National AI Awards 2025Discover AI's trailblazers! Join us to celebrate innovation and nominate industry leaders.

Nominate & Attend

Head of Security Governance, Risk & Compliance

Cambridge
2 weeks ago
Applications closed

Related Jobs

View all jobs

Head of GRC - Cybersecurity

Head of Security Architecture & Compliance

Information Security Manager

Security Architect - Data

IT Security Engineering Manager

Head of Cyber Security

Head of Security Governance, Risk & Compliance

  • Salary: £70,400 - £94,100

  • Location: Cambridge/Hybrid Minimum 2 days a week in the office

  • Contract: Permanent

    The Head of Security GRC is a senior leadership role within the Security SMT, tasked with driving the organisation's security governance, risk, and compliance strategy. This position engages across all levels of the business, ensuring regulatory compliance, effective risk management, and robust assurance processes to support decision-making by the Senior Leadership Team.

    You will deliver a robust Security Assurance Framework, oversee supplier assurance activities, and maintain relevant ISO and Cyber Essentials certifications. Additionally, you'll drive the implementation of security standards, policies, governance reporting, and audit programmes to ensure robust controls are in place. You'll play a critical role in enabling informed decision-making and promoting a culture of security awareness across the organisation.

    We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge.

    About the role

    The position involves engaging at all organisational levels, managing security risks, ensuring regulatory compliance, and providing assurance on business practices to support informed decisions by the Senior Leadership Team and Security Board. Responsibilities include implementing and monitoring security standards, policies, AI governance, and audit programmes to ensure effective mitigations and controls. Additionally, the role entails designing and delivering the Security Assurance Framework, conducting supplier assurance activities and audits, leading the Awareness Community of Practice, and maintaining relevant ISO & Cyber Essentials certifications.

    Key Accountabilities:

  • Develops security standards, policies, and guidelines and ensures compliance across Cambridge.

  • Leads the delivery of approved projects and investments to reduce risk and security exposure.

  • Proactively identifies new threats, risks, and trends; reports mitigation progress to the Security Board and SLT.

  • Collaborates with key stakeholders to create customer-centric security policies for products and services.

  • Coordinates audits, regulatory inquiries, and external vendor activities to align with industry standards.

  • Responsible for leading and managing the GRC team to achieve compliance and team success in the organisation.

  • Oversees vendor relationships to ensure protection of Cambridge global people and assets.

  • Aligns attack surface management (ASM) process with GRC objectives and provides updates on mitigation progress.

  • Integrates AI governance with relevant GRC frameworks to meet regulatory standards.

  • Manages certifications like ISO 27001, 42001, Cyber Essentials, and HMG Security Policy Framework.

    About you

    We are looking for a highly skilled and experienced professional with the following expertise:

  • Proven experience managing an Information Security Management System (ISMS), including ISO 27001 certification.

  • Strong working knowledge of security threats and proportionate mitigations, as well as supply chain security management systems.

  • A minimum of 3 years' experience in a senior governance or risk management role.

  • Active CRISC or ISO 27005 Risk Manager certification (or higher), with additional certifications such as ISO 27001/42001 Lead Auditor or Implementor being advantageous.

  • Demonstrated experience in strategic governance of security, managing security risks in line with ISO 27005, and implementing ISO 27001 compliant systems.

  • Expertise in auditing security controls for both internal operations and third parties.

  • Exceptional stakeholder management skills, with the ability to build relationships across all organisational levels.

  • Strong negotiation skills to influence decisions and achieve positive outcomes.

  • Experience leading and developing teams, both within the UK and regionally.

    If you would like to know more about this opportunity and what will make you successful, please see the full job description attached to the bottom of this vacancy on our careers site.

    Rewards and benefits

    We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package, featuring family-friendly and planet-friendly benefits including:

  • 28 days annual leave plus bank holidays

  • Private medical and Permanent Health Insurance

  • Discretionary annual bonus

  • Group personal pension scheme

  • Life assurance up to 4 x annual salary

  • Green travel schemes

    We are a hybrid working organisation, and we offer a range of flexible working options from day one. We expect most hybrid-working colleagues to spend 40-60% of their time at their dedicated office or location. We will also consider other work arrangements if you wish to work more flexibly or require adjustments due to a disability.

    Ready to pursue your potential? Apply now.

    We review applications on an ongoing basis, with a closing date for all applications being 27th July although we may close it earlier if suitable candidates are identified. Interviews are scheduled to take place shortly after it closes.

    Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry.

    University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov website for guidance to understand your own eligibility based on the role you are applying for.

    Head of Security Governance, Risk & Compliance
National AI Awards 2025

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Cyber Security Jobs Skills Radar 2026: Emerging Frameworks, Tools & Certifications to Learn Now

Cyber threats are evolving—and so must the people defending against them. As ransomware, AI-enhanced phishing, and supply chain attacks grow more advanced, UK employers are urgently hiring cyber security professionals with the right mix of strategic and hands-on skills. Welcome to the Cyber Security Jobs Skills Radar 2026, your go-to guide for the most in-demand tools, frameworks, certifications, and technologies shaping the UK's cyber workforce. Whether you're a SOC analyst, penetration tester, or cloud security architect, this annual radar is designed to help you stay ahead of the market.

How to Find Hidden Cyber Security Jobs in the UK Using Professional Bodies like BCS, CIISec & More

The demand for skilled cyber security professionals in the UK has never been higher. With threats increasing in sophistication and frequency, organisations are urgently hiring ethical hackers, threat analysts, GRC specialists, and security architects. But many of the most valuable roles—particularly in government, defence, and critical infrastructure—are never publicly advertised. Instead, these jobs are shared behind the scenes through trusted networks, private communities, and professional bodies. In this article, we explore how to uncover hidden cyber security jobs in the UK using organisations like the BCS (The Chartered Institute for IT), CIISec (The Chartered Institute of Information Security), ISACA, and ISC² UK Chapter. We’ll show you how to use membership directories, special interest groups, CPD events and informal networks to gain early access to roles most people never see.

How to Get a Better Cyber Security Job After a Lay-Off or Redundancy

Redundancy is never easy—especially in a fast-moving field like cyber security, where your skills and experience are constantly evolving. But if you’ve recently been made redundant from a cyber security role, know this: the UK cyber workforce remains in high demand, and your expertise is more valuable than ever. Whether you’re a SOC analyst, penetration tester, incident responder, security architect or GRC specialist, there are still thousands of opportunities across sectors including finance, defence, government, retail, and critical infrastructure. This guide will help you turn redundancy into a career relaunch, with a clear action plan tailored to the UK cyber security job market.