Information Security Governance, Risk and Assurance Lead in Swindon

Information Security Governance, Risk and Assurance Lead in Swindon

Swindon Full-Time 46743 - 46743 £ / year (est.) No working from home possible
Cyber Security training courses

At a Glance

  • Tasks: Lead information security governance, risk management, and assurance in a dynamic research environment.
  • Company: Join a pioneering organisation at the forefront of UK research and innovation.
  • Benefits: Enjoy competitive salary, generous leave, flexible working, and a strong pension scheme.
  • Other info: Collaborate with top professionals and enjoy excellent career development opportunities.
  • Why this job: Make a real impact by safeguarding vital data and systems in groundbreaking scientific research.
  • Qualifications: Experience in information security governance and risk management is essential.

The predicted salary is between 46743 - 46743 £ per year.

Salary: £46,743

Band: UKRI Band E

Contract Type: Open Ended – Permanent

Hours: Full-time (Compressed hours & flexible working patterns available)

Location: Keyworth, Nottingham or Polaris House, Swindon - Hybrid working available

Closing Date: Sunday 19th July 2026

Step into the world where cutting‑edge science meets robust information security. Protect the technology that powers groundbreaking discoveries and be part of the team that safeguards the future of Big Science. Here, you’ll collaborate with leading engineers, researchers, and technologists to tackle the most pressing security challenges in a fast‑paced, innovative environment. Every day offers you the chance to defend vital data and systems, ensuring that the pursuit of scientific excellence continues securely and seamlessly.

Discover the difference you can make when you bring your expertise in information security to an organisation at the forefront of global research – working alongside some of the brightest minds and most advanced facilities in the world.

Security

As a minimum, due to the nature of this role, candidates must be eligible for clearance in line with UK National vetting guidelines and willing to undertake the process. Please indicate eligibility in the written submission. Candidates not meeting this level of clearance will not be considered. The level of clearance required is security check.

About the role

The UKRI CIO Group plays a pivotal role in managing and optimising the organisations critical enterprise technical services that underpin and enable UKRI’s business capabilities. Within the group a team of Information Security Professionals support the delivery of modern, secure, resilient and scalable services across a larger federated team of Digital, Data and Technology professionals to deliver impact across the organisation and the wider UK research and innovation system.

Join us for this rare opportunity to apply your expertise in information security in a dynamic, fast‑paced security operational, risk, compliance and assurance role in an organisation at the heart of research and innovation in the UK. Working as part of a team of technical specialists, your broad remit is to drive the implementation of our ambitious information security roadmap and support the Information Security Governance and Risk Manager and Head of Information Security to mature our information security function. This Band E role focuses on strengthening governance, risk management and assurance across UKRI’s security operations, ensuring that information assets remain protected, risks are understood and mitigated, and security processes operate effectively across a complex federated environment.

Your responsibilities:

  • Operate and enhance UKRI’s security governance, risk and assurance framework, ensuring controls remain appropriate, effective and aligned to organisational risk.
  • Perform security risk assessments for systems, services, projects and suppliers, producing clear risk treatment recommendations.
  • Lead the coordination and delivery of assurance activities across operational security domains (e.g., SOC processes, vulnerability management, incident response, identity and access management).
  • Monitor operational security performance, control effectiveness and compliance against internal policies and external frameworks including NIST CSF, ISO 27001 and the Government Cyber Assessment Framework.
  • Manage and improve processes for evidence gathering, audit preparation, remediation planning and control validation.
  • Conduct gap analyses following audits, incidents or assessments, ensuring remediation actions are tracked and delivered.
  • Work closely with technology teams and service owners to integrate good governance and risk practices into operational workflows ("secure by design").
  • Provide specialist advice to operational teams on risk, compliance obligations, and best‑practice implementation.
  • Produce enterprise‑level assurance reporting, including metrics, dashboards and trend analysis to support senior decision‑making.

Personal Specification

The below criteria will be scored during Shortlisting (S), Interview (I) or both (S&I). Applicants will be able to demonstrate skills in line with the cyber security risk manager roles using the Government Security Profession career framework.

Essential

  • Experience in information security governance, risk management or security operations in a complex organisation. (S&I)
  • Proven ability to conduct security risk assessments and operational assurance reviews. (S&I)
  • Good knowledge of cyber security and information assurance frameworks (NIST CSF, ISO 27001, CAF). (S&I)
  • Experience supporting audits, compliance assessments or continuous monitoring activities. (S&I)
  • Ability to interpret complex technical and procedural information to provide clear recommendations. (I)
  • Strong analytical skills and experience producing meaningful risk and assurance reporting. (S&I)

Benefits

We recognise and value our employees as individuals and aim to provide a favourable pay and rewards package. We are committed to supporting employees' development and promote a culture of continuous learning. Below is a selection of benefits:

  • An outstanding defined benefit pension scheme
  • 30 days' annual leave in addition to 10.5 public and privilege days (full time equivalent)
  • Employee discounts and offers on retail and leisure activities
  • Employee assistance programme, providing confidential help and advice
  • Flexible working options
  • Plus many more benefits and wellbeing initiatives that enable our employees to have a great work life balance.

Information Security Governance, Risk and Assurance Lead in Swindon employer: Cyber Security training courses

As an AI Engineer at our Central London office, you will be part of a dynamic team dedicated to pioneering cutting-edge AI solutions that drive business growth and enhance engineering capabilities. We pride ourselves on fostering a collaborative work culture that encourages innovation and professional development, offering competitive salaries, performance bonuses, and the flexibility of a hybrid working model to ensure a healthy work-life balance.

Cyber Security training courses

Contact Details:

Cyber Security training courses Recruitment Team

We think you need these skills to ace Information Security Governance, Risk and Assurance Lead in Swindon

Information Security Governance
Risk Management
Security Operations
Security Risk Assessments
Operational Assurance Reviews
Cyber Security Frameworks (NIST CSF, ISO 27001, CAF)
Audit Support