Information Security Governance and Risk Manager in Swindon

Information Security Governance and Risk Manager in Swindon

Swindon Full-Time 58589 - 58589 € / year (est.) Home office (partial)
UKRI

At a Glance

  • Tasks: Lead information security governance and risk management for cutting-edge research.
  • Company: Join UKRI, a leader in global research and innovation.
  • Benefits: Enjoy flexible working, 30 days leave, and a great pension scheme.
  • Other info: Dynamic role with opportunities for continuous learning and career growth.
  • Why this job: Make a real impact in safeguarding vital data for groundbreaking discoveries.
  • Qualifications: Degree in a related field and relevant professional qualifications required.

The predicted salary is between 58589 - 58589 € per year.

Step into the world where cutting-edge science meets robust information security. Protect the technology that powers groundbreaking discoveries and be part of the team that safeguards the future of Big Science. Here, you’ll collaborate with leading engineers, researchers, and technologists to tackle the most pressing security challenges in a fast-paced, innovative environment. Every day offers you the chance to defend vital data and systems, ensuring that the pursuit of scientific excellence continues securely and seamlessly.

Discover the difference you can make when you bring your expertise in information security to an organisation at the forefront of global research - working alongside some of the brightest minds and most advanced facilities in the world.

As a minimum, due to the nature of this role, candidates must be eligible for clearance in line with UK National vetting guidelines and willing to undertake the process. Please indicate eligibility in the written submission. Candidates not meeting this level of clearance will not be considered. The level of clearance required is security check.

The UKRI CIO Group plays a pivotal role in managing and optimising the organisations critical enterprise technical services that underpin and enable UKRI’s business capabilities. Within the group a team of Information Security Professionals support the delivery of modern, secure, resilient and scalable services across a larger federated team of Digital, Data and Technology professionals to deliver impact across the organisation and the wider UK research and innovation system.

Join us for this rare opportunity to apply your experience in information security governance, risk and assurance in a dynamic, fast-paced strategic role in an organisation at the heart of research and innovation in the UK. Managing the Information Security Governance, Risk and Assurance function your broad remit is to drive the implementation of our ambitious information security roadmap and support the UKRI Head of Information Security to mature our information security function. You will lead UKRI’s cyber security risk, compliance and assurance activity for cloud and enterprise services (AWS and Azure). You will own the information security management system (ISMS) and accreditations (ISO 27001 and Cyber Essentials Plus), run the information security risk framework, and drive secure-by-design assurance for new and existing services. You will work across UKRI’s federated technology estate to set proportionate controls, monitor compliance, and provide clear, actionable risk reporting to senior stakeholders.

Your responsibilities:

  • Own and lead UKRI’s Information Security Governance, Risk and Assurance framework.
  • Own, operate and continuously improve the Information Security Management System (ISMS).
  • Provide end‑to‑end security assurance for cloud and enterprise services (AWS and Azure).
  • Define and maintain UKRI’s security policy and control framework.
  • Enable and support risk ownership across UKRI’s federated technology and business teams.
  • Develop and maintain meaningful security metrics, dashboards and management information.
  • Define, deliver and track a multi‑year security governance, risk and assurance roadmap.
  • Lead security assessment, testing and remediation activity.
  • Provide ongoing oversight of supplier and third‑party security risk.
  • Establish and maintain enterprise visibility of assets, services and data risk context.
  • Provide governance leadership across incident management, people, suppliers and assurance partnerships.
  • Ensure governance‑level oversight of significant security incidents.

Personal Specification

The below criteria will be scored during Shortlisting (S), Interview (I) or both (S&I). Applicants will be able to demonstrate skills in line with the cyber security risk manager roles using the Government Security Profession career framework.

Essential:

  • Degree in a related subject or relevant comparable education. (S)
  • A professional qualification (e.g., CISM, CISSP, CCSP, ISO 27001 Lead Implementer/Lead Auditor). (S)
  • Effective decision-making, communication and interpersonal skills, with the ability to adapt communication style and approach to different environments and audiences. (I)
  • Self-motivated, shows initiative and works with minimal direction, demonstrating strong customer focus. (S&I)
  • Changing and improving processes, systems, and people to achieve positive outcomes. (S&I)
  • Strong knowledge of information security governance, risk management and compliance, including operating within an ISO/IEC 27001 management system. (S&I)
  • In-depth understanding of cloud security principles and practices for AWS and Azure, including secure configuration, identity, logging, network controls and data protection. (S&I)
  • Ability to coordinate and communicate security risk issues at a senior level and propose solutions that are appropriate, proportionate and effective. (S&I)
  • Strong problem-solving and analytical skills, including interpreting technical evidence and translating it into business risk. (S&I)

Application Guidance:

You are encouraged to use the STAR method (Situation, Task, Action, Result) in the cover letter to evidence your ability to meet the ‘person specification’ criteria in the job description. Cover letters should be no more than two sides of A4 (minimum font size 11).

