Head of Governance Risk and Compliance in Wokingham

Head of Governance Risk and Compliance in Wokingham

Wokingham Full-Time 85000 - 100000 £ / year (est.) Home office (partial)
National Energy System Operator

At a Glance

  • Tasks: Lead governance, risk, and compliance for a critical national infrastructure organisation.
  • Company: Join NESO, a key player in the UK's energy transformation.
  • Benefits: Competitive salary, bonus potential, private medical insurance, and generous leave.
  • Other info: Flexible working options and a commitment to diversity and inclusion.
  • Why this job: Shape the future of energy while enhancing security and compliance.
  • Qualifications: Proven experience in cyber security governance and risk management.

The predicted salary is between 85000 - 100000 £ per year.

About the Role

The Head of Governance, Risk & Compliance is a senior leadership role within NESO's Security function, reporting directly to the Chief Information Security Officer (CISO).

This role is responsible for developing, implementing and continually enhancing NESO's security governance framework, threat-led cyber risk management framework and assurance strategy across one of the UK's most critical national infrastructure organisations.

This is a strategic role that requires close working with Executive stakeholders, the CIO leadership team, Enterprise Risk Management, Internal Audit, regulators and industry partners to ensure cyber and physical security risks are effectively understood, governed and managed in line with NESO's risk appetite and regulatory obligations.

The successful candidate will play a pivotal role in embedding a proactive risk culture, strengthening regulatory confidence, and ensuring security is integrated into NESO's digital, operational and business transformation agenda.

his role is designated as requiring a National Security Vetting (NSV) clearance.

The level of clearance associated with this role (SC) will usually need you to have been a resident in the UK for the last five years to apply.

We would invite any applicants who do not currently meet this residency requirement to still express an interest in the role.

This role can be based from Wokingham or Warwick and we continue to offer hybrid working from office and home.

  • Key Accountabilities
  • Governance & Strategy
  • Lead the development and continual evolution of NESO's Security Governance Framework, ensuring alignment with organisational strategy, risk appetite and regulatory obligations.
  • Develop and maintain security policies, standards, control frameworks and governance processes across cyber, technology and operational environments.
  • Act as a strategic advisor to the CISO on governance, risk and assurance matters.
  • Threat‑Led Risk Management
  • Develop and operate NESO's enterprise cyber risk management framework, aligned to NIS Regulations, and external standards such as CAF, ISO 27001, and enterprise risk management processes.
  • Drive a threat-informed approach to risk identification, assessment, prioritisation and treatment.
  • Establish clear risk ownership and accountability across the organisation.
  • Lead development of Board and Executive Committee cyber risk reporting.
  • Provide independent challenge and assurance to major technology and business programmes.
  • Compliance & Assurance
  • Develop and implement a comprehensive cyber assurance strategy covering technology, operational environments, third parties and critical suppliers.
  • Lead NESO's compliance activities relating to NIS Regulations, CAF, ISO27001 and other applicable regulatory obligations.
  • Manage relationships with regulators, auditors and external assurance providers.
  • Establish metrics and reporting that provide meaningful insight into control effectiveness and organisational resilience.
  • Secure by Design & Transformation
  • Ensure governance, risk and assurance activities support NESO's digital, data, AI and technology transformation agenda.
  • Embed secure-by-design and risk-based decision-making into technology delivery, cloud adoption and Dev Sec Ops practices.
  • Provide strategic oversight and challenge to major change programmes.
  • Provide governance, risk and assurance oversight for emerging technologies, including Artificial Intelligence (AI), ensuring their adoption aligns with NESO's risk appetite, regulatory obligations and security requirements.
  • Leadership & Culture
  • Lead and develop a high-performing Governance, Risk & Compliance function.
  • Foster a proactive security culture that promotes accountability, transparency and continuous improvement.
  • Build strong relationships across operational, technology and business teams to drive shared ownership of risk.

Applicants must have the right to work in the UK by the start of employment.

Visa sponsorship may not be available for this role and will be considered in line with business requirements.

About You

We are seeking a strategic security leader with the ability to operate at both executive and technical levels.

You will combine strong governance and risk leadership capabilities with sufficient technical credibility to challenge technology decisions, understand emerging threats and influence security outcomes across complex environments.

