At a Glance
- Tasks: Lead the management of Governance, Risk, Compliance in IT Security.
- Company: Join HS2 Ltd, the UK's innovative high-speed rail network.
- Benefits: Competitive salary, flexible benefits fund, and professional development opportunities.
- Other info: Inclusive culture with a focus on personal growth and safety.
- Why this job: Make a real impact on cybersecurity while shaping the future of transport.
- Qualifications: Experience in IT security governance and risk management required.
The predicted salary is between 63000 - 77000 £ per year.
Job Description
Base salary from £65,474pa.
Depending on skills and experience.
In addition, we offer flexible benefits fund of 20% which is paid on top base salary and is fully pensionable, as well as a range of competitive benefits - check them out in the Benefits section on our website.
HS2 Ltd endeavours to ensure everyone working for us and with us feels included, thrives and achieves their full potential.
In practice, this means we are positive and inclusive about making adjustments, providing flexible working, encouraging our staff networks to flourish and providing personal and professional development opportunities.
Job Purpose
The Principal IT Security Manager (GRC) is accountable for the effective management of the Governance, Risk, Compliance (GRC) within the Information & Cyber Security function.
This includes ensuring that Information & technology controls are appropriately tested and risk assessed to mitigate threats, and to monitor that standards and obligations are being appropriately adopted through all delivery activity.
This role is responsible for using and applying knowledge of business goals and security requirements to frame problems and set priorities for internal and external delivery teams.
About the Role
- Direct the development, implementation and maintaining organisation wide cybersecurity governance frameworks, defining and evolving the cyber governance operating model.
- Own the enterprise-wise Information & Cyber Security policy lifecycle, ensuring the regular review, approval, and publication of security policies.
- Defining, managing and maintaining security policies, standards, procedures and controls aligned with regulatory and legal requirements (e. g. the NCSC Cyber Assessment Framework, and Cabinet Office requirements.).
- Accountable for translating business goals and requirements into cyber governance requirements, and embedding these into third-party and internal delivery frameworks, balancing the trade-offs between business outcomes and security posture.
- Oversee the provision of security testing and assurance strategy and capability, including penetration testing, simulation exercises and continuous control validation.
- Own the information and cyber risk register, ensuring risks are identified, assessed, prioritized, and tracked through mitigation.
- Set the direction for enterprise-wide Information & Cyber Security risk assessment methodologies and ensure integration with corporate risk processes.
- Lead the provision of an Information & Cyber Security third-party risk management program, including vendor due diligence, onboarding assessments, and ongoing monitoring.
- Work with procurement, legal, and IT teams to ensure security clauses and risk requirements are embedded in supplier contracts.
- Maintain a risk profile for critical suppliers and support risk treatment or exit strategies where necessary.
- Ensure ongoing compliance with cybersecurity-related legal, regulatory, and contractual obligations.
- Manage responses to internal and external audits, including but not limited to GIAA, NAO, Internal Audit and UK Government returns such s Gov Assure.
- Track and report compliance status, gaps, and remediation progress.
- Provide executive-level reporting on risk metrics and key risk indicators (KRIs).
- Promote a strong culture of security awareness and risk ownership throughout the organization.
- Design and deliver GRC-related training and education programs to internal stakeholders.
- Champion cross-functional collaboration with Legal, HR, IT, and Finance to embed security best practices.
- Manage budget and resourcing requirements for the delivery of security testing activity.
- Own strategic supplier relationships and drive value/performance outcomes from third-party contracts.
About You
Skills
Security and Enterprise-wide Governance.
Defining, embedding and evolving enterprise Information & Cyber governance aligned to risk appetite and regulatory expectations.
Governance and assurance.
Ability to evolve and define governance and take responsibility for working with other stakeholders across HS2's wider governance structure.
Assure standards, guardrails and principles to effectively govern delivery.
Problem definition and shaping.
Ability to define security-related strategies and policies, providing guidance to others on working within a strategic context.
Stakeholder communication.
Confidence working with senior stakeholders, influencing decisions and providing clear, risk-based recommendations.
Including excellent written and verbal communication skills, including the ability to prepare board-level reports and briefings.
Team Management and Organisational directive.
Ability to lead multidisciplinary teams and influence change in matrixed or federated environments.
- Knowledge of governance, risk, and compliance's role with across Information & Cyber Security or Information Assurance in an Enterprise.
- Knowledge of Cyber Security Frameworks, methodologies, and best practice / guidance such as NCSC standards.
- Knowledge of common security testing methods (E. g., Penetration testing, breach & attack simulation tools etc.).
- Understanding of UK public sector security expectations including NIS Regulations, NCSC guidance, and Cabinet Office policy.
- Type of Experience
- Experience across industry frameworks and best practices (E. g., NCSC CAF, CIS CSC, etc.).
- Experience of risk management and delivery of audit remediation activities.
- Experience of partnering with supplier teams for managed services delivery of improvements.
- Experience designing and implementing secure systems, leading review where necessary of complex security issues.
- Experience of enabling and informing risk-based decisions.
- Experience dealing with the security implications of transformation and day-to-day product changes.
- Experience working with system architectures, displaying a strong understanding of the impact of vulnerabilities on varied systems.
We ask for a variety of detail in your online application, however we perform the first assessment of suitability for a role based solely on the information in your CV.
In a further development of our efforts to create a more diverse workforce, your CV will be anonymised and personal information will be removed during the first stage of the application review.
This removes bias from the process and makes it even more important that you attach an updated word version of your CV for each new application ensuring you include evidence directly related to the criteria in the job advert.
Watch this video on how we remove bias in the recruitment process: Removing bias in the recruitment process - You Tube.
Any applications received after the closing date will not be considered.
About Us
High Speed 2 (HS2 Ltd) will be the UK's new high speed rail network.
As well as improving capacity, the new scheme will shorten journey times between a number of Britain's major population centres, boost the economy and create thousands of jobs.
HS2 Ltd will create a skills legacy and develop a diverse range of talent.
We aim to a leader in EDI practice by creating a safe & inclusive working environment for all our staff - living our values of Safety, Respect, Integrity and Leadership.
In practice, this means we are positive and inclusive about making adjustments, providing flexible working, encouraging our staff networks to flourish and providing personal and professional development opportunities.
HS2 Ltd is also a safety-critical organisation.
Employees are required to ensure reasonable care of their own and others' health and safety by taking personal responsibility for working to our 'Safe at Heart' programme principles and following safe working procedures at all times.
HS2 Ltd endeavours to ensure everyone working for us and with us feels included, thrives and achieves their full potential.
#J-18808-Ljbffr
Principal IT Security Manager (GRC) in Birmingham employer: HS2 (High Speed Two)
HS2 Ltd is an exceptional employer, offering a dynamic work environment in London that fosters collaboration and inclusivity. With a strong focus on employee growth, we provide opportunities for professional development while ensuring a supportive culture that values every team member's contributions. Join us to be part of a transformative project that not only shapes the future of transport but also prioritises your career advancement and well-being.
StudySmarter Expert Advice🤫
We think this is how you could land Principal IT Security Manager (GRC) in Birmingham
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including HS2 (High Speed Two), love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through HS2 (High Speed Two)
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at HS2 (High Speed Two). Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Principal IT Security Manager (GRC) in Birmingham
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at HS2 (High Speed Two) insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to HS2 (High Speed Two) that you’re committed to staying ahead in the game.
How to prepare for a job interview at HS2 (High Speed Two)
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at HS2 (High Speed Two) to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at HS2 (High Speed Two).
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.