Behaviours

We'll assess you against these behaviours during the selection process:

  • Managing a quality service
  • Changing and improving
  • Delivering at pace
  • Seeing the Big Picture

Selection Process Details

We know different organisations use different processes, so we wanted you to know what to expect from us.

  • Stage 0 - Pre-application: If you would like to find out more about the role we encourage prospective applicants to get in touch with us to discuss the opportunity.
  • Stage 1 - Written Submission: Candidates will need to submit a written application which consists of 2 parts: A CV – this should contain your work experience and any skills, qualifications and accomplishments relevant to the jobs you have completed based on the shortlisting criteria. A personal statement (max. 1000 words) - this statement should be used to provide examples of how you meet the essential criteria listed in the shortlisting criteria. Applications will be reviewed for suitability and shortlisted.
  • Stage 2 - Interview: Applicants who are successful at stage 1 will be invited to interview. The interview will generally be 1 hour in length. The interview will consist of competency-based questions. A presentation will be required.
  • Stage 3 - Outcome: The panel outcome is decided and the successful candidate will be offered verbally first, followed by a formal offer letter.

Benefits

We recognise and value our employees as individuals and aim to provide a favourable pay and rewards package. We are committed to supporting employees' development and promote a culture of continuous learning!

A list of benefits below:

  • An outstanding defined benefit pension scheme
  • 30 days' annual leave in addition to 10.5 public and privilege days (full time equivalent)
  • Employee discounts and offers on retail and leisure activities
  • Employee assistance programme, providing confidential help and advice
  • Flexible working options
  • Plus many more benefits and wellbeing initiatives that enable our employees to have a great work life balance!

For further information on our benefits please see: Benefits of working at UK Research and Innovation (UKRI). We encourage candidates to apply as soon as possible, as we reserve the right to close this vacancy early.

Please apply online, if you experience any issue applying, please contact Recruitment@ukri.org.

Please note, if you will require sponsorship to work in the UK, as part of your sponsorship application, you and any dependants travelling with you, will be required to pay costs directly to The Home Office for the application before you start your role with us. UKRI is normally able to reimburse some, or all of these fees after you have become an employee and this can be discussed with the Hiring Manager.

Information Security Governance and Risk Manager in Swindon employer: UKRI

At UK Research and Innovation, we pride ourselves on being an exceptional employer that champions employee development and work-life balance. With a commitment to flexible working patterns, a generous benefits package including a defined benefit pension scheme and 30 days of annual leave, our collaborative culture fosters innovation and personal growth, making it an ideal environment for professionals in information security governance and risk management.

UKRI

Contact Detail:

UKRI Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Governance and Risk Manager in Swindon

Tip Number 1

Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their mission and values, especially around information security. Tailor your responses to show how your skills align with their goals.

Tip Number 3

Practice makes perfect! Conduct mock interviews with friends or use online platforms. This will help you articulate your experience and demonstrate your problem-solving skills effectively.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re genuinely interested in being part of our team at UKRI.

We think you need these skills to ace Information Security Governance and Risk Manager in Swindon

Information Security Governance
Risk Management
Compliance
ISO 27001
Cyber Essentials Plus
Cloud Security (AWS and Azure)
Security Assurance

Some tips for your application 🫡

Get to Know the STAR Method:Before you start writing, familiarise yourself with the STAR method (Situation, Task, Action, Result). It’s a great way to structure your personal statement and showcase how you meet the essential criteria. Trust us, it makes your examples stand out!

Tailor Your CV:Make sure your CV is tailored to the role. Highlight relevant work experience, skills, and qualifications that align with the job description. We want to see how your background fits into our world of information security governance and risk management.

Keep It Concise:When writing your personal statement, stick to the 1000-word limit. Be concise and focus on the most impactful examples that demonstrate your skills and experience. Remember, quality over quantity!

Apply Through Our Website:We encourage you to apply through our website for a smooth application process. It’s the best way to ensure your application gets to us without any hiccups. Plus, we love seeing applications come directly from our site!

How to prepare for a job interview at UKRI

Know Your Stuff

Make sure you brush up on your knowledge of information security governance, risk management, and compliance. Familiarise yourself with ISO/IEC 27001 and the specific cloud security principles for AWS and Azure. This will not only help you answer questions confidently but also show that you're genuinely interested in the role.

Use the STAR Method

When preparing for competency-based questions, use the STAR method (Situation, Task, Action, Result) to structure your responses. This approach helps you clearly articulate your experiences and how they relate to the job requirements, making it easier for the interviewers to see your fit for the role.

Show Your Problem-Solving Skills

Be ready to discuss specific examples where you've tackled security challenges or improved processes. Highlight your analytical skills and how you've translated technical evidence into business risks. This will demonstrate your ability to think critically and make effective decisions in a fast-paced environment.

Engage with the Interviewers

Remember, interviews are a two-way street! Prepare thoughtful questions about the team, the organisation's security roadmap, and how they measure success in this role. Engaging with the interviewers shows your enthusiasm and helps you assess if the company is the right fit for you.