At a Glance
- Tasks: Lead the governance, risk, and compliance function for Information Security at Allianz UK.
- Company: Join Allianz UK, a leader in insurance with a commitment to inclusion and diversity.
- Benefits: Enjoy flexible working, competitive salary, and a range of benefits tailored for you.
- Other info: We embrace neurodiversity and offer tailored adjustments for all candidates.
- Why this job: Make a real impact in InfoSec while developing your career in a supportive environment.
- Qualifications: Extensive experience in Information Security and risk management is essential.
The predicted salary is between 48000 - 72000 € per year.
Reporting to the Chief Information Security Officer (CISO), you will lead the governance, risk, and compliance (GRC) function for Information Security across Allianz UK, including the supplier assurance team. This role ensures alignment with internal frameworks, regulatory requirements, and industry standards.
Key Accountabilities
- Governance & Strategy
- Define and execute the InfoSec governance strategy aligned to business objectives and corporate risk appetite.
- Lead the Governance annual self‑assessment, ensuring alignment with Allianz Group expectations.
- Oversee the annual NIST, Cyber Essentials certification and PCI‑DSS attestation processes.
- Ensure compliance with Allianz frameworks (AFRIT, AFRIS, AFIRM) and UK regulatory standards.
- Develop and maintain the InfoSec control framework, integrating with AZC and AZP change governance.
- Risk Management
- Own and manage Archer GRC platform activities, including risk identification, assessment, mitigation, and reporting.
- Maintain the InfoSec risk register and ensure timely resolution of actions by risk owners.
- Provide assurance that InfoSec risks are monitored and managed across operational and change environments.
- Engage with Board Risk Committee, Compliance, and Audit to ensure InfoSec risk management is aligned with enterprise governance.
- Supplier Assurance
- Oversee the information security assurance of third‑party suppliers, ensuring alignment with internal policies and regulatory requirements.
- Maintain a supplier risk assessment framework, including onboarding, periodic reviews, and exit processes in line with Group requirements.
- Ensure suppliers meet contractual InfoSec obligations and provide evidence of compliance (e.g., certifications, assessments).
- Collaborate with Procurement, Legal, and Risk teams to manage supplier‑related risks and remediation activities.
- Escalate key risks and issues to information security and OPSIT leadership as necessary.
- Reporting & Assurance
- Lead the production of executive governance reporting and submissions to Allianz Group and local stakeholders.
- Deliver regular board‑level reporting on information security posture, risk trends, and compliance status.
- Act as IRCS Risk Officer for InfoSec, supporting AZC and AZP risk committees with governance MI.
- Evaluate risk mitigation and audit response plans, escalating risks beyond appetite to senior leadership.
- Collaboration & Oversight
- Partner with the wider OpsIT function and the business to embed InfoSec controls across BAU and project activities.
- Ensure delivery of InfoSec quality, standards, and assurance functions with effective performance tracking.
- Monitor the effectiveness of InfoSec controls and elevate deficiencies to the CIO and senior leadership.
- Technical Skills
- Lead and oversee robust IS Governance & Risk frameworks based on industry standards within delivery methods and processes.
- Ability to produce reports, presentations and formal papers for senior stakeholders.
- Manage comprehensive security risk catalogue with clear ownership and tracking mechanisms.
- Enhance security controls within IT delivery methods and associated processes.
- Ensure quality assurance of security elements in change projects, collaborating with Change Directors.
- Partner with CIO to maintain comprehensive security control oversight across operational environments.
- Document, test, and remediate key security controls to maintain a secure technology environment.
- Track and elevate audit findings, ensuring timely remediation of security issues.
- Business‑focused security mindset with strong customer orientation.
- Adaptability to evolving threat landscape.
- Strategic relationship management across technical and business stakeholders.
- Experience
- Extensive relevant experience in Information Security and risk management.
- Strong track record of Group alignment and CXO committee exposure preferred.
- Business knowledge of the insurance sector preferred.
- Consulting experience or customer‑facing sales experience preferred.
- Experience in using presentation tools to a high standard.
What We Will Offer You
- Recognised and rewarded for a job well done, we have a range of flexible benefits for you to choose from – so you can pick a package that’s perfect for you.
- We also offer flexible working options, global career opportunities across the wider Allianz Group, and fantastic career development and training.
