Head of Security Governance, Risk & Compliance - 5880
Head of Security Governance, Risk & Compliance - 5880

Head of Security Governance, Risk & Compliance - 5880

Cambridge Full-Time 60400 - 75100 £ / year (est.) No home office possible
Go Premium
C

At a Glance

  • Tasks: Lead security governance, risk management, and compliance strategies across the organisation.
  • Company: Join Cambridge University Press & Assessment, a leading academic publisher and part of the University of Cambridge.
  • Benefits: Enjoy flexible working, 28 days leave, private medical insurance, and a discretionary bonus.
  • Why this job: Be part of a collaborative team driving security awareness and making impactful decisions.
  • Qualifications: Proven experience in security management, with relevant certifications and strong stakeholder skills required.
  • Other info: Hybrid working options available; applications reviewed on an ongoing basis.

The predicted salary is between 60400 - 75100 £ per year.

Job Title: Head of Security Governance, Risk & Compliance

Salary: £70,400 – £94,100

Location: Cambridge/Hybrid Minimum 2 days a week in the office

Contract: Permanent

The Head of Security GRC is a senior leadership role within the Security SMT, tasked with driving the organisation\’s security governance, risk, and compliance strategy. This position engages across all levels of the business, ensuring regulatory compliance, effective risk management, and robust assurance processes to support decision-making by the Senior Leadership Team.

You will deliver a robust Security Assurance Framework, oversee supplier assurance activities, and maintain relevant ISO and Cyber Essentials certifications. Additionally, you\’ll drive the implementation of security standards, policies, governance reporting, and audit programmes to ensure robust controls are in place. You\’ll play a critical role in enabling informed decision-making and promoting a culture of security awareness across the organisation.

We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge.

About the role

The position involves engaging at all organisational levels, managing security risks, ensuring regulatory compliance, and providing assurance on business practices to support informed decisions by the Senior Leadership Team and Security Board. Responsibilities include implementing and monitoring security standards, policies, AI governance, and audit programmes to ensure effective mitigations and controls. Additionally, the role entails designing and delivering the Security Assurance Framework, conducting supplier assurance activities and audits, leading the Awareness Community of Practice, and maintaining relevant ISO & Cyber Essentials certifications.

Key Accountabilities:

  • Develops security standards, policies, and guidelines and ensures compliance across Cambridge.
  • Leads the delivery of approved projects and investments to reduce risk and security exposure.
  • Proactively identifies new threats, risks, and trends; reports mitigation progress to the Security Board and SLT.
  • Collaborates with key stakeholders to create customer-centric security policies for products and services.
  • Coordinates audits, regulatory inquiries, and external vendor activities to align with industry standards.
  • Responsible for leading and managing the GRC team to achieve compliance and team success in the organisation.
  • Oversees vendor relationships to ensure protection of Cambridge global people and assets.
  • Aligns attack surface management (ASM) process with GRC objectives and provides updates on mitigation progress.
  • Integrates AI governance with relevant GRC frameworks to meet regulatory standards.
  • Manages certifications like ISO 27001, 42001, Cyber Essentials, and HMG Security Policy Framework.

About you

We are looking for a highly skilled and experienced professional with the following expertise:

  • Proven experience managing an Information Security Management System (ISMS), including ISO 27001 certification.
  • Strong working knowledge of security threats and proportionate mitigations, as well as supply chain security management systems.
  • A minimum of 3 years\’ experience in a senior governance or risk management role.
  • Active CRISC or ISO 27005 Risk Manager certification (or higher), with additional certifications such as ISO 27001/42001 Lead Auditor or Implementor being advantageous.
  • Demonstrated experience in strategic governance of security, managing security risks in line with ISO 27005, and implementing ISO 27001 compliant systems.
  • Expertise in auditing security controls for both internal operations and third parties.
  • Exceptional stakeholder management skills, with the ability to build relationships across all organisational levels.
  • Strong negotiation skills to influence decisions and achieve positive outcomes.
  • Experience leading and developing teams, both within the UK and regionally.

If you would like to know more about this opportunity and what will make you successful, please see the full job description attached to the bottom of this vacancy on our careers site.

