GRC - Cyber Assurance and Risk Lead
GRC - Cyber Assurance and Risk Lead

GRC - Cyber Assurance and Risk Lead

London Full-Time 54000 - 84000 Β£ / year (est.) No home office possible
Go Premium
N

At a Glance

  • Tasks: Lead and shape security and risk programmes to meet business goals and regulatory standards.
  • Company: Join a forward-thinking organisation committed to cybersecurity excellence and industry best practices.
  • Benefits: Enjoy competitive pay, flexible working options, and opportunities for professional growth.
  • Why this job: Make a real impact in cybersecurity while fostering a culture of accountability and innovation.
  • Qualifications: 10+ years in Governance, Risk and Compliance, with leadership experience and relevant certifications.
  • Other info: Candidates must be eligible for UK SC level Security Clearance.

The predicted salary is between 54000 - 84000 Β£ per year.

As a strategic and leadership role you will be instrumental in shaping and driving security and risk programs to align with internal business objectives as well as industry good practice (including Secure by Design aligned to UK Government principles) and regulatory requirements (including GovAssure and NCSC Cyber Assurance Framework).

What you'll be doing:

  • Develop and execute GRC strategies that align with business objectives and inform appropriate supporting business processes.
  • Drive pragmatic and creative solutions to GRC challenges, applying agile methodologies to adapt to new regulations, compliance requirements and business change.
  • Advise on and foster continuous improvement and effectiveness of GRC processes, driving improved management information to better allow appropriate prioritisation and risk based decisions.
  • Lead initiatives that build a culture of accountability and responsibility across engagements.
  • Enhance governance processes and advise on how best to evidence alignment with regulatory requirements (such as NCSC CAF) and industry good practice (including Secure by Design).
  • Providing security expertise across security standards and accreditations, measure and control the effectiveness of the security controls framework and maintain the Information Security Management System.
  • Deriving and delivering documented Information Security Management Plans which incorporate Regulatory, Legal and Compliance in relation to applicable security policies, standards and guidelines.
  • Assisting with the identification of identified risks and emerging cyber security vulnerabilities and threats. The subsequent analysis to quantify and lead risk mitigation plans.
  • Work with Service Management to ensure that partners and suppliers adhere to agreed standards, policies and verify/evidence appropriate compliance and security KPIs.
  • Work closely with 1st, 2nd and 3rd lines of defence on all matters relating to cyber security, information assurance, cyber risk, data privacy including regulatory and compliance considerations.
  • Lead the development and enhancement of governance, risk and compliance aligned to policy, standards and industry good practice.
  • Ensure that continuous assessment, identification, analysis and reporting of useful metrics to enable informed risk based decisions to be taken.
  • Develops and maintains Information Security Management practice and process to ensure certification to required industry standards (e.g., ISO 27001) within relevant geographic boundaries.
  • Performs focused information risk assessments of existing or new services and technologies, alongside the Operational/Service Management team and technology subject matter experts.
  • As required, will extend the assessment of existing and proposed services to third party suppliers, including the facilitation of IT Security checks during the supplier onboarding and contract lifecycle to ensure coherent approach to risk management.
  • Maintains strong working relationships with individuals and groups involved in managing information risk across the in-scope services and aligned suppliers / 3rd parties.
  • Chairs and co-ordinates Security Working Groups (SWG) and actively participates in supporting/governing forums.

What experience you'll bring:

  • Requires extensive knowledge of GRC frameworks, regulatory compliance obligations and a proactive approach to risk management.
  • Minimum of 10 years’ experience in a Governance, Risk and Compliance role, with at least 5 years in a leadership or managerial position.
  • Relevant certifications such as CISSP, CISM, CCSP, CISA, CRISC or equivalent experience.
  • Expertise and practical knowledge and understanding of industry security frameworks and guidance such as NIST 800-53, NCSC CAF GovAssure, NIST CSF, DORA and NCSC guidelines.
  • Good knowledge and understanding of Cyber Security domains, including; network and cloud security, security operations, vulnerability management, Third Party supplier Risk Management, application security, physical security.
  • Good knowledge of networking (switching, routing, firewalls).
  • A good understanding of security testing and vulnerability management is important (including pen testing/ITHC, CVSS/CVE).
  • Experience working with security standards such as ISO 27001, 27002, 27017, 27108 etc.

