At a Glance
- Tasks: Lead information security governance and risk management for cutting-edge research.
- Company: Join a pioneering organisation at the forefront of global research and innovation.
- Benefits: Enjoy flexible working, 30 days annual leave, and a fantastic pension scheme.
- Other info: Dynamic role with opportunities for continuous learning and career growth.
- Why this job: Make a real impact in safeguarding vital data for groundbreaking scientific discoveries.
- Qualifications: Degree in a related field and relevant professional qualifications required.
The predicted salary is between 58589 - 58589 £ per year.
Step into the world where cutting‑edge science meets robust information security. Protect the technology that powers groundbreaking discoveries and be part of the team that safeguards the future of Big Science. Here, you’ll collaborate with leading engineers, researchers, and technologists to tackle the most pressing security challenges in a fast‑paced, innovative environment. Every day offers you the chance to defend vital data and systems, ensuring that the pursuit of scientific excellence continues securely and seamlessly. Discover the difference you can make when you bring your expertise in information security to an organisation at the forefront of global research – working alongside some of the brightest minds and most advanced facilities in the world.
Security: As a minimum, due to the nature of this role, candidates must be eligible for clearance in line with UK National vetting guidelines and willing to undertake the process. Please indicate eligibility in the written submission. Candidates not meeting this level of clearance will not be considered. The level of clearance required is security check.
About the role: The UKRI CIO Group plays a pivotal role in managing and optimising the organisations critical enterprise technical services that underpin and enable UKRI’s business capabilities. Within the group, a team of Information Security Professionals support the delivery of modern, secure, resilient and scalable services across a larger federated team of Digital, Data and Technology professionals to deliver impact across the organisation and the wider UK research and innovation system. Join us for this rare opportunity to apply your experience in information security governance, risk and assurance in a dynamic, fast‑paced strategic role in an organisation at the heart of research and innovation in the UK.
Your responsibilities:
- Own and lead UKRI’s Information Security Governance, Risk and Assurance framework.
- Own, operate and continuously improve the Information Security Management System (ISMS).
- Provide end‑to‑end security assurance for cloud and enterprise services (AWS and Azure).
- Define and maintain UKRI’s security policy and control framework.
- Enable and support risk ownership across UKRI’s federated technology and business teams.
- Develop and maintain meaningful security metrics, dashboards and management information.
- Define, deliver and track a multi‑year security governance, risk and assurance roadmap.
- Lead security assessment, testing and remediation activity.
- Provide ongoing oversight of supplier and third‑party security risk.
- Establish and maintain enterprise visibility of assets, services and data risk context.
- Provide governance leadership across incident management, people, suppliers and assurance partnerships.
- Ensure governance‑level oversight of significant security incidents.
Personal Specification: The below criteria will be scored during Shortlisting (S), Interview (I) or both (S&I). Applicants will be able to demonstrate skills in line with the cyber security risk manager roles using the Government Security Profession career framework.
Essential:
- Degree in a related subject or relevant comparable education. (S)
- A professional qualification (e.g., CISM, CISSP, CCSP, ISO 27001 Lead Implementer/Lead Auditor). (S)
- Effective decision‑making, communication and interpersonal skills, with the ability to adapt communication style and approach to different environments and audiences. (I)
- Self‑motivated, shows initiative and works with minimal direction, demonstrating strong customer focus. (S&I)
- Changing and improving processes, systems, and people to achieve positive outcomes. (S&I)
- Strong knowledge of information security governance, risk management and compliance, including operating within an ISO/IEC 27001 management system. (S&I)
- In‑depth understanding of cloud security principles and practices for AWS and Azure, including secure configuration, identity, logging, network controls and data protection. (S&I)
- Ability to coordinate and communicate security risk issues at a senior level and propose solutions that are appropriate, proportionate and effective. (S&I)
- Strong problem‑solving and analytical skills, including interpreting technical evidence and translating it into business risk. (S&I)
Behaviours:
- Managing a quality service
- Changing and improving
- Delivering at pace
- Seeing the Big Picture
Benefits:
- An outstanding defined benefit pension scheme
- 30 days' annual leave in addition to 10.5 public and privilege days (full time equivalent)
- Employee discounts and offers on retail and leisure activities
- Employee assistance programme, providing confidential help and advice
- Flexible working options
We recognise and value our employees as individuals and aim to provide a favourable pay and rewards package. We are committed to supporting employees' development and promote a culture of continuous learning!
We encourage candidates to apply as soon as possible, as we reserve the right to close this vacancy early.
Information Security Governance and Risk Manager in Nottingham employer: UKRI
Join a pioneering organisation at the forefront of research and innovation, where your expertise in information security will play a crucial role in safeguarding vital data and systems. With a commitment to employee development, flexible working options, and an outstanding benefits package including a defined benefit pension scheme and generous annual leave, UKRI fosters a collaborative and dynamic work culture that empowers you to make a meaningful impact alongside some of the brightest minds in the field. Experience the unique advantage of contributing to groundbreaking scientific discoveries while enjoying a supportive environment that values your contributions.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security Governance and Risk Manager in Nottingham
✨Tip Number 1
Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their mission and values, especially around information security. Tailor your answers to show how you can contribute to their goals.
✨Tip Number 3
Practice your responses to common interview questions, but keep it natural. Use the STAR method (Situation, Task, Action, Result) to structure your answers and highlight your achievements in information security.
✨Tip Number 4
Don’t forget to follow up after your interview! A quick thank-you email can leave a lasting impression and shows your enthusiasm for the role. Plus, it keeps you on their radar as they make their decision.
We think you need these skills to ace Information Security Governance and Risk Manager in Nottingham
Some tips for your application 🫡
Show Your Security Savvy:When you're writing your application, make sure to highlight your experience in information security governance and risk management. We want to see how you've tackled challenges in the past and what makes you a great fit for our team.
Tailor Your Application:Don’t just send a generic application! Take the time to tailor your CV and cover letter to match the job description. Use keywords from the posting to show us that you understand what we're looking for and how you can contribute.
Be Clear About Your Qualifications:Make sure to clearly state your relevant qualifications, especially any professional certifications like CISM or CISSP. This helps us quickly see that you meet the essential criteria for the role.
Apply Through Our Website:We encourage you to apply through our website for a smoother process. It’s the best way to ensure your application gets into our system correctly, and we can’t wait to see what you bring to the table!
How to prepare for a job interview at UKRI
✨Know Your Stuff
Make sure you brush up on your knowledge of information security governance, risk management, and compliance. Familiarise yourself with ISO/IEC 27001 and the specific cloud security principles for AWS and Azure. Being able to discuss these topics confidently will show that you're serious about the role.
✨Showcase Your Experience
Prepare to share specific examples from your past work that demonstrate your decision-making skills and ability to manage security risks. Think about times when you've improved processes or systems and be ready to explain how you achieved positive outcomes.
✨Communicate Effectively
Practice adapting your communication style to different audiences. You’ll need to convey complex security issues to senior stakeholders, so being clear and concise is key. Consider rehearsing with a friend or mentor to refine your approach.
✨Ask Insightful Questions
Prepare thoughtful questions about the organisation's current security challenges and future goals. This not only shows your interest in the role but also gives you a chance to demonstrate your understanding of the field and how you can contribute to their mission.