At a Glance
- Tasks: Lead the governance, risk, and compliance for Information Security at Allianz UK.
- Company: Join Allianz, a top global insurance brand with a commitment to innovation.
- Benefits: Enjoy flexible working, competitive salary, and a range of perks tailored for you.
- Other info: Embrace a diverse workplace that values inclusion and offers career growth opportunities.
- Why this job: Make a real impact on security culture and risk management in a dynamic environment.
- Qualifications: Extensive experience in Information Security and risk management is essential.
The predicted salary is between 43200 - 72000 £ per year.
Reporting to the Chief Information Security Officer (CISO), you will lead the governance, risk, and compliance (GRC) function for Information Security across Allianz UK, including the supplier assurance team. This role ensures alignment with internal frameworks, regulatory requirements, and industry standards. Further, you will be pivotal in driving the security culture of Allianz and leading our outreach and Information Security risk agenda across our supplier ecosystem.
Key Accountabilities
- Governance & Strategy
- Define and execute the InfoSec governance strategy aligned to business objectives and corporate risk appetite.
- Lead the Governance annual self-assessment, ensuring alignment with Allianz Group expectations.
- Oversee the annual NIST, Cyber Essentials certification and PCI-DSS attestation processes.
- Ensure compliance with Allianz frameworks (AFRIT, AFRIS, AFIRM) and UK regulatory standards.
- Develop and maintain the InfoSec control framework, integrating with AZC and AZP change governance.
- Risk Management
- Own and manage Archer GRC platform activities, including risk identification, assessment, mitigation, and reporting.
- Maintain the InfoSec risk register and ensure timely resolution of actions by risk owners.
- Provide assurance that InfoSec risks are monitored and managed across operational and change environments.
- Engage with Board Risk Committee, Compliance, and Audit to ensure InfoSec risk management is aligned with enterprise governance.
- Supplier Assurance
- Oversee the information security assurance of third-party suppliers, ensuring alignment with internal policies and regulatory requirements.
- Maintain a supplier risk assessment framework, including onboarding, periodic reviews, and exit processes in line with Group requirements.
- Ensure suppliers meet contractual InfoSec obligations and provide evidence of compliance (e.g. certifications, assessments).
- Collaborate with Procurement, Legal, and Risk teams to manage supplier-related risks and remediation activities.
- Escalate key risks and issues to information security and OPSIT leadership as necessary.
- Reporting & Assurance
- Lead the production of Executive governance reporting and submissions to Allianz Group and local Stakeholders.
- Deliver regular Board-level reporting on information security posture, risk trends, and compliance status.
- Act as IRCS Risk Officer for InfoSec, supporting AZC and AZP risk committees with governance MI.
- Evaluate risk mitigation and audit response plans, escalating risks beyond appetite to senior leadership.
- Collaboration & Oversight
- Partner with the wider OpsIT function and the business to embed InfoSec controls across BAU and project activities.
- Ensure delivery of InfoSec quality, standards, and assurance functions with effective performance tracking.
- Monitor the effectiveness of InfoSec controls and escalate deficiencies to the CIO and senior leadership.
- Technical Skills
- Lead and oversee robust IS Governance & Risk frameworks based on industry standards within delivery methods and processes.
- Ability to produce reports, presentations and formal papers for senior stakeholders.
- Manage comprehensive security risk catalogue with clear ownership and tracking mechanisms.
- Enhance security controls within IT delivery methods and associated processes.
- Ensure quality assurance of security elements in change projects, collaborating with Change Directors.
- Partner with CIO to maintain comprehensive security control oversight across operational environments.
- Document, test, and remediate key security controls to maintain a secure technology environment.
- Track and escalate audit findings, ensuring timely remediation of security issues.
- Business-focused security mindset with strong customer orientation.
- Adaptability to evolving threat landscape.
- Strategic relationship management across technical and business stakeholders.
Experience
- Extensive relevant experience in Information Security and risk management.
- Strong track record of Group alignment and CXO committee exposure preferred.
- Business knowledge of the insurance sector preferred.
- Consulting experience or Customer facing sales experience preferred.
- Experience in using presentation tools to a high standard.
What We Will Offer You
- Recognised and rewarded for a job well done, we have a range of flexible benefits for you to choose from so you can pick a package that's perfect for you.
- We also offer flexible working options, global career opportunities across the wider Allianz Group, and fantastic career development and training.
