At a Glance
- Tasks: Lead information security risk and governance for a major UK portfolio.
- Company: Join DXC Technology, a leader in mission-critical IT services.
- Benefits: Flexible working, collaborative culture, and opportunities for professional growth.
- Other info: Engage with top government and defence stakeholders while promoting a strong security culture.
- Why this job: Shape the future of secure digital transformation at a national scale.
- Qualifications: Extensive leadership experience in information security within regulated environments.
The predicted salary is between 75000 - 100000 £ per year.
Location: United Kingdom (Hybrid / Flexible)
Security Clearance: Must be eligible for high-level UK security clearance
Overview
At DXC Technology, we deliver mission-critical IT services to some of the UK’s most secure and complex organisations across government, Defence, and regulated industries. We are looking for an exceptional Senior Information Risk Owner (SIRO) to lead information security risk across our UK business (~$1bn annual revenue). Reporting to the Group Operations Lead, this is a pivotal leadership role responsible for safeguarding DXC’s information assets, ensuring compliance with UK regulatory frameworks, and enabling secure growth across highly classified environments. This role will also act as a Security Control Officer, requiring a UK national with the ability to operate at the highest levels of trust with government, Defence, and international stakeholders.
Key Responsibilities
- Information Risk Leadership
- Own and oversee information security risk across DXC UK, aligned to global security strategy.
- Lead risk assessment and mitigation across government, Defence, and commercial portfolios.
- Provide independent challenge and strategic guidance on decisions impacting information risk.
- Regulatory & Stakeholder Engagement
- Act as a senior point of contact for customer SIROs, UK regulators and government agencies.
- Represent DXC’s security posture externally, building trust and maintaining compliance.
- Support business development activities, providing assurance on security and regulatory obligations.
- Defence Security & Classified Environments
- Overseeing Defence security frameworks, accreditations, and cleared systems.
- Managing risk reporting, incidents, and residual exposure.
- Liaising with national authorities and defence bodies.
- Sponsoring insider threat, FOCI risk, and security awareness initiatives.
- Governance & Compliance
- Lead the UK Security Risk & Governance function, including:
- Information security policy and assurance.
- Compliance and audit readiness.
- Vetting and personnel security programmes.
- Security awareness initiatives.
- Ensure compliance with GDPR, UK data legislation, and emerging AI regulations.
- Cyber Incident Leadership
- Act as the UK lead for major cyber incidents (e.g. ransomware, data breaches, supply chain attacks).
- Coordinate responses with regulators, law enforcement, and internal leadership.
- Third-Party & Supply Chain Risk
- Oversee third-party and supply chain security risks, ensuring UK-specific exposures are identified and mitigated.
- Collaboration & Culture
- Partner with CISO, Resilience, Protective Security, and Insider Threat teams.
- Promote a strong security-first culture across the UK business.
Skills & Experience
Essential
- Extensive senior leadership experience in information security risk within complex, regulated environments.
- Proven experience supporting UK government, defence, or NATO customers at high classification levels.
- Strong understanding of UK, EU, and US regulatory frameworks, including cyber and data legislation.
- Demonstrated ability to influence and engage executive stakeholders and regulators.
- Track record of leading multi-disciplinary security teams (cyber, personnel security, governance).
Highly Desirable
- Qualified UK solicitor (15+ years PQE) with cyber or data specialisation.
- Experience as a UK Director within a US-listed organisation.
- Deep expertise in security-cleared environments and personnel risk management.
Key Attributes
- Decisive & Responsive – Able to act quickly and effectively in high-pressure situations.
- Strategic Thinker – Anticipates emerging threats and aligns security with business priorities.
- Collaborative Leader – Builds strong cross-functional partnerships.
- People-Focused – Develops high-performing teams and supports succession planning.
- Outcome-Driven – Balances attention to detail with delivery of impactful results.
Why Join DXC?
- Lead information security for a critical national-scale portfolio.
- Engage at the highest levels with government, defence, and global stakeholders.
- Shape the future of secure digital transformation in the UK.
- Be part of a collaborative, purpose-driven organisation that values innovation, trust, and people.
If you’re ready to take on a strategic leadership role at the forefront of UK information security, we’d love to hear from you.
At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritises in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We’re committed to fostering an inclusive environment where everyone can thrive.
Recruitment fraud is a scheme in which fictitious job opportunities are offered to job seekers typically through online services, such as false websites, or through unsolicited emails claiming to be from the company. These emails may request recipients to provide personal information or to make payments as part of their illegitimate recruiting process. DXC does not make offers of employment via social media networks and DXC never asks for any money or payments from applicants at any point in the recruitment process, nor ask a job seeker to purchase IT or other equipment on our behalf. More information on employment scams is available here.
Director, UK Security Risk & Governance (SIRO) in London employer: DXC Technology
At DXC Technology, we pride ourselves on being a leading employer in the UK, offering a dynamic and collaborative work environment that prioritises innovation and employee wellbeing. As a Director in our Security Risk & Governance team, you will have the unique opportunity to engage with high-level government and defence stakeholders while shaping the future of secure digital transformation. We are committed to fostering an inclusive culture that supports professional growth and development, ensuring that our employees thrive in their careers.
StudySmarter Expert Advice🤫
We think this is how you could land Director, UK Security Risk & Governance (SIRO) in London
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, especially those who work at DXC or similar companies. A friendly chat can open doors and give you insights that might just land you an interview.
✨Tip Number 2
Prepare for the interview by researching the company’s recent projects and challenges. Show us that you’re not just another candidate; demonstrate your understanding of their mission-critical services and how you can contribute to their success.
✨Tip Number 3
Practice your pitch! Be ready to explain how your extensive experience aligns with the role of Director, UK Security Risk & Governance. We want to hear about your leadership style and how you’ve tackled complex security challenges in the past.
✨Tip Number 4
Don’t forget to follow up after your interview! A quick thank-you email can leave a lasting impression. It shows us that you’re genuinely interested in the position and appreciate the opportunity to connect.
We think you need these skills to ace Director, UK Security Risk & Governance (SIRO) in London
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in information security risk, especially in regulated environments. We want to see how your skills align with the role of SIRO at DXC!
Showcase Your Leadership Skills:As this is a senior role, it's crucial to demonstrate your leadership experience. Share examples of how you've led teams or projects in high-pressure situations, particularly in government or defence sectors.
Be Clear and Concise:When writing your application, keep it straightforward and to the point. Use clear language to convey your achievements and how they relate to the responsibilities outlined in the job description.
Apply Through Our Website:We encourage you to apply directly through our website for a smoother process. This way, we can ensure your application gets the attention it deserves and you can stay updated on your application status!
How to prepare for a job interview at DXC Technology
✨Know Your Stuff
Make sure you have a solid understanding of information security risk management, especially in regulated environments. Brush up on UK, EU, and US regulatory frameworks, as well as any recent developments in cyber legislation. This will help you speak confidently about how your experience aligns with the role.
✨Showcase Your Leadership Skills
As a Director, you'll need to demonstrate your ability to lead multi-disciplinary teams effectively. Prepare examples of how you've influenced stakeholders and navigated complex situations in previous roles. Highlight your strategic thinking and decisiveness in high-pressure scenarios.
✨Engage with Real Scenarios
Be ready to discuss real-world examples of how you've managed information security risks, particularly in government or defence contexts. Think about specific incidents you've handled, your approach to risk assessment, and how you ensured compliance with regulations.
✨Build Rapport
Remember, interviews are a two-way street. Engage with your interviewers by asking insightful questions about their security culture and challenges. This not only shows your interest but also helps you assess if the company is the right fit for you.