- Flexible buy/sell holiday options
- Hybrid working
- Annual performance‑related bonus
- Contributory pension scheme
- Development days
- A discount up to 50% on a range of insurance products including car, home and pet
- Retail discounts
- Volunteering days
Integrity, Fairness, Inclusion & Trust
At Allianz, we believe in fostering an inclusive workforce and are proud to be an equal‐opportunity employer. Our commitment to equal opportunities, gender equity, and balanced gender representation is demonstrated by our numerous accreditations: EDGE certified for gender inclusion, Women in Finance Charter members, Disability Confident employer, Stonewall Diversity Champion, Business in the Community’s Race at Work Charter signatories, and Armed Forces Covenant gold standard employer. We embrace neurodiversity and welcome applications from neurodivergent and disabled candidates, offering tailored adjustments to ensure your success. We encourage our employees to advocate for their needs, whether it’s assistive technology, ergonomic equipment, mentoring, coaching, or flexible work arrangements.
Accessible Application for All
As part of the Disability Confident Scheme, we support candidates with disabilities or long‑term health conditions through the Offer an Interview Scheme, for those meeting the essential skills for the role. Contact our Resourcing team to opt into this scheme or for assistance with your application, including larger text, hard copies, or spoken applications.
Closing date 19/01/2026. We reserve the right to close the advert early if we reach enough applications.
Head of Information Security - GRC employer: Allianz UK
Allianz UK is an exceptional employer that prioritises employee well-being and professional growth, offering a flexible benefits package tailored to individual needs. With a strong commitment to inclusivity and diversity, employees can thrive in a supportive work culture while enjoying opportunities for global career advancement within the Allianz Group. The hybrid working model and focus on integrity, fairness, and trust make Allianz UK a rewarding place to build a meaningful career in Information Security.
StudySmarter Expert Advice🤫
We think this is how you could land Head of Information Security - GRC
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, especially those who work at Allianz or similar companies. A friendly chat can sometimes lead to insider info about job openings that aren't even advertised yet.
✨Tip Number 2
Prepare for interviews by researching the company culture and values. Allianz is all about integrity and inclusion, so be ready to discuss how your experience aligns with these principles. Show them you’re not just a fit for the role, but for the team too!
✨Tip Number 3
Practice makes perfect! Conduct mock interviews with friends or mentors to refine your answers. Focus on articulating your experience in governance, risk management, and compliance clearly and confidently.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re genuinely interested in joining Allianz and being part of their mission.
We think you need these skills to ace Head of Information Security - GRC
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in governance, risk, and compliance. We want to see how your skills align with the specific requirements of the Head of Information Security role.
Showcase Your Achievements:Don’t just list your responsibilities; share your successes! Use metrics and examples to demonstrate how you've effectively managed InfoSec risks or led successful compliance initiatives in the past.
Be Clear and Concise:Keep your application straightforward and to the point. We appreciate clarity, so avoid jargon and ensure your key points stand out. This will help us quickly see why you’re a great fit for the role.
Apply Through Our Website:We encourage you to submit your application directly through our website. It’s the best way to ensure it gets into the right hands and helps us keep track of all applications efficiently.
How to prepare for a job interview at Allianz UK
✨Know Your GRC Inside Out
Make sure you’re well-versed in governance, risk, and compliance frameworks relevant to the role. Brush up on NIST, Cyber Essentials, and PCI-DSS standards, as these will likely come up during your interview. Being able to discuss how you've applied these in past roles will show your expertise.
✨Showcase Your Leadership Skills
As a Head of Information Security, you'll need to demonstrate strong leadership capabilities. Prepare examples of how you've led teams or projects, particularly in risk management or compliance. Highlight your experience in engaging with senior stakeholders and how you’ve influenced decision-making.
✨Prepare for Scenario-Based Questions
Expect scenario-based questions that assess your problem-solving skills in real-world situations. Think about challenges you've faced in previous roles related to InfoSec governance or supplier assurance, and be ready to explain how you tackled them effectively.
✨Understand Allianz's Culture and Values
Familiarise yourself with Allianz’s commitment to integrity, fairness, and inclusion. Be prepared to discuss how your values align with theirs and how you can contribute to fostering an inclusive workplace. This will show that you’re not just a fit for the role, but also for the company culture.