At a Glance
- Tasks: Lead the strategy and build a modern Governance, Risk and Compliance function in Cyber Security.
- Company: Join a leading media and entertainment company with a focus on innovation.
- Benefits: Competitive salary, flexible working, and opportunities for professional growth.
- Other info: Be part of a creative team that values simplicity and effectiveness.
- Why this job: Shape the future of GRC using AI and automation in a dynamic environment.
- Qualifications: Experience in GRC strategy, strong collaboration skills, and a passion for technology.
The predicted salary is between 63000 - 77000 £ per year.
Accepting applications until: 28 August 2026
Job Description
Your Role: Head of Governance, Risk and Compliance - Cyber Security
This is a builder role.
You'll shape how GRC works at Global from the ground up, creating a modern, engineering-led function that fits a fast-moving, creative business rather than a heavily regulated institution.
As Head of Governance, Risk and Compliance - Cyber Security at Global, you will lead the strategy, operating model and future team for GRC, working directly with the Director of Cyber Security with wider cyber security team and senior leaders across Technology, Consumer and the wider business.
You will be curious and inventive about how AI and automation can be used thoughtfully to solve real GRC problems and remove unnecessary friction.
Key Responsibilities
- Set the GRC strategy and operating model (30%) : Define and own the cyber GRC vision, principles and multi-year roadmap.
Design practical governance forums and decision pathways, establish a clear security policy framework and lifecycle, and agree the future team structure, capabilities and hiring plan.
- Build risk, control and compliance frameworks (30%): Create and embed simple, outcome-focused frameworks for security and enterprise risk management, control design and assurance, and compliance coordination.
Ensure risks have clear owners and treatment plans, controls are measurable and effective, and evidence management is scalable and reusable.
- Establish GRC engineering, tooling and automation (25%): Lead the move towards policy as code, automated control testing, workflow-driven assurance and integration of GRC into engineering and business processes.
Use data, tooling and automation to reduce manual, document-heavy tasks and improve visibility of risk and compliance posture.
- Lead stakeholder engagement, culture and reporting (15%): Partner with Technology, Product, Legal, Procurement, Privacy, Audit and business teams to embed GRC into day-to-day work.
Own security culture, awareness and behaviour-change activities, and provide clear, concise risk and compliance reporting and insights for senior leaders and boards.
- What You'll Love About This Role
- Think Big: Shape what 'great' GRC looks like for a leading media and entertainment company, creating a function that is modern, data-driven and fit for a digital world.
- Own It: You'll have the mandate to design and implement the strategy, operating model, processes and shape the tooling we use.
- Keep it
Simple: Your focus will be on practical, lightweight frameworks that help people make good decisions, not on bureaucracy.
You'll strip out red tape and build approaches that teams genuinely want to use.
- Better
Together: Work closely with engineers, product teams, commercial leaders and support functions to embed GRC into everyday workflows and build a strong, collaborative security culture.
- What Success Looks Like
- Agreed a clear, phased GRC strategy and roadmap with the Director of Cyber Security and key stakeholders.
- Established simple, repeatable governance and risk processes that leaders find helpful, not burdensome.
- Reviewed our security policy and standards framework.
- Launched or enhanced core GRC tooling, automation or data flows to reduce manual effort and improve visibility.
- Delivered clear, concise risk and compliance updates for senior stakeholders, improving shared understanding of priorities.
- What You'll Need
- Strategic and hands-on: Experience setting GRC strategy and operating models, combined with a willingness to roll up your sleeves and build frameworks, content and processes yourself.
- Modern GRC mindset: Strong background in security governance, risk and compliance in technology-led organisations, with an interest in GRC engineering, automation and policy-as-code approaches.
- Pragmatic risk leadership: Ability to not let perfect be the enemy of good, keeping things proportionate and outcomes-focused rather than checkbox-driven.
- Influence and collaboration: Excellent stakeholder skills, able to build credibility with engineers, product teams, legal, procurement, audit and senior executives.
- AI-curious and inventive: A genuine curiosity about how AI and related technologies can safely augment GRC processes, and an ability to spot practical use cases that reduce friction and improve outcomes.
- Delivery focus: Comfortable in fast-paced, changing environments, with a track record of turning ideas into working practices, tooling and measurable improvements.
- #J-18808-Ljbffr
Head of Governance, Risk and Compliance - Cyber Security in London employer: PVH (Tommy Hilfiger/Calvin Klein)
Intapp is an exceptional employer, offering a dynamic work environment that fosters innovation and collaboration within the accounting and consulting sectors across EMEA. With a strong commitment to employee growth, Intapp provides ample opportunities for professional development and leadership coaching, ensuring that team members thrive in their careers while contributing to the company's strategic vision. The culture is built on accountability and high performance, making it an ideal place for those looking to make a significant impact in a rapidly evolving industry.
Contact Details:
PVH (Tommy Hilfiger/Calvin Klein) Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Head of Governance, Risk and Compliance - Cyber Security in London
✨Join Compliance Communities
Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!
✨Attend Industry Conferences
Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.
✨Leverage Your University Career Services
If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.
✨Showcase Your Knowledge Online
Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like PVH (Tommy Hilfiger/Calvin Klein) looking for candidates who are engaged and informed.
We think you need these skills to ace Head of Governance, Risk and Compliance - Cyber Security in London
Some tips for your application 🫡
Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!
Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.
Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!
Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at PVH (Tommy Hilfiger/Calvin Klein). Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!
How to prepare for a job interview at PVH (Tommy Hilfiger/Calvin Klein)
✨Master the Regulations
Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!
✨Show Your Analytical Skills
Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!
✨Know Your Tools
Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!
✨Align with Company Culture
Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with PVH (Tommy Hilfiger/Calvin Klein)’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!