Desirable skills and experience:

  • Thrive as a consultant seeking the variety and challenge of engaging with different clients and variety of technologies and solution types.
  • Proposes security requirements for new systems or changes to existing systems without close supervision.
  • Execute technical management tasks in respect to ongoing client projects.
  • Hands on technical background with technologies and systems.

Security clearance:

Please note that candidates must hold or be able to gain UK SC level Security Clearance or higher.

N

Contact Detail:

NTT DATA Recruiting Team

StudySmarter Expert Advice 🀫

We think this is how you could land GRC - Cyber Assurance and Risk Lead

✨Tip Number 1

Familiarise yourself with the specific GRC frameworks mentioned in the job description, such as NCSC CAF and GovAssure. Understanding these frameworks will not only help you in interviews but also demonstrate your commitment to aligning with industry standards.

✨Tip Number 2

Network with professionals in the cybersecurity field, especially those who have experience in governance, risk, and compliance roles. Engaging in discussions or attending relevant events can provide insights and potentially lead to referrals.

✨Tip Number 3

Showcase your leadership skills by discussing any previous experiences where you led teams or initiatives related to GRC. Highlighting your ability to drive change and foster a culture of accountability will resonate well with the hiring team.

✨Tip Number 4

Stay updated on the latest trends and emerging threats in cybersecurity. Being knowledgeable about current vulnerabilities and how they relate to GRC will position you as a proactive candidate who is ready to tackle challenges head-on.

We think you need these skills to ace GRC - Cyber Assurance and Risk Lead

GRC Frameworks Knowledge
Regulatory Compliance Expertise
Risk Management Proficiency
Leadership and Management Skills
CISSP Certification
CISM Certification
CCSP Certification
CISA Certification
CRISC Certification
NIST 800-53 Familiarity
NCSC CAF Understanding
GovAssure Knowledge
NIST CSF Awareness
DORA Guidelines Familiarity
Cyber Security Domain Knowledge
Network Security Understanding
Cloud Security Expertise
Vulnerability Management Skills
Third Party Risk Management
Application Security Knowledge
Physical Security Awareness
ISO 27001 Standards Knowledge
Security Testing Experience
Penetration Testing Understanding
Technical Management Skills
Strong Communication Skills
Stakeholder Engagement
Agile Methodologies Application
Continuous Improvement Mindset

Some tips for your application 🫑

Tailor Your CV: Make sure your CV highlights your extensive knowledge of GRC frameworks and regulatory compliance obligations. Emphasise your leadership experience and relevant certifications like CISSP or CISM, as these are crucial for the role.

Craft a Compelling Cover Letter: In your cover letter, explain how your experience aligns with the job description. Discuss specific examples of how you've developed and executed GRC strategies in previous roles, and how you’ve driven improvements in governance processes.

Showcase Relevant Experience: When detailing your work history, focus on your 10+ years in Governance, Risk, and Compliance roles. Highlight any experience with industry security frameworks like NIST or ISO standards, and mention your hands-on technical background where applicable.

Demonstrate Continuous Improvement Mindset: Illustrate your proactive approach to risk management by providing examples of how you've fostered continuous improvement in GRC processes. Mention any initiatives you've led that built a culture of accountability and responsibility within teams.

How to prepare for a job interview at NTT DATA

✨Showcase Your GRC Knowledge

Make sure to highlight your extensive knowledge of Governance, Risk, and Compliance frameworks during the interview. Be prepared to discuss specific frameworks like NIST 800-53 and NCSC CAF, and how you've applied them in previous roles.

✨Demonstrate Leadership Experience

Since this role requires a minimum of 5 years in a leadership position, be ready to share examples of how you've led teams or initiatives. Discuss your approach to fostering a culture of accountability and responsibility within your team.

✨Prepare for Technical Questions

Expect technical questions related to cyber security domains, such as network and cloud security, vulnerability management, and security testing. Brush up on your knowledge of security standards like ISO 27001 and be ready to explain how you've implemented these in practice.

✨Align with Business Objectives

Be prepared to discuss how you can align GRC strategies with business objectives. Share examples of how you've driven pragmatic solutions to GRC challenges and adapted to new regulations or compliance requirements in past roles.

GRC - Cyber Assurance and Risk Lead
NTT DATA
Location: London
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

N
  • GRC - Cyber Assurance and Risk Lead

    London
    Full-Time
    54000 - 84000 Β£ / year (est.)
  • N

    NTT DATA

Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>