At a Glance
- Tasks: Lead security governance, risk, and compliance initiatives to enhance AVEVA's security framework.
- Company: AVEVA is a global leader in industrial software, driving digital transformation and sustainability.
- Benefits: Enjoy flexible benefits, 28 days annual leave, private medical insurance, and hybrid working options.
- Why this job: Join a diverse team making a real impact in cybersecurity and digital transformation.
- Qualifications: 7+ years in security governance with strong communication and problem-solving skills required.
- Other info: This is a 1-year fixed-term role based in Cambridge or London.
The predicted salary is between 48000 - 84000 £ per year.
AVEVA is a global leader in industrial software, driving digital transformation and sustainability. By connecting the power of information and artificial intelligence with human insight, AVEVA enables teams to use their data to unlock new value. We call this Performance Intelligence.
The Principal Specialist, Security GRC is a 1-year fixed-term employee position, critical role in shaping and standing-up AVEVA’s 2nd Line of Defence Security Governance, Risk and Compliance capabilities and services. This role will be responsible for providing insightful knowledge and actionable recommendations to achieve AVEVA’s target operating model for security GRC and increase the maturity of existing processes and systems.
The post holder will be expected to quickly integrate into the team, proactively engage with stakeholders across the business, from technical SMEs to business leadership. They will need to work independently and be able to prioritise their time across multiple projects and engagements.
Key responsibilities
- Implementation of Security Policy & Standards: Provide subject matter expert knowledge and support on developing policy, standards, and exemption services to enable controls and supporting control practices to be embedded and optimised across the organisation.
- Implementation of Security Risk Management & Assurance: Provide subject matter expert knowledge on developing security risk management and risk assurance services that enable effective, and data-driven risk management and reporting across operations.
- Implementation of Security Control Systems: Provide subject matter expert knowledge to business stakeholders to enable adoption, adaption, and optimisation of security controls across the organisation.
- Implementation of Supply Chain Security Risk Management: Provide subject matter expert knowledge to build and optimise the supply chain security risk management service to enable effective management of supplier security risks across the organisation.
- Implementation of Enterprise GRC Platform: Provide subject matter expert knowledge and support on the design, implementation and successful launch of an Enterprise GRC platform focused on security requirements.
- Stakeholder Engagement: Build and maintain trusted relationships with stakeholders to embed security risk practices into operational activities.
Essential requirements
- Experience: Preferable 7+ years relevant work experience in security governance, risk, and compliance with at least 3 years of working as a senior expert or manager of a significant department.
- Governance: Significant experience in developing, implementing, and optimising security policies, standards, and control-sets.
- Risk Management and Assurance: Extensive experience of understanding using threat, security control performance and business operations to independently assess residual security risk position.
- Regulatory Compliance: Significant experience of working within a regulated environment and advising others on the principal requirements of major legislation and regulations relevant to security.
Desired skills
- Organisational Skills: Highly skilled in managing multiple tasks within set deadlines whilst managing expectations of invested parties.
- Communication Skills: Excellent verbal and written communication skills, with the ability to convey complex information clearly and concisely to diverse audiences.
- Decision making: Highly skilled in tactical decision-making with organisational impact.
- Problem-solving: Able to address day-to-day challenges quickly with a focus on operational solutions.
Our Digital Security team is responsible for protecting AVEVA’s digital assets and keeping the company’s data and IP secure. We’re also playing a critical role in AVEVA’s move to the cloud. If you’re a collaborative problem solver that’s passionate about cybersecurity, you’ll find fulfilment and opportunity in our team.
UK Benefits include: Flexible benefits fund, emergency leave days, adoption leave, 28 days annual leave (plus bank holidays), pension, life cover, private medical insurance, parental leave, education assistance program.
Hybrid working: By default, employees are expected to be in their local AVEVA office three days a week, but some positions are fully office-based.
Hiring process: Interested? Great! Get started by submitting your cover letter and CV through our application portal.
AVEVA is committed to recruiting and retaining people with disabilities. Please let us know in advance if you need reasonable support during your application process.
AVEVA requires all successful applicants to undergo and pass a drug screening and comprehensive background check before they start employment.
AVEVA is an Equal Opportunity Employer. We are committed to being an exemplary employer with an inclusive culture, developing a workplace environment where all our employees are treated with dignity and respect.
Principal Specialist, Security GRC (1-year Fixed Term) employer: AVEVA Denmark
Contact Detail:
AVEVA Denmark Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Principal Specialist, Security GRC (1-year Fixed Term)
✨Tip Number 1
Familiarise yourself with AVEVA's core values and their approach to sustainability and digital transformation. Understanding these aspects will help you align your responses during interviews and demonstrate that you're a good cultural fit.
✨Tip Number 2
Network with current or former employees of AVEVA, especially those in security governance, risk, and compliance roles. They can provide valuable insights into the company culture and expectations for the Principal Specialist position.
✨Tip Number 3
Stay updated on the latest trends and regulations in security governance, risk, and compliance, particularly those relevant to software publishing. This knowledge will not only prepare you for potential interview questions but also show your commitment to the field.
✨Tip Number 4
Prepare to discuss specific examples from your past experience where you've successfully implemented security policies or managed risks. Tailoring your examples to reflect the responsibilities outlined in the job description will make you stand out as a candidate.
We think you need these skills to ace Principal Specialist, Security GRC (1-year Fixed Term)
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in security governance, risk, and compliance. Focus on your achievements in similar roles, especially those that align with the responsibilities outlined in the job description.
Craft a Compelling Cover Letter: Your cover letter should not only express your interest in the role but also demonstrate your understanding of AVEVA's mission and values. Mention specific experiences that showcase your expertise in security policy implementation and stakeholder engagement.
Highlight Relevant Skills: In both your CV and cover letter, emphasise your organisational skills, communication abilities, and problem-solving capabilities. These are crucial for the Principal Specialist role and will help you stand out.
Proofread Your Application: Before submitting, carefully proofread your CV and cover letter for any spelling or grammatical errors. A polished application reflects your attention to detail, which is essential for a role focused on security and compliance.
How to prepare for a job interview at AVEVA Denmark
✨Understand the Role
Make sure you have a solid grasp of the Principal Specialist, Security GRC role. Familiarise yourself with AVEVA's security governance, risk, and compliance frameworks, as well as their specific policies and standards. This will help you demonstrate your knowledge and show how your experience aligns with their needs.
✨Showcase Relevant Experience
Prepare to discuss your past experiences in security governance, risk management, and compliance. Highlight specific projects where you've implemented security policies or optimised risk management processes. Use concrete examples to illustrate your expertise and how it can benefit AVEVA.
✨Engage with Stakeholders
Since the role involves engaging with various stakeholders, be ready to discuss how you've built relationships in previous roles. Share examples of how you've communicated complex information to both technical and non-technical audiences, showcasing your strong communication skills.
✨Demonstrate Problem-Solving Skills
Prepare to discuss how you've tackled challenges in your previous roles, especially those related to security risks and compliance. Be ready to break down complex problems into manageable solutions, demonstrating your ability to think critically and act decisively.