Be at the heart of actionFly remote-controlled drones into enemy territory to gather vital information.

Apply Now

Head of Cybersecurity Governance Risk and Compliance

Cowley
3 weeks ago
Create job alert

Head of Cybersecurity Governance Risk and Compliance

Location: Mainly remote based working in the UK with travel to Oxford, Cowley (OX4 2GQ) occasionally
Contract: Permanent
Hours: Full time
Salary: £70,000 per annum, plus car / car allowance
Benefits: 33 days holiday, pension, life assurance, employee assistance programme, wellbeing support, and flexible benefits scheme

About the Job
 
As our Head of Cybersecurity Governance Risk and Compliance you’ll work closely with business and technology teams, helping to articulate and communicate the InfoSec governance program, identify risks and evaluate and help implement controls and improvements.
 
As part of your key responsibilities you’ll:
 
• Manage the day to day of the function and team
• Support the management of Information Security governance for the organisation, ensuring adherence to Group policies and standards
• Ensure key Information Security risks and issues are identified, addressed and resolved in a timely manner
• Work closely with the Director of Information Security to ensure Group security strategy is appropriately implemented, and divisional requirements are understood and supported
• Assist in management of the Group’s Information Security Management System including maintenance of the ISO 27001 certification
• Engage with the IT Security Operations team and assist the Director of Information Security in providing oversight and challenge to that function
• Participate in periodic security related testing activities (e.g. Crisis planning events, DR exercises)
• Prioritise and manage response activities
• Drive the audit and client management aspects of the Information Security team, including client due diligence questionnaires, and help design more effective procedures in this space
• Improve and support relevant security metrics; analyse data, identify trends and drive improvements to the control environment
• Assist in general Information Security related issues as required, including potential interaction with the Security Operations team, Technology teams and business stakeholders
• Working with the Security Architect ensure alignment of bid requirements with existing InfoSec standards and liaise with relevant teams for resolution where non-standard requirements are identified

About You
 
We’d love you to have the following skills and experience, but please apply if you think you’d be able to perform well in this role!
 
• Excellent written and verbal communication skills
• Previous experience within a GRC function, IT Security/Cyber team, Internal Audit or an IT environment
• Hands on practical experience of ensuring full compliance with legal & regulatory frameworks including ISO 27001
• Risk management
• Strong leadership and communication skills, with the ability to motivate and manage a team

Our recruitment and selection process has been developed to ensure that it is consistent, fair and provides equality of opportunity - all selection decisions are based solely on technical and behavioural competencies. We do not discriminate on the grounds of race, colour, or nationality, ethnic or national origins, sex, gender reassignment, sexual orientation, marital or civil partnership status, pregnancy or maternity, disability, religion or belief, age or any other current or future protected characteristic as defined in the current Equality Act of England and Wales. As an organisation we also promote an environment which encourages diversity of characteristics and thought, where you feel included, safe and confident to be the best version of yourself and do your best work every day.
 
You may also have experience in the following: Head of Cybersecurity GRC, Head of Information Security Governance, Cybersecurity Governance Lead, GRC Manager (Cybersecurity), Information Security Risk Manager, Senior GRC Consultant (Cybersecurity), Cybersecurity Risk and Compliance Lead, Information Security Compliance Manager, Head of InfoSec Governance, ISO 27001 Compliance Lead, ISO 27001 Lead Implementer / Auditor, NIST Cybersecurity Framework, Risk management (cyber/information security), Information Security Management System (ISMS), Control assurance / control testing, Regulatory compliance (GDPR, UK Cyber Essentials), Security governance frameworks
 
REF-(Apply online only)

Related Jobs

View all jobs

Head of Risk Reporting

Assistant Vice President, Penetration Tester

Risk Reporting Data Engineering Lead

Head of Compliance

Chief Information Security Officer – Managing Director

Senior Information Security Analyst

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

The Future of Cybersecurity Jobs: Careers That Don’t Exist Yet

Cyber security has become one of the most critical issues of our age. Once regarded as a technical problem confined to IT departments, it is now a board-level priority, a government mandate, and a daily necessity for individuals. The shift towards cloud services, remote working, connected devices, and artificial intelligence has dramatically increased the risks of digital attacks. In the UK, cyber security is central to national resilience. The government has identified cyber as a “tier one” threat to national security, alongside terrorism and pandemics. The private sector, from banks to retailers, now sees data breaches and ransomware as existential risks. Global spending on cyber security is projected to exceed $250 billion by 2030, with the UK already home to a thriving cyber industry employing tens of thousands. Yet, as powerful as the industry already is, we are only at the beginning. The technologies shaping the next two decades—AI, quantum computing, edge computing, extended reality, and biotechnology—will radically reshape cyber security. Many of the most vital cyber security jobs of the future don’t exist yet. This article explores why new roles will emerge, the careers likely to appear, how today’s jobs will evolve, why the UK is well-positioned, and how professionals can prepare now.

Seasonal Hiring Peaks for Cybersecurity Jobs: The Best Months to Apply & Why

The UK's cybersecurity sector has emerged as one of the most critical and lucrative technology markets, with roles spanning from security analysts to penetration testers and chief information security officers. With cybersecurity positions commanding salaries from £28,000 for junior security analysts to £140,000+ for senior security architects, understanding when organisations actively recruit can dramatically impact your career trajectory in this essential field. Unlike traditional IT sectors, cybersecurity hiring follows distinct patterns influenced by threat landscapes, regulatory compliance cycles, and incident response requirements. The sector's unique combination of perpetual threat evolution, regulatory pressures, and skills shortages creates predictable hiring windows that strategic professionals can leverage to advance their careers in protecting Britain's digital infrastructure. This comprehensive guide explores the optimal timing for cybersecurity job applications in the UK, examining how cyber threat cycles, compliance deadlines, and government initiatives influence recruitment patterns, and why strategic timing can determine whether you join a cutting-edge security consultancy or miss the opportunity to defend against tomorrow's cyber threats.

Pre-Employment Checks for Cyber Security Jobs: DBS, References & Right-to-Work and more Explained

The cyber security sector in the UK stands at the forefront of protecting national infrastructure, business operations, and personal data from increasingly sophisticated cyber threats. As organisations across all sectors recognise cyber security as a critical business function, employers are implementing the most rigorous pre-employment screening processes in the technology industry to ensure they recruit professionals capable of defending against advanced persistent threats and maintaining the highest standards of security and trustworthiness. Whether you're a penetration tester, security analyst, incident response specialist, or chief information security officer, understanding the comprehensive vetting requirements is essential for successfully advancing your career in this security-critical field. This detailed guide explores the extensive background checks and screening processes you'll encounter when applying for cyber security positions in the UK, from fundamental eligibility verification to the most stringent security clearance requirements and specialised threat intelligence assessments.