At a Glance
- Tasks: Lead cyber security governance, risk management, and compliance initiatives across a global organisation.
- Company: Join a forward-thinking Group committed to world-class cyber resilience.
- Benefits: Competitive salary, professional development, and opportunities for career advancement.
- Other info: Be part of a transformative programme with significant investment in cyber capabilities.
- Why this job: Shape the future of cyber security in a dynamic and evolving digital landscape.
- Qualifications: 7+ years in GRC, strong knowledge of cyber frameworks, and excellent leadership skills.
The predicted salary is between 72000 - 108000 € per year.
The Group Cyber Security team is responsible for ensuring that cyber risk is managed appropriately across the Group. The cyber strategy has been updated, recognising that cyber security needs to be part of the Group's culture and DNA. The Group operates a highly federated business model, and the strategy has considered the most effective way to build improved cyber capabilities while supporting this operating model. This permanent role will play a key part in shaping and supporting the delivery of the transformation programme, before assuming responsibility for embedding, operating, and continually improving the new initiatives as they transition into business-as-usual.
The Head of Cyber Security Governance, Risk & Compliance (GRC) serves as the driving force behind the Group's vision for world-class cyber resilience and is accountable for defining and advancing the enterprise cyber risk and assurance strategy. This role champions a culture of proactive risk management, robust governance, and unwavering compliance, ensuring that the Group not only meets but sets the standard for information security across a complex, global business landscape.
Key Responsibilities:
- Governance
- Define and maintain the cyber security governance framework, policies, and standards.
- Lead the liaison with divisional GRC roles, supporting the development and maintenance of the GRC operating model and framework.
- Ensure alignment with the Cyber Standard and global regulatory requirements (e.g., NIS2, GDPR).
- Provide direction on cyber security tooling relating to governance and assurance objectives.
- Collaborate with the Technical Assurance team to define and implement metrics and reporting standards for divisions.
- Chair governance forums and provide regular reporting to senior leadership and audit committees.
- Plan, coordinate and facilitate Security Working Group (SWG) meetings.
- Assist in the preparation of board papers and materials for annual reporting and Group level risk management.
- Risk Management
- Develop and implement enterprise-wide cyber risk management processes.
- Lead risk quantification initiatives by implementing risk quantification methodologies and developing metrics to measure and communicate risk reduction.
- Provide assurance that cyber risks are identified, assessed, and mitigated across all divisions.
- Maintain and update risk registers, ensuring Group risks are accurately captured, assessed, and managed.
- Conduct and oversee risk assessments at Group level in support of all divisions and business units.
- Track and manage deviations from policy, including the documentation and approval of exceptions.
- Conduct horizon scanning for regulatory changes and emerging cyber security requirements, ensuring the risk landscape is proactively managed.
- Compliance & Assurance
- Build and lead the non-automated second line assurance capability to monitor compliance to the Group's cyber standard.
- Oversee readiness for internal audits and external regulatory reviews, liaising with internal audit and external bodies to support audit activities, address findings, and drive remediation.
- Report monthly on GRC and assurance activities to senior management and divisional stakeholders.
- Respond to ad-hoc reporting requests from divisions, business units, and senior management.
- Third Party Security
- Develop the strategy for third party cyber security.
- Manage cyber security third-party risk and assurance, at point of contract and through ongoing assurance.
- Deliver a demonstrable and measurable reduction in third party cyber security risk.
- Strategic Leadership
- Lead the Group Cyber Security GRC function, establishing a robust second line of defence and embedding risk-based decision-making.
- Provide strategic direction on GRC initiatives, ensuring continuous improvement and alignment with business objectives whilst supporting the delivery of the cyber transformation programme.
- Act as a trusted advisor to the CISO and senior stakeholders on governance and compliance matters.
- Influence organisational culture to embed security awareness and risk-based thinking.
- Work in partnership and collaborate across verticals with the GCS Leadership Team.
- Stakeholder Engagement
- Collaborate with divisional GRC functions, BISOs, legal, finance, and operational teams to ensure integrated risk management.
- Represent the Group in external forums and regulatory engagements.
