At a Glance
- Tasks: Lead security governance, risk management, and compliance strategies across the organisation.
- Company: Join Cambridge University Press & Assessment, a prestigious academic publisher linked to the University of Cambridge.
- Benefits: Enjoy a competitive salary, hybrid working options, and a dynamic work environment.
- Why this job: Make a real impact on security culture while collaborating with senior leaders in a respected institution.
- Qualifications: Minimum 2 years in a leadership role with expertise in security governance and compliance.
- Other info: This is a permanent position with opportunities for professional growth and development.
The predicted salary is between 70400 - 94100 £ per year.
Head of Security Governance, Risk & Compliance
Salary: £70,400 – £94,100
Location: Cambridge/Hybrid Minimum 2 days a week in the office
Contract: Permanent
TheHead of Security GRCis a senior leadership role within the Security SMT, tasked with driving the organisation\’s security governance, risk, and compliance strategy. This position engages across all levels of the business, ensuring regulatory compliance, effective risk management, and robust assurance processes to support decision-making by the Senior Leadership Team.
Youwill deliver a robust Security Assurance Framework, oversee supplier assurance activities, and maintain relevant ISO and Cyber Essentials certifications. Additionally, you\’ll drive the implementation of security standards, policies, governance reporting, and audit programmes to ensure robust controls are in place. You\’ll play a critical role in enabling informed decision-making and promoting a culture of security awareness across the organisation.
We areCambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge.
About the role
The position involves engaging atall organisational levels, managing security risks, ensuring regulatory compliance, and providing assurance on business practices to support informed decisions by the Senior Leadership Team and Security Board. Responsibilities include implementing and monitoring security standards, policies, AI governance, and audit programmes to ensure effective mitigations and controls. Additionally, the role entails designing and delivering the Security Assurance Framework, conducting supplier assurance activities and audits, leading the Awareness Community of Practice, and maintaining relevant ISO & Cyber Essentials certifications.
KeyAccountabilities:
- Develops security standards, policies, and guidelines and ensures compliance across Cambridge.
- Leads the delivery of approved projects and investments to reduce risk and security exposure.
- Proactively identifies new threats, risks, and trends; reports mitigation progress to the Security Board and SLT.
- Collaborates with key stakeholders to create customer-centric security policies for products and services.
- Coordinates audits, regulatory inquiries, and external vendor activities to align with industry standards.
- Responsible for leading and managing the GRC team to achieve compliance and team success in the organisation.
- Oversees vendor relationships to ensure protection of Cambridge global people and assets.
- Aligns attack surface management (ASM) process with GRC objectives and provides updates on mitigation progress.
- Integrates AI governance with relevant GRC frameworks to meet regulatory standards.
- Manages certifications like ISO 27001, 42001, Cyber Essentials, and HMG Security Policy Framework.
About you
We are looking for a highly skilled and experiencedprofessional with the following expertise:
- Proven experience managing an Information Security Management System (ISMS), including ISO 27001 certification.
- Strong working knowledge of security threats and proportionate mitigations, as well as supply chain security management systems.
- A minimum of 3 years\’ experience in a senior governance or risk management role.
- Active CRISC or ISO 27005 Risk Manager certification (or higher), with additional certifications such as ISO 27001/42001 Lead Auditor or Implementor being advantageous.
- Demonstrated experience in strategic governance of security, managing security risks in line with ISO 27005, and implementing ISO 27001 compliant systems.
- Expertise in auditing security controls for both internal operations and third parties.
- Exceptional stakeholder management skills, with the ability to build relationships across all organisational levels.
- Strong negotiation skills to influence decisions and achieve positive outcomes.
- Experience leading and developing teams, both within the UK and regionally.
If you would like to know more about thisopportunity and what will make you successful, please see the full job description attached to the bottom of this vacancy on our careers site.
Rewards and benefits
We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexiblerewards package , featuring family-friendly and planet-friendly benefits including:
- 28 days annual leave plus bank holidays
- Private medical and Permanent Health Insurance
- Discretionary annual bonus
- Group personal pension scheme
- Life assurance up to 4 x annual salary
- Green travel schemes
We are a hybrid working organisation, and we offer a range of flexible working options from day one. We expect most hybrid-working colleagues to spend 40-60% of their time at their dedicated office or location. We will also consider other work arrangements if you wish to work more flexibly or require adjustments due to a disability.
Ready to pursue your potential? Apply now.
We reviewapplications on an ongoing basis, with a closing date for all applications being 27th July although we may close it earlier if suitable candidates areidentified. Interviews are scheduled to take place shortly after it closes.
Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry.
University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for.
Why join us
Joining us isyour opportunity to pursue potential. You\’ll belong to a collaborative team that\’s exploring new and better ways to serve students, teachers and researchers across the globe – for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration.
Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it\’s safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identityand sexual identity), cultural, or social class/background.
We believe better outcomes come throughdiversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
#J-18808-Ljbffr
Head of Security Governance, Risk & Compliance employer: Cambridge University Press & Assessment
Contact Detail:
Cambridge University Press & Assessment Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Head of Security Governance, Risk & Compliance
✨Tip Number 1
Familiarise yourself with the latest security governance frameworks and compliance standards relevant to our industry. This knowledge will not only help you in interviews but also demonstrate your commitment to staying updated in a rapidly evolving field.
✨Tip Number 2
Network with professionals in the security governance, risk, and compliance space. Attend industry events or webinars where you can connect with others in similar roles, as personal recommendations can often give you an edge in the hiring process.
✨Tip Number 3
Prepare to discuss real-world scenarios where you've successfully managed security risks or implemented compliance measures. Having concrete examples ready will showcase your practical experience and problem-solving skills during discussions.
✨Tip Number 4
Research Cambridge University Press & Assessment thoroughly. Understanding our mission, values, and recent initiatives will allow you to tailor your conversations and show how your vision aligns with ours, making you a more attractive candidate.
We think you need these skills to ace Head of Security Governance, Risk & Compliance
Some tips for your application 🫡
Understand the Role: Take time to thoroughly read the job description for the Head of Security Governance, Risk & Compliance position. Understand the key responsibilities and required skills, as this will help you tailor your application effectively.
Highlight Relevant Experience: In your CV and cover letter, emphasise your experience in security governance, risk management, and compliance. Use specific examples that demonstrate your ability to drive security strategies and manage risks effectively.
Showcase Leadership Skills: Since this is a senior leadership role, make sure to highlight your leadership experience. Discuss how you've engaged with various levels of an organisation and led teams to achieve security objectives.
Tailor Your Application: Customise your CV and cover letter to reflect the values and mission of Cambridge University Press & Assessment. Show how your personal values align with their commitment to security and compliance, and express your enthusiasm for contributing to their goals.
How to prepare for a job interview at Cambridge University Press & Assessment
✨Understand the Security Landscape
Familiarise yourself with current security governance, risk, and compliance trends. Be prepared to discuss how these trends can impact the organisation and demonstrate your knowledge of relevant frameworks and certifications like ISO and Cyber Essentials.
✨Showcase Leadership Experience
As a senior leadership role, it's crucial to highlight your previous experience in leading teams and driving strategic initiatives. Prepare examples that showcase your ability to influence decision-making and promote a culture of security awareness within an organisation.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills in real-world scenarios. Think about past experiences where you successfully managed security risks or ensured compliance, and be ready to explain your thought process and the outcomes.
✨Engage with the Interviewers
Remember that interviews are a two-way street. Prepare insightful questions about the company's security strategy and how the role fits into their overall objectives. This shows your genuine interest in the position and helps you assess if the company aligns with your values.