- That's on top of enjoying all the benefits you'd expect from the world's number one insurance brand, including:
- Flexible buy/sell holiday options
- Hybrid working
- Annual performance related bonus
- Contributory pension scheme
- Development days
- A discount up to 50% on a range of insurance products including car, home and pet
- Retail discounts
- Volunteering days
Our Ways of Working
Do you need flexibility with the hours you work? Let us know as part of your application and if it's right for our customers, our business and for you, then we'll do everything we can to make it happen. Here at Allianz, we are signatories of the ABIs flexible working charter. We believe in supporting hybrid work patterns, which balance the needs of our customers, with your personal circumstances and our business requirements. Our aim with this is to help innovation, creativity, and you to thrive - Your work life balance is important to us.
Integrity, Fairness, Inclusion & Trust
At Allianz, we believe in fostering an inclusive workforce and are proud to be an equal opportunity employer. Our commitment to equal opportunities, gender equity, and balanced gender representation, is demonstrated by our numerous accreditations: EDGE certified for gender inclusion, Women in Finance Charter members, Disability Confident employer, Stonewall Diversity Champion, Business in the Community's Race at Work Charter signatories, and Armed Forces Covenant gold standard employer. We embrace neurodiversity and welcome applications from neurodivergent and disabled candidates, offering tailored adjustments to ensure your success. We encourage our employees to advocate for their needs, whether it's assistive technology, ergonomic equipment, mentoring, coaching, or flexible work arrangements.
Accessible Application for All
As part of the Disability Confident Scheme, we support candidates with disabilities or long-term health conditions through the Offer an Interview Scheme, for those meeting the essential skills for the role. Contact our Resourcing team to opt into this scheme or for assistance with your application, including larger text, hard copies, or spoken applications.
For any inquiries or to submit your application, please contact: Scott Burns
Closing date 20/03/26. We reserve the right to close the advert early if we reach enough applications. Join us - Let's Care for Tomorrow.
Head of Information Security - GRC (12 Month Secondment) in Guildford employer: Allianz
Allianz UK is an exceptional employer that prioritises employee well-being and professional growth, offering flexible working options and a comprehensive benefits package tailored to individual needs. With a strong commitment to inclusivity and diversity, employees are encouraged to thrive in a supportive environment that fosters innovation and creativity. The opportunity to work within a globally recognised insurance brand ensures meaningful contributions to the security landscape while enjoying significant career development opportunities.
StudySmarter Expert Advice🤫
We think this is how you could land Head of Information Security - GRC (12 Month Secondment) in Guildford
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, especially those who work at Allianz or similar companies. A friendly chat can open doors and give you insider info on the role.
✨Tip Number 2
Prepare for the interview by researching Allianz's values and recent projects. Show us that you’re not just another candidate; you’re genuinely interested in how you can contribute to their mission.
✨Tip Number 3
Practice common interview questions related to governance, risk, and compliance. We want to see how you think on your feet, so consider doing mock interviews with friends or mentors.
✨Tip Number 4
Don’t forget to follow up after your interview! A quick thank-you email can leave a lasting impression and shows us that you’re keen on the position. Plus, it keeps you on their radar!
We think you need these skills to ace Head of Information Security - GRC (12 Month Secondment) in Guildford
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in governance, risk, and compliance. We want to see how your skills align with the specific requirements of the Head of Information Security role.
Showcase Your Achievements:Don’t just list your responsibilities; share your successes! Use quantifiable results to demonstrate how you've made a difference in previous roles, especially in areas like risk management and compliance.
Be Clear and Concise:Keep your application straightforward and to the point. We appreciate clarity, so avoid jargon and ensure your key points stand out. This will help us quickly see why you’re a great fit for the team.
Apply Through Our Website:We encourage you to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super easy!
How to prepare for a job interview at Allianz
✨Know Your Governance Frameworks
Familiarise yourself with the specific governance frameworks mentioned in the job description, like NIST and Cyber Essentials. Be ready to discuss how you've applied these in previous roles and how they align with Allianz's objectives.
✨Showcase Risk Management Experience
Prepare examples of your experience with risk identification and mitigation. Highlight your familiarity with platforms like Archer GRC and how you've successfully managed InfoSec risks in past positions.
✨Engage with Supplier Assurance
Understand the importance of supplier assurance in the role. Be prepared to discuss how you’ve ensured compliance with third-party suppliers and any frameworks you've developed for risk assessment and management.
✨Communicate Effectively with Stakeholders
Practice articulating complex information security concepts in a way that resonates with non-technical stakeholders. Prepare to share examples of how you've produced executive reports or presentations for senior leadership.