At a Glance
- Tasks: Lead regulatory assurance and cyber initiatives to shape the UK's data protection landscape.
- Company: Join the Information Commissioner’s Office, a key player in data rights regulation.
- Benefits: Enjoy competitive salary, flexible working, generous holiday, and health benefits.
- Other info: Be part of a diverse team committed to equality and inclusion.
- Why this job: Make a real impact on national data protection and cyber resilience.
- Qualifications: Senior-level experience in cyber or regulatory assurance is essential.
The predicted salary is between 119930 - 145590 £ per year.
Locations: Circle Square, Belfast, Cardiff, Edinburgh, London/Hybrid
Full time / Part time
Salary: £119,930 - £145,590, with potential for further progression to £171,248 with our pay progression scheme
End Date: August 17, 2026
Contracted to our Manchester, London, Edinburgh, Cardiff or Belfast office
Why work for the ICO?
- Pay progression scheme.
- Hybrid and flexible working options.
- 25 days paid holiday per year, plus privilege and public holidays.
- Flexi leave (up to 26 additional days leave per year).
- Pension (employer contribution around 28.9%).
- Online discount scheme to save money at major supermarkets, retailers, gyms, restaurants, insurance providers and many more.
- Health Cash Plan.
- Fantastic development opportunities to learn and progress.
Job Summary
Join the Information Commissioner’s Office at a pivotal moment, where rapid technological change and the growing importance of data are reshaping the UK’s economy and society. As Group Director for Regulatory Assurance and Cyber, you’ll take on a high-impact leadership role, steering the ICO’s approach to assurance and cyber regulation. You’ll drive forward a risk-led, outcome-focused supervisory model, ensuring the UK maintains strong, trusted data protection frameworks that support innovation and public confidence. From delivering major regulatory programmes to shaping the ICO’s response to new cyber legislation, you’ll lead expert teams to provide proactive assurance, targeted interventions and strategic oversight where it matters most. This is a unique opportunity to influence national regulatory direction, strengthen cyber resilience, and play a critical role in enabling a secure, data-driven future.
The Information Commissioner’s Office (ICO) is the independent regulator of information rights. In a data-driven world, we provide advice, guidance, and support to organisations enabling compliance with their obligations, as well as protecting individuals and their personal data. As an employer, we are passionate about making a positive difference to the lives and careers of our people, and we empower you to be curious, impactful, collaborative and respectful.
Job Description
Reporting to the Executive Director for Regulatory Risk and Innovation, the role provides focused leadership and capacity in a high‑risk, fast‑evolving regulatory area. You will work closely with Executive Directors and senior leaders across the organisation to ensure coherence between assurance, supervision, investigations and enforcement activity, and to support clear prioritisation and measurable regulatory impact. As a senior leader, you will be expected to make a significant contribution to the development and delivery of the ICO’s strategic plans, policies and initiatives. You will also promote and safeguard the good corporate reputation of the ICO, raise awareness of information rights and obligations and provide leadership to the organisation and its people.
Key Responsibilities
- Work collaboratively with senior leader colleagues to develop and deliver the ICO’s purpose and vision, role modelling our values at all times.
- Provide direct leadership and line management for the Director of Regulatory Assurance, Director of Cyber, and two PACE product roles, bringing together assurance, cyber and product capability under a single senior leadership role. You will be responsible for ensuring all staff within the directorates are clear about standards expected and are empowered to achieve them.
- Provide senior oversight of PACE product activity within scope, ensuring product delivery supports regulatory assurance and cyber priorities and is aligned to the ICO’s strategy and Better Regulatory Interventions approach.
- Lead delivery of the ICO’s regulatory responsibilities arising from the Cyber Security and Resilience Bill, ensuring readiness, capability and effective supervisory approaches are in place.
- Ensure strategic risks and opportunities in all areas of responsibility are managed effectively. This means agreeing clear risk appetites, ensuring all risks are clearly articulated and actively managed, and that all controls and mitigating actions are effective and proportionate.
- Overall budgetary and fiscal responsibility for Regulatory Assurance and Cyber functions, overseeing operational spend and leading on development of business cases where necessary.
- Embed a supervisory approach to regulation, focused on earlier engagement, prevention of harm and delivery of clear, measurable regulatory outcomes.
- Ensure assurance and cyber interventions are proportionate, evidence‑based and consistent with the ICO’s Better Regulatory Interventions approach.
- Work closely with Legal, Investigations and other regulatory functions to support effective escalation, enforcement decision‑making and end‑to‑end regulatory coherence.
- Contribute to organisational horizon‑scanning and risk assessment, identifying emerging threats, opportunities and trends relevant to cyber resilience and assurance.
- Establish and maintain effective internal and external relationships with government, public bodies, regulators, industry and other stakeholders to support delivery of regulatory objectives, regulatory coherence and effective risk management.