Rewards and benefits

We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package, featuring family-friendly and planet-friendly benefits including:

  • 28 days annual leave plus bank holidays
  • Private medical and Permanent Health Insurance
  • Discretionary annual bonus
  • Group personal pension scheme
  • Life assurance up to 4 x annual salary
  • Green travel schemes

We are a hybrid working organisation, and we offer a range of flexible working options from day one. We expect most hybrid-working colleagues to spend 40-60% of their time at their dedicated office or location. We will also consider other work arrangements if you wish to work more flexibly or require adjustments due to a disability.

Ready to pursue your potential? Apply now.

We review applications on an ongoing basis, with a closing date for all applications being 27th July although we may close it earlier if suitable candidates are identified. Interviews are scheduled to take place shortly after it closes.

Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry.

University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for.

Why join us

Joining us is your opportunity to pursue potential. You\’ll belong to a collaborative team that\’s exploring new and better ways to serve students, teachers and researchers across the globe – for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration.

Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it\’s safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background.

We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.

#LI-SW1

#J-18808-Ljbffr

Head of Security Governance, Risk & Compliance - 5880 employer: Cambridge University Press

Cambridge University Press & Assessment is an exceptional employer, offering a dynamic work culture that prioritises collaboration and innovation. With a strong commitment to employee growth, we provide extensive professional development opportunities and a flexible rewards package, including generous annual leave and health benefits. Located in the vibrant city of Cambridge, our hybrid working model allows for a balanced work-life integration, making it an ideal place for those seeking meaningful and rewarding employment.
C

Contact Detail:

Cambridge University Press Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Head of Security Governance, Risk & Compliance - 5880

✨Tip Number 1

Familiarise yourself with the latest ISO standards and Cyber Essentials requirements. Understanding these frameworks will not only help you in interviews but also demonstrate your commitment to compliance and risk management.

✨Tip Number 2

Network with professionals in the security governance field, especially those who have experience in similar roles. Engaging with industry peers can provide insights into the role and may even lead to referrals.

✨Tip Number 3

Prepare to discuss specific examples of how you've managed security risks and compliance in previous roles. Highlighting your hands-on experience will show that you can effectively lead the GRC team.

✨Tip Number 4

Stay updated on current security threats and trends. Being knowledgeable about the latest developments in the field will allow you to speak confidently about proactive measures and strategies during your interview.

We think you need these skills to ace Head of Security Governance, Risk & Compliance - 5880

Information Security Management System (ISMS) expertise
ISO 27001 certification management
Risk management and governance experience
Strong knowledge of security threats and mitigations
Supply chain security management
CRISC or ISO 27005 Risk Manager certification
ISO 27001/42001 Lead Auditor or Implementor certifications
Auditing security controls for internal and third-party operations
Stakeholder management and relationship building
Negotiation skills for influencing decisions
Team leadership and development experience
Implementation of security standards and policies
Experience with Cyber Essentials and HMG Security Policy Framework
Ability to conduct audits and regulatory inquiries
Integration of AI governance with GRC frameworks

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in security governance, risk management, and compliance. Use keywords from the job description to demonstrate that you meet the specific requirements of the role.

Craft a Compelling Cover Letter: Write a cover letter that showcases your leadership skills and experience in managing an Information Security Management System. Explain how your background aligns with the responsibilities outlined in the job description.

Highlight Certifications: Clearly list any relevant certifications such as CRISC, ISO 27001, or ISO 27005 in your application. This will help demonstrate your qualifications and commitment to the field of security governance.

Showcase Stakeholder Management Skills: Provide examples in your application of how you've successfully managed relationships with stakeholders at various levels. This is crucial for the role, so make sure to highlight your negotiation and communication skills.

How to prepare for a job interview at Cambridge University Press

✨Understand the Security Landscape

Familiarise yourself with current security threats and trends relevant to the role. Be prepared to discuss how you would proactively identify and mitigate these risks within the organisation.

✨Showcase Your Leadership Skills

As a senior role, demonstrate your experience in leading teams and managing stakeholder relationships. Prepare examples of how you've successfully influenced decisions and driven compliance initiatives in previous positions.

✨Highlight Relevant Certifications

Make sure to mention any relevant certifications such as CRISC or ISO 27001. Discuss how these qualifications have equipped you to manage an Information Security Management System effectively.

✨Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving skills in real-world scenarios. Think about past experiences where you had to implement security standards or manage audits, and be ready to explain your thought process and outcomes.

Head of Security Governance, Risk & Compliance - 5880
Cambridge University Press
Location: Cambridge
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

C
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>