At a Glance
- Tasks: Lead IT security compliance and GRC strategy for a FTSE 100 organisation.
- Company: Join a leading company focused on security, compliance, and risk maturity.
- Benefits: Competitive salary, senior leadership role, and influence in a dynamic environment.
- Other info: Opportunity for strategic ownership and career growth in a collaborative setting.
- Why this job: Make a tangible impact on security culture and compliance across a complex enterprise.
- Qualifications: Significant experience in IT security and strong understanding of global regulations.
The predicted salary is between 90000 - 110000 £ per year.
I've partnered with a FTSE 100 organisation in their search for a Head of Cyber (GRC). This is a brand new role, and it plays a big part of their continued focus on security, compliance, and risk maturity. This is a senior role reporting directly to the CIO, with accountability for regulatory compliance, audit readiness, and embedding a strong security and risk culture across the organisation.
The role involves taking ownership of IT security compliance and GRC strategy, ensuring alignment with business objectives and global regulatory requirements. Key responsibilities include:
- Defining and leading the enterprise IT GRC strategy, aligned to ISO 27001 and wider regulatory frameworks
- Overseeing IT risk management across systems, operations, and third parties
- Ensuring compliance with GDPR, SOX, NIS2, ISO 27001 and managing internal/external audits
- Developing and maintaining security policies, procedures, tools, and processes
- Driving risk assessments across internal environments and the supply chain
- Promoting a strong culture of GRC awareness through training and stakeholder engagement
- Providing clear reporting to senior leadership and the board
- Leading and developing a team of direct reports
- Supporting critical incident and response activities when required
What we're looking for:
- Significant experience in IT security, governance, risk and compliance, including senior leadership exposure
- Strong understanding of global regulatory requirements and industry standards (GDPR, ISO 27001, NIST, etc.)
- Experience operating in large, complex or highly regulated environments
- Excellent stakeholder management and communication skills
- Ability to balance strategic leadership with operational execution
Location: West Midlands (3 days a week)
If you’re a GRC leader looking to make a tangible impact across a complex enterprise environment, please reach out to me with your CV.
We’re Hiring: Head of Information Security employer: James Adams
At James Adams, we pride ourselves on being an excellent employer, offering a vibrant work culture that fosters collaboration and innovation in Worcester. Our commitment to employee growth is evident through continuous training opportunities and a supportive environment that encourages professional development. Join us to be part of a forward-thinking team dedicated to enhancing security governance while enjoying the unique advantages of working in a dynamic and engaging location.