Shape the Future of AIJoin one of the UK's fastest-growing companies and become a Professional Development Expert in Artificial Intelligence.

View Roles

Head of Cybersecurity Governance Risk and Compliance

Cowley
6 days ago
Create job alert

Head of Cybersecurity Governance Risk and Compliance

Location: Mainly remote based working in the UK with travel to Oxford, Cowley (OX4 2GQ) occasionally
Contract: Permanent
Hours: Full time
Salary: £70,000 per annum, plus car / car allowance
Benefits: 33 days holiday, pension, life assurance, employee assistance programme, wellbeing support, and flexible benefits scheme

About the Job
 
As our Head of Cybersecurity Governance Risk and Compliance you’ll work closely with business and technology teams, helping to articulate and communicate the InfoSec governance program, identify risks and evaluate and help implement controls and improvements.
 
As part of your key responsibilities you’ll:
 
• Manage the day to day of the function and team
• Support the management of Information Security governance for the organisation, ensuring adherence to Group policies and standards
• Ensure key Information Security risks and issues are identified, addressed and resolved in a timely manner
• Work closely with the Director of Information Security to ensure Group security strategy is appropriately implemented, and divisional requirements are understood and supported
• Assist in management of the Group’s Information Security Management System including maintenance of the ISO 27001 certification
• Engage with the IT Security Operations team and assist the Director of Information Security in providing oversight and challenge to that function
• Participate in periodic security related testing activities (e.g. Crisis planning events, DR exercises)
• Prioritise and manage response activities
• Drive the audit and client management aspects of the Information Security team, including client due diligence questionnaires, and help design more effective procedures in this space
• Improve and support relevant security metrics; analyse data, identify trends and drive improvements to the control environment
• Assist in general Information Security related issues as required, including potential interaction with the Security Operations team, Technology teams and business stakeholders
• Working with the Security Architect ensure alignment of bid requirements with existing InfoSec standards and liaise with relevant teams for resolution where non-standard requirements are identified

About You
 
We’d love you to have the following skills and experience, but please apply if you think you’d be able to perform well in this role!
 
• Excellent written and verbal communication skills
• Previous experience within a GRC function, IT Security/Cyber team, Internal Audit or an IT environment
• Hands on practical experience of ensuring full compliance with legal & regulatory frameworks including ISO 27001
• Risk management
• Strong leadership and communication skills, with the ability to motivate and manage a team

Our recruitment and selection process has been developed to ensure that it is consistent, fair and provides equality of opportunity - all selection decisions are based solely on technical and behavioural competencies. We do not discriminate on the grounds of race, colour, or nationality, ethnic or national origins, sex, gender reassignment, sexual orientation, marital or civil partnership status, pregnancy or maternity, disability, religion or belief, age or any other current or future protected characteristic as defined in the current Equality Act of England and Wales. As an organisation we also promote an environment which encourages diversity of characteristics and thought, where you feel included, safe and confident to be the best version of yourself and do your best work every day.
 
You may also have experience in the following: Head of Cybersecurity GRC, Head of Information Security Governance, Cybersecurity Governance Lead, GRC Manager (Cybersecurity), Information Security Risk Manager, Senior GRC Consultant (Cybersecurity), Cybersecurity Risk and Compliance Lead, Information Security Compliance Manager, Head of InfoSec Governance, ISO 27001 Compliance Lead, ISO 27001 Lead Implementer / Auditor, NIST Cybersecurity Framework, Risk management (cyber/information security), Information Security Management System (ISMS), Control assurance / control testing, Regulatory compliance (GDPR, UK Cyber Essentials), Security governance frameworks
 
REF-(Apply online only)

Related Jobs

View all jobs

Head of Cybersecurity Governance Risk and Compliance

Global Head of Solutioning - Cybersecurity

Head of GRC - Cybersecurity

Risk Management Specialist (93986)

Information Security Officer (ISO)

Data Protection Officer

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Automate Your Cyber Security Jobs Search: Using ChatGPT, RSS & Alerts to Save Hours Each Week

Cyber roles drop across consultancies, MSSPs, hyperscalers, banks, gov & start-ups every day—often buried in ATS portals or duplicated across boards. The fix is simple: put discovery on autopilot with keyword-rich alerts, RSS feeds & a reusable ChatGPT workflow that triages listings, ranks fit, & tailors your CV in minutes. This copy-paste playbook is built for www.cybersecurityjobs.tech readers. It’s UK-centric, practical, & designed to save you hours each week. What You’ll Have Working In 30 Minutes A role & keyword map spanning SecOps/Detection, DFIR, AppSec, Cloud Security, GRC, Red Team, Threat Intel, IAM/PAM, OT/ICS & Vulnerability Management. Shareable Boolean search strings for Google & job boards to cut noise fast. Always-on alerts & RSS feeds delivering fresh roles to your inbox/reader. A ChatGPT “Cyber Job Scout” prompt that deduplicates, scores fit & outputs tailored actions. A simple pipeline tracker so deadlines & follow-ups never slip.

10 Cyber Security Recruitment Agencies in the UK You Should Know (2025 Job‑Seeker Guide)

UK cyber security hiring remains resilient in 2025, driven by nation-state threats, cloud security investments, and NCSC regulatory pressures. Lightcast reports +42 % YoY growth in UK roles mentioning “SOC”, “cyber risk”, “offensive security” or “GRC”. Yet despite 30,000 active cyber professionals, monthly live vacancies remain in the 2,500–2,900 range. The result: strong demand across public and private sector. We reviewed 50 + consultancies and included only those that: Are registered in the UK (Companies House) Operate a dedicated Cyber Security / InfoSec / Risk & Compliance desk Posted at least 5 UK cyber security roles between March and June 2025 This guide includes 2025 salary ranges, key skills, interview prep tips, and a verified recruiter directory.

Cyber Security Jobs Skills Radar 2026: Emerging Frameworks, Tools & Certifications to Learn Now

Cyber threats are evolving—and so must the people defending against them. As ransomware, AI-enhanced phishing, and supply chain attacks grow more advanced, UK employers are urgently hiring cyber security professionals with the right mix of strategic and hands-on skills. Welcome to the Cyber Security Jobs Skills Radar 2026, your go-to guide for the most in-demand tools, frameworks, certifications, and technologies shaping the UK's cyber workforce. Whether you're a SOC analyst, penetration tester, or cloud security architect, this annual radar is designed to help you stay ahead of the market.