- Build and maintain trusted relationships with senior stakeholders, demonstrating a personable and collaborative approach.
- Ensure positive engagement and communication with all internal and external stakeholders.
Experience, Knowledge, Skills & Attributes
Essential
- 7+ years experience in governance, risk, and compliance within a large, complex organisation.
- Strong knowledge of cyber security frameworks (ISO 27001, NIST, CIS Controls).
- Expertise in regulatory compliance (GDPR, NIS2, SOX).
- Excellent leadership, communication, and influencing skills.
- Professional certifications such as CISSP, CISM, CRISC.
- Proven experience developing and implementing enterprise-wide cyber risk management processes.
- Excellent collaboration skills with cross-functional teams.
- Strong relationship-building and communication skills, with a personable and credible approach.
Desirable
- Experience in a federated business model.
- Familiarity with risk quantification tools and methodologies.
- Ability to drive cultural change and embed security awareness.
- Experience building a strong relationship with internal audit.
- Experience implementing an effective third party security risk management service.
Head of Cyber Security Governance, Risk and Compliance in London employer: Information Security Solutions
Join a forward-thinking organisation that prioritises cyber security as a core aspect of its culture and operations. As the Head of Cyber Security Governance, Risk and Compliance, you will be part of a dynamic team dedicated to shaping a world-class cyber resilience strategy, with ample opportunities for professional growth and development in a supportive environment. Our commitment to innovation and collaboration ensures that you will play a pivotal role in driving meaningful change while enjoying a diverse and inclusive workplace.
Contact Detail:
Information Security Solutions Recruiting Team
StudySmarter Expert Advice🤫
We think this is how you could land Head of Cyber Security Governance, Risk and Compliance in London
✨Tip Number 1
Network like a pro! Get out there and connect with people in the cyber security field. Attend industry events, webinars, or local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your expertise! Create a personal blog or LinkedIn posts discussing current trends in cyber security governance, risk, and compliance. This not only showcases your knowledge but also helps you stand out to potential employers.
✨Tip Number 3
Prepare for interviews by brushing up on common questions related to GRC. Think about how your experience aligns with the role's responsibilities. Practising your responses will help you feel more confident and articulate during the actual interview.
✨Tip Number 4
Don’t forget to apply through our website! We’re always looking for passionate individuals to join our team. Make sure to tailor your application to highlight how you can contribute to our cyber security strategy and culture.
We think you need these skills to ace Head of Cyber Security Governance, Risk and Compliance in London
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Head of Cyber Security Governance, Risk and Compliance role. Highlight your experience in governance, risk, and compliance, and don’t forget to mention any relevant certifications like CISSP or CISM.
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re passionate about cyber security and how your skills align with our vision for world-class cyber resilience. Keep it engaging and personal!
Showcase Your Leadership Skills:Since this role involves strategic leadership, make sure to highlight your experience in leading teams and driving cultural change. Share specific examples of how you've influenced risk management practices in previous roles.
Apply Through Our Website:We encourage you to apply through our website for a smoother application process. It’s the best way for us to receive your application and ensure it gets the attention it deserves!
How to prepare for a job interview at Information Security Solutions
✨Know Your Cyber Security Frameworks
Make sure you’re well-versed in key cyber security frameworks like ISO 27001, NIST, and CIS Controls. Be ready to discuss how you've applied these in previous roles, especially in governance, risk, and compliance.
✨Showcase Your Leadership Skills
As a Head of GRC, you'll need to demonstrate strong leadership. Prepare examples of how you've led teams or initiatives in the past, particularly in complex organisations. Highlight your ability to influence and engage stakeholders at all levels.
✨Understand Regulatory Compliance Inside Out
Brush up on your knowledge of GDPR, NIS2, and SOX regulations. Be prepared to discuss how you've ensured compliance in previous roles and how you would approach compliance challenges in this new position.
✨Prepare for Scenario-Based Questions
Expect scenario-based questions that assess your problem-solving skills in real-world situations. Think about potential risks and compliance issues the Group might face and how you would address them. This will show your proactive risk management mindset.