Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) in Leatherhead

Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) in Leatherhead

Leatherhead Full-Time 50000 - 57186 £ / year (est.) Home office (partial)
KBR

At a Glance

  • Tasks: Lead cybersecurity governance and risk management across the UK, ensuring data protection and compliance.
  • Company: Join KBR, a forward-thinking company dedicated to innovation and security.
  • Benefits: Enjoy hybrid working, competitive salary, and a culture focused on growth and safety.
  • Other info: Be part of a People First company that values diversity and inclusion.
  • Why this job: Make a real impact in cybersecurity while collaborating with top professionals in the field.
  • Qualifications: Bachelor's degree in Cybersecurity or related field; leadership experience in complex environments required.

The predicted salary is between 50000 - 57186 £ per year.

KBR is seeking a Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) to lead cybersecurity governance, risk management, information assurance, and data protection activities across the United Kingdom. As the senior information security representative for UK operations, this role is responsible for driving the implementation of security policies, standards, and controls while overseeing accreditation, compliance, and assurance activities. Working closely with business, technology, and security leaders, the successful candidate will identify, assess, and mitigate cyber risks across the enterprise. This position provides strategic security leadership, ensures compliance with regulatory and contractual requirements, and delivers executive-level reporting on security risks, control effectiveness, and the organisation's overall security posture.

What You’ll Be Doing:

  • Lead the implementation and oversight of enterprise information security, data protection, and privacy policies across the business.
  • Manage security governance processes and ensure alignment with Office of the CISO policies, standards, and procedures.
  • Plan and manage network certification, accreditation, and compliance activities in coordination with the Office of the CISO, government customers, auditors, certification bodies, and third-party assessors.
  • Coordinate and support penetration testing, security assessments, and related assurance activities.
  • Assist in the management and coordination of regional regulatory compliance and data privacy initiatives.
  • Collaborate with Security Operations and IT teams to ensure appropriate governance and protection of OFFICIAL-SENSITIVE and classified information.
  • Assess security threats and risks and develop appropriate mitigation strategies.
  • Serve as a cybersecurity subject matter expert, providing guidance on security architecture, governance, and risk management.
  • Provide consulting and security oversight for current and future projects involving network, infrastructure, and enterprise security architecture.
  • Support the development and delivery of security awareness training, data protection education, and best practice guidance.
  • Author, review, and maintain information security policies, standards, procedures, and supporting documentation.
  • Provide security representation and guidance for Architecture Review Boards, Change Control Boards, and project governance forums.
  • Respond to customer security inquiries and support security-related requirements for business programs and projects.
  • Support formal investigations involving security incidents, policy violations, and misconduct in coordination with Human Resources, Corporate Security, Finance, Business Integrity, and Office of the CISO teams.
  • Participate in cybersecurity incident response activities and support incident investigations as required.
  • Manage and respond to Data Privacy and Information Security support requests across the business.
  • Provide security advice, guidance, and risk-based recommendations to management, stakeholders, and customers.
  • Participate in Privacy Impact Assessments and support the review and development of data protection requirements and contractual language.
  • Review and approve information security governance activities including risk assessments, security categorization, waivers, exceptions, and variances in accordance with CISO directives.
  • Provide regular reporting and executive-level briefings regarding security risks, compliance posture, and the effectiveness of security controls.

Qualifications & Experience:

  • Essential: Bachelor's degree in Cybersecurity, Information Security, Information Assurance, Computer Science, Information Technology, or a related field; additional relevant experience may be considered in lieu of a degree.
  • Experience in Information Security, Information Assurance, Cybersecurity, or a related discipline, including leadership of security initiatives within complex enterprise environments.
  • Experience in cybersecurity governance, risk management, compliance, accreditation, and information security programme oversight.
  • Knowledge of information security frameworks and standards, including ISO 27001, NIST, and related governance controls.
  • Experience working with UK government, defence, or other highly regulated environments.
  • Preferred: Master's degree in Cybersecurity, Information Security, or a related field; CISSP, CISM, CCSP, or equivalent cybersecurity certification; Experience supporting accreditation, auditing, and compliance activities within defence, aerospace, or regulated industry environments; Experience conducting enterprise cybersecurity risk assessments and developing risk mitigation strategies; Experience preparing executive-level reports, security assessments, and technical documentation.

Location: This role can be based in either Leatherhead or Swindon and offers a hybrid working arrangement.

Security Requirements: SC Clearance. Due to the secure nature of this project, restrictions in relation to UK residency and nationality will apply.

KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, colour, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) in Leatherhead employer: KBR

As a Senior Quantity Surveyor with us, you'll join a dynamic team that values collaboration and professional growth, all while working on impactful civil and infrastructure projects in the UK. We offer a supportive work culture that encourages continuous improvement and provides opportunities for coaching and mentoring junior staff, ensuring you can develop your skills and advance your career. Our commitment to maintaining high standards in procurement and project management means you'll be part of a company that prioritises excellence and innovation in every aspect of its operations.

KBR

Contact Details:

KBR Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) in Leatherhead

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including KBR, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through KBR

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at KBR. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) in Leatherhead

Cybersecurity Governance
Risk Management
Information Assurance
Data Protection
Security Policy Implementation
Compliance Oversight
Penetration Testing Coordination

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at KBR insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to KBR that you’re committed to staying ahead in the game.

How to prepare for a job interview at KBR

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at KBR to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at KBR.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.