
  • Strong knowledge of regulations and standards (e.g., GDPR, PECR, HIPAA, PCI, SOC2, NIST, DORA, ISO27001), with experience in implementation and monitoring.
  • Excellent communication skills, capable of presenting complex concepts clearly to senior stakeholders.
  • Ability to work independently and as part of a collaborative team in a fast-paced, dynamic environment.
  • Willingness to work flexibly with colleagues across different time zones and locations when necessary.



''#J-18808-Ljbffr

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Cyber Security Recruitment Trends 2025 (UK): What Job Seekers Must Know About Today’s Hiring Process

Summary: UK cyber security hiring has shifted from title‑led CV screens to capability‑driven assessments that emphasise incident readiness, cloud & identity security, detection engineering, governance/risk/compliance (GRC), measurable MTTR/coverage gains & secure‑by‑default engineering. This guide explains what’s changed, what to expect in interviews, & how to prepare—especially for SOC analysts, detection engineers, blue/purple teamers, penetration testers, cloud security engineers, DFIR, AppSec, GRC & security architecture. Who this is for: SOC & detection engineers, security operations leads, DFIR analysts, penetration testers/red teamers, purple teamers, AppSec/DevSecOps engineers, security architects, cloud security engineers, identity/IAM engineers, vulnerability managers, GRC/compliance specialists, product security & security programme managers targeting roles in the UK.

Why Cyber Security Careers in the UK Are Becoming More Multidisciplinary

Cyber security used to be viewed primarily as a technical discipline: firewalls, encryption, intrusion detection, penetration testing. In the UK today, it’s far broader. Organisations now face complex legal frameworks, ethical dilemmas, human-behaviour risks, communication challenges & usability hurdles. This shift means cyber security careers are becoming more multidisciplinary. From protecting NHS patient records to defending financial services, securing supply chains & safeguarding national infrastructure, cyber security now touches every sector. Employers increasingly want professionals who understand law, ethics, psychology, linguistics & design alongside traditional technical skills. In this article, we’ll explore why UK cyber security careers are expanding in this way, how these five disciplines shape the profession, and what job-seekers & employers need to know to thrive in this new landscape.

Cyber Security Team Structures Explained: Who Does What in a Modern Cyber Security Department

Cyber security has become a top priority for UK organisations of all sizes. From small businesses to financial institutions, healthcare providers, and government bodies, the risk of cyber attack is now a constant concern. Threats are more sophisticated, regulations more demanding, and customers more aware of data privacy than ever before. But defending against cyber threats isn’t simply about having the right tools — it’s about having the right team. A modern cyber security department relies on clearly defined roles and responsibilities to ensure that defences are proactive, incidents are managed swiftly, and compliance is maintained. This article explains the structure of a modern cyber security team, the roles you’ll typically find within it, how they collaborate, and what skills, qualifications, and salaries are expected in the UK job market.