- Support the Executive Director for Regulatory Risk and Innovation in business planning, performance management and reporting on assurance and cyber activity.
- Engaging across the whole of the ICO, establishing close working relationships and taking responsibility for matrix management where necessary to ensure a connection across the organisation to achieve a successful and cohesive implementation of the relevant strategies.
- Ensure that the ICO values diversity in its workforce and demonstrates equality of opportunity in its treatment of staff, customers and in all aspects of its business.
- Seeking continuous improvement in all areas of responsibility and acting as a catalyst for efficiency, high performance, continuous improvement and innovation across the organisation.
- Play a significant role in the leadership of the ICO and all relevant initiatives, taking personal responsibility for ad hoc projects or tasks agreed with the CEO and Executive Team.
- Represent the ICO and personally advise the Executive Team wherever required.
Person specification
Essential Criteria Assessed At Application Stage
- Senior‑level experience demonstrating widely recognised expertise in cyber, regulatory assurance or closely related risk‑focused disciplines, gained in public, private or third‑sector settings.
- Strong track record of leading complex cyber‑related, regulatory or assurance activity and delivering high‑quality outcomes in high‑risk or fast‑moving contexts.
- Extensive experience of senior leadership and people management, including setting clear direction, motivating teams and sustaining delivery through change.
- Experience operating effectively in high‑profile, high‑risk environments with significant reputational, public trust or wider system implications.
- Substantial experience in senior representational and negotiating roles, building effective relationships with government, regulators, industry and other stakeholders to influence outcomes, manage risk and maintain public confidence.
Essential Criteria Assessed During Interview
- Strong understanding of the principles of good regulation and their practical application within assurance and supervisory contexts.
- Knowledge of cyber risk, resilience, assurance or related regulatory domains with the credibility to operate authoritatively at senior levels, or the demonstrable ability to develop and apply such expertise quickly.
- Ability to champion and role model equality, diversity and inclusion, demonstrating strong personal integrity and a commitment to the ICO’s values at both an organisational and team level.
- The ability to exercise sound judgement in ambiguous or controversial circumstances.
- Ability to lead cross‑functional and matrix working, influencing without line authority where required.
- Experience of embedding outcome‑focused, proportionate regulatory interventions and measuring their effectiveness.
- Good understanding of public sector governance, accountability and performance management.
- Commercially and politically aware, with an understanding of how cyber risk, technological change and system resilience impact regulatory decision‑making and public trust.
- Collaborative leadership style, with a commitment to empowering others and building high‑performing teams.
- Strong written, verbal and communications skills, directed in particular at negotiating with and influencing a wide range of stakeholders including public speaking and media.
- Resilient, adaptable and able to operate effectively under pressure.
Equality, diversity, and inclusion
The ICO is committed to promoting and enhancing equality, diversity, and inclusion. We are focused on developing a workforce that is representative of the communities we serve and together we are building an inclusive workplace where all of our colleagues have the opportunity to make a real difference. We are championing this through our Equality Diversity and Inclusion Board together with a number of staff networks. Read more about our commitment on our website.
Candidates with a disability who meet the minimum criteria for this vacancy will be invited to interview as part of the ICO’s commitment to the Disability Confident Scheme. As part of the ICO’s commitment to our EDI objectives and creating a workplace that represents the communities and societies we serve, we guarantee an interview to candidates who declare they identify as belonging from an ethnic minority background and who meet the minimum criteria for this vacancy.
Group Director – Regulatory Assurance and Cyber in Edinburgh employer: Information Commissioner’s Office
The ICO is an exceptional employer, offering a dynamic work environment with hybrid and flexible working options across multiple locations including Wilmslow, London, Edinburgh, Cardiff, and Belfast. Employees benefit from generous holiday allowances, a robust pension scheme, and extensive professional development opportunities, all while contributing to the vital mission of safeguarding information rights in the UK. With a strong commitment to equality, diversity, and inclusion, the ICO fosters a supportive culture where every team member can thrive and make a meaningful impact.
Contact Details:
Information Commissioner’s Office Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Group Director – Regulatory Assurance and Cyber in Edinburgh
✨Join Compliance Communities
Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!
✨Attend Industry Conferences
Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.
✨Leverage Your University Career Services
If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.
✨Showcase Your Knowledge Online
Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Information Commissioner’s Office looking for candidates who are engaged and informed.
We think you need these skills to ace Group Director – Regulatory Assurance and Cyber in Edinburgh
Some tips for your application 🫡
Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!
Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.
Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!
Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Information Commissioner’s Office. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!
How to prepare for a job interview at Information Commissioner’s Office
✨Master the Regulations
Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!
✨Show Your Analytical Skills
Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!
✨Know Your Tools
Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!
✨Align with Company Culture
Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Information Commissioner’s Office’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!