Head, Governance, Risk and Compliance (Head Security GRC)

Head, Governance, Risk and Compliance (Head Security GRC)

Full-Time No working from home possible
Willis Re (UK) Limited

At a Glance

  • Tasks: Lead cybersecurity governance, risk and compliance strategy for a dynamic organisation.
  • Company: Join a forward-thinking company prioritising cybersecurity and innovation.
  • Benefits: Comprehensive health benefits, generous leave, and retirement plans.
  • Other info: Diverse and inclusive workplace with opportunities for professional growth.
  • Why this job: Make a significant impact on cybersecurity while collaborating with top leaders.
  • Qualifications: 10 years in cybersecurity with strong knowledge of GRC frameworks.

The Head, GRC is a senior cybersecurity leader responsible for defining and operating the governance, risk and compliance strategy for the organization. This role partners closely with the CISO, technology leaders, legal, risk, compliance and business stakeholders to ensure cyber risk is governed effectively, regulatory obligations are met, and security controls are aligned to business priorities.

The role will lead policy and standards governance, cyber risk management, control assurance, audit and regulatory engagement, and third-party risk oversight while building a culture of accountability and continuous improvement.

  • Lead and continuously improve the cybersecurity GRC framework, operating model, governance forums and reporting cadence.
  • Own the lifecycle of cybersecurity policies, standards, procedures and exception management, ensuring alignment to business objectives and regulatory expectations.
  • Establish and maintain a risk-based control environment aligned to recognized frameworks such as NIST CSF, ISO 27001 and other applicable regulatory requirements.
  • Direct enterprise cyber risk assessments, risk treatment planning, control testing and issue remediation tracking.
  • Oversee internal and external audits, customer assurance activities and regulatory examinations related to information security and cyber controls.
  • Partner with legal, privacy, compliance and enterprise risk teams to interpret and operationalize changing cyber and data protection obligations.
  • Oversee third-party cyber risk governance, including due diligence, control reviews and ongoing monitoring of critical suppliers.
  • Develop meaningful metrics, KRIs and executive reporting to communicate cyber risk posture, compliance status and remediation progress to senior leadership.

Company Benefits:

  • Health and Welfare Benefits: Medical, Dental, Vision, Health Savings Account, Commuter Benefits, Health Care and Dependent Care Flexible Spending Accounts, Accident Insurance, Critical Illness Insurance, Life Insurance, AD&D, Financial wellbeing support, Wellbeing Program and Work/Life Resources (including Employee Assistance Program).
  • Leave Benefits: Paid Holidays, Annual Paid Time Off (includes paid state/local paid leave where required), Short-Term Disability, Long-Term Disability, Other Leaves (e.g., Bereavement, FMLA, ADA, Jury Duty, Military Leave, and Parental and Adoption Leave), Paid Time Off (Washington State only).
  • Retirement Benefits: Salvage Plan (401k).
  • Compensation: The salary benchmark for this role is US (New York): $220,000 – $250,000 – $280,000.

About You:

  • You are a strategic and hands-on cybersecurity GRC leader who can translate regulatory, audit and risk requirements into practical actions for technology and business teams.
  • You are comfortable operating at executive level while also driving program execution, control maturity and measurable outcomes.
  • You bring strong judgment, clear communication and the ability to influence across complex stakeholder groups.
  • Proven experience leading cybersecurity governance, risk and compliance programs in a complex enterprise environment.
  • Strong knowledge of cybersecurity and control frameworks, including NIST CSF 2.0, ISO 27001, SOC 2 and relevant regulatory expectations.
  • Demonstrated experience with cyber risk assessments, policy governance, control assurance, audit management and issue remediation.
  • Ability to communicate cyber risk and control effectiveness in clear business terms to executives and non-technical stakeholders.
  • Experience partnering with audit, enterprise risk, legal, privacy, procurement and technology teams.
  • 10 years of experience in cybersecurity, information security, information technology, risk management or a related field.
  • Relevant certifications such as CISM, CRISC or CISA are desirable.

We provide equal opportunity to all qualified individuals regardless of race, colour, religion, age, gender, gender expression, national origin, veteran status, disability, orientation, or any other legally protected categories. If you have a need that requires accommodation, please email us at talentacquisition@willisre.com.

Head, Governance, Risk and Compliance (Head Security GRC) employer: Willis Re (UK) Limited

As a leading employer in the cybersecurity sector, we offer a dynamic work environment that fosters innovation and collaboration. Our commitment to employee growth is evident through comprehensive training programs and opportunities for advancement, all while providing competitive benefits including health and wellness support, generous leave policies, and a robust retirement plan. Located in New York, our culture prioritises accountability and continuous improvement, making it an ideal place for professionals seeking meaningful and rewarding careers in governance, risk, and compliance.

Willis Re (UK) Limited

Contact Details:

Willis Re (UK) Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Head, Governance, Risk and Compliance (Head Security GRC)

Tip Number 1

Network like a pro! Reach out to your connections in the cybersecurity field, especially those who are already in governance, risk, and compliance roles. A friendly chat can lead to insider info about job openings or even a referral.

Tip Number 2

Show off your expertise! Prepare a portfolio or presentation that highlights your experience with frameworks like NIST CSF and ISO 27001. This will help you stand out during interviews and demonstrate your hands-on knowledge.

Tip Number 3

Stay updated on industry trends! Follow relevant blogs, podcasts, and news sources to keep your knowledge fresh. Being able to discuss current events in cybersecurity during interviews shows you're passionate and engaged.

Tip Number 4

Apply through our website! We make it easy for you to find roles that match your skills. Plus, applying directly can sometimes give you an edge over other candidates. Don’t miss out!

We think you need these skills to ace Head, Governance, Risk and Compliance (Head Security GRC)

Governance, Risk and Compliance (GRC)
Cybersecurity Leadership
Policy Governance
Cyber Risk Management
Control Assurance
Audit Management
Regulatory Engagement

Some tips for your application 🫡

Tailor Your CV:Make sure your CV speaks directly to the role of Head, GRC. Highlight your experience in cybersecurity governance, risk management, and compliance, and don’t forget to mention any relevant frameworks like NIST CSF or ISO 27001.

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re the perfect fit for this role. Share specific examples of how you've led GRC initiatives and improved cyber risk management in previous positions.

Showcase Your Leadership Skills:As a senior leader, we want to see your ability to influence and communicate effectively with stakeholders. Include examples of how you've partnered with teams across the business to drive