Essential

  • Significant experience leading Cyber Security Governance, Risk and Compliance functions within critical national infrastructure, highly regulated or complex operational environments.
  • Demonstrable experience designing and implementing enterprise security governance and threat-led risk management frameworks.
  • Proven track record leading NIS Regulations and CAF compliance programmes.
  • Experience providing cyber risk reporting and strategic advice to Boards, Executive Committees and regulators.
  • Experience operating within digital transformation, cloud, data, AI and Dev Sec Ops environments.
  • Experience leading assurance activities across technology and third-party ecosystems.
  • Strong understanding of modern cyber threats, threat intelligence and risk management methodologies.
  • Experience building and leading high-performing teams.

Desirable

  • Energy sector experience.
  • Experience working closely with NCSC, Ofgem or other regulatory bodies.
  • CISSP, CISM, CRISC, ISO27001 Lead Implementer/Auditor or equivalent.
  • Experience of developing governance, risk management and assurance approaches for emerging technologies, including Artificial Intelligence (AI), Generative AI and advanced analytics, with an understanding of associated security, ethical and regulatory considerations.
  • What You'll Get

A competitive salary of £85,000 - £100,000 dependent on experience and capability.

As well as your base salary, you will receive a benefits allowance, a bonus of up to 20% of your salary for stretch performance, private medical insurance, 28 days annual leave as standard and a competitive contributory pension scheme where we will double match your contribution to a maximum company contribution of 12%.

NESO's flexible benefits programme provides you with more flexibility around your health, lifestyle and protection benefits, here's just a few available:

  • Flexible Bank Holidays & Holiday Trading
  • Additional Birthday Day Off
  • Cycle to Work Scheme, Retail & Gym Discounts
  • Private Medical Insurance, Critical Illness Insurance & Personal Accident Insurance

About Us

At the National Energy System Operator (NESO), we play a vital role in tackling climate change and securing Great Britain's energy future.

We already operate the world's fastest decarbonising electricity system and are working towards our ambition to run it carbon-free for a short period this year - provided the market supplies electricity exclusively from renewable sources.

Alongside this, we provide expert advice to government on how to deliver a clean power system by 2030.

In autumn 2024, the Electricity System Operator (ESO) transitioned to become NESO - an independent, expert public corporation with a whole-system view across electricity, gas, and hydrogen.

NESO operates independently and transparently, always acting in the best interests of all energy users.

Licensed and regulated by Ofgem, we make impartial decisions that balance sustainability, affordability and security.

Our organisation is fully independent from government, the regulator and all commercial interests, with a clear focus on system-wide benefit, long-term thing and public value.

The time to deliver is now. Join the energy transformation and help shape the future. Your energy. Our future. Together.

National Energy System Operator (NESO) recognises the potential of bright and talented individuals, and we encourage you to join us as Great Britain's energy system undergoes an ambitious, exciting, and vital transformation.

Together with industry, we are creating a cleaner, more sustainable energy future.

More Information

This role closes at 23:59, on the day before date shown above, however we encourage candidates to submit their application as early as possible and not wait until the published closing date as this can vary.

Research shows that some people may hesitate to apply unless they meet every single requirement.

At NESO, we believe potential comes in many forms and we're committed to a fair, inclusive recruitment.

We're committed to building a workforce that represents the communities we serve, and a working environment in which each individual feels valued, respected, fairly treated, and able to reach their full potential.

If this role sparks your interest but you're not sure you tick every box, we still want to hear from you.

We celebrate the difference people can bring into our organisation, and welcome and encourage applicants with diverse experiences and backgrounds.

#J-18808-Ljbffr

Head of Governance Risk and Compliance in Wokingham employer: National Energy System Operator

The National Energy System Operator is an exceptional employer, offering a dynamic work environment in Warwick that fosters collaboration and innovation in the energy sector. With a strong commitment to employee development, competitive salaries, and comprehensive benefits, including bonuses and a pension scheme, this role not only provides meaningful work in regulatory law but also supports your professional growth in a vital industry focused on sustainability.

National Energy System Operator

Contact Details:

National Energy System Operator Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Head of Governance Risk and Compliance in Wokingham

Join Compliance Communities

Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!

Attend Industry Conferences

Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.

Leverage Your University Career Services

If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.

Showcase Your Knowledge Online

Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like National Energy System Operator looking for candidates who are engaged and informed.

We think you need these skills to ace Head of Governance Risk and Compliance in Wokingham

Cyber Security Governance
Risk Management
Compliance Management
NIS Regulations
ISO 27001
Threat Intelligence
Digital Transformation

Some tips for your application 🫡

Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!

Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.

Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!

Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at National Energy System Operator. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!

How to prepare for a job interview at National Energy System Operator

Master the Regulations

Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!

Show Your Analytical Skills

Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!

Know Your Tools

Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!

Align with Company Culture

Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with National Energy System Operator’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!