At a Glance
- Tasks: Lead cyber security governance, risk management, and compliance initiatives.
- Company: GlobalData helps clients decode the future with expert analysis and innovative solutions.
- Benefits: Enjoy health perks, fitness support, travel benefits, and a diverse work environment.
- Why this job: Join a fast-paced, entrepreneurial team making a real impact in cyber security.
- Qualifications: Bachelor's degree in Cyber Security or related field; 5-7 years experience preferred.
- Other info: This is a newly created role reporting to the Chief Information & Security Officer.
The predicted salary is between 43200 - 72000 £ per year.
Who we are… GlobalData is a specialist information services business on a mission to help our clients decode the future, make better decisions and reach more customers. Using our unique data, expert analysis and innovative solutions we deliver intelligence on the world’s largest industries for companies, government organisations and industry professionals. We began our journey in 2016, by combining a diverse range of specialist information services companies, with decades of trusted customer relationships and deep sector specialisms. Today, we operate as a single company and one fully integrated platform, with more than 3,500 colleagues worldwide, across 20+ industries, delivering value for over 5,000 customers.
Why join GlobalData? GlobalData is at a pivotal point in its growth journey. Following multiple acquisitions and having recently received transformational investment we need curious, ambitious, courageous people to support us in achieving our vision of becoming the world’s trusted source of strategic industry intelligence. Our big ambitions mean that life at GlobalData is fast paced, entrepreneurial and rewarding. We recognise the collective power of our people, and it’s the collaboration of our teams that have shaped our success and will continue to do so in the future.
The role… We are looking for a Cyber Security Governance Risk and Compliance Lead to join the corporate team at GlobalData. This is a newly created role, reporting into the Chief Information & Security Officer. The Cyber Security GRC Lead will be responsible for implementing ISO 27001 and gaining certification.
What you'll be doing...
- Governance: Develop and maintain cyber security policies and governance framework in line with ISO 27001. Ensure alignment with organisational goals and strategic objectives.
- Risk Management: Lead and implement the risk management process, including risk identification, assessment and mitigation. Perform regular risk assessments to ensure appropriate risk mitigation strategies are in place, in alignment with an evolving threat landscape and business growth.
- Compliance: Establish a compliance programme and conduct internal audits to assess the operational effectiveness of existing controls and ensure adherence to company policy.
- Stakeholder Engagement: Collaborate with key stakeholders across the business, including IT, legal, sales and HR, to ensure effective integration of policies.
- Continuous Improvement: Drive continuous improvement initiatives to enhance and mature the company’s security posture, while densifying new tools, technologies and best practices.
What we're looking for...
- Bachelor's degree in Cyber Security, Information Technology, or a related field (or equivalent work experience)
- 5-7 years of experience in cyber security, with a focus on Governance Risk and Compliance. Experience at an enterprise, global company desirable.
- Relevant certifications such as CISA, CRISC, CISM or equivalent is highly preferred.
- Proven experience in implementing and/or maintaining ISO 27001 certification is highly preferred.
- Knowledge and expertise with other risk and compliance frameworks, such as NIST, is also acceptable.
- Strong experience in risk management, including risk assessments and remediation strategies.
- Extensive experience in leading or managing audits, compliance assessments, and certifications.
- Familiarity with cyber security technologies, tools, and methodologies.
- Excellent communication skills, with the ability to present complex concepts to non-technical stakeholders.
In addition to a rewarding career, we support our GlobalData colleagues with a range of benefits across health, finances, fitness, travel, tech and more. To find out more about the roles and benefits on offer in your region, visit careers.globaldata.com.
GlobalData believes strongly in the value of diversity and creating supportive, inclusive environments where our colleagues can succeed. As such, we are proud to be an Equal Opportunity Employer. GlobalData is determined to ensure that no applicant or employee receives less favourable treatment on the grounds of gender, age, disability, religion, belief, sexual orientation, marital status, race, or is disadvantaged by conditions or requirements which cannot be shown to be justifiable.
Cyber Security GRC Lead employer: GlobalData Plc
Contact Detail:
GlobalData Plc Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security GRC Lead
✨Tip Number 1
Familiarise yourself with ISO 27001 and other relevant compliance frameworks like NIST. Understanding these standards will not only help you in the interview but also demonstrate your commitment to the role.
✨Tip Number 2
Network with professionals in the cyber security field, especially those who have experience in Governance, Risk, and Compliance. Engaging with industry peers can provide insights and potentially valuable connections that could aid your application.
✨Tip Number 3
Prepare to discuss specific examples of how you've implemented risk management processes in previous roles. Being able to articulate your hands-on experience will set you apart from other candidates.
✨Tip Number 4
Showcase your communication skills by preparing to explain complex cyber security concepts in simple terms. This is crucial for engaging with non-technical stakeholders, which is a key part of the role.
We think you need these skills to ace Cyber Security GRC Lead
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in cyber security, particularly in Governance, Risk, and Compliance. Emphasise any experience with ISO 27001 and other compliance frameworks, as well as your ability to communicate complex concepts effectively.
Craft a Compelling Cover Letter: In your cover letter, express your enthusiasm for the role and the company. Discuss how your background aligns with GlobalData's mission and values, and provide specific examples of your achievements in risk management and compliance.
Highlight Relevant Certifications: If you hold certifications such as CISA, CRISC, or CISM, make sure to mention them prominently in your application. These credentials are highly preferred for this role and can set you apart from other candidates.
Showcase Stakeholder Engagement Skills: Demonstrate your experience in collaborating with various stakeholders across different departments. Provide examples of how you've successfully integrated policies and driven continuous improvement initiatives in previous roles.
How to prepare for a job interview at GlobalData Plc
✨Understand ISO 27001 Inside Out
Make sure you have a solid grasp of ISO 27001 and its requirements. Be prepared to discuss how you've implemented or maintained this standard in previous roles, as it will be a key focus for the Cyber Security GRC Lead position.
✨Showcase Your Risk Management Experience
Highlight your experience with risk management processes, including risk identification, assessment, and mitigation. Be ready to provide examples of how you've successfully managed risks in a fast-paced environment.
✨Prepare for Stakeholder Engagement Scenarios
Since collaboration with various stakeholders is crucial, think of examples where you've effectively communicated complex security concepts to non-technical teams. This will demonstrate your ability to bridge the gap between technical and non-technical stakeholders.
✨Continuous Improvement Mindset
Discuss any initiatives you've led that focused on enhancing security posture or implementing new tools and technologies. Showing a proactive approach to continuous improvement will resonate well with the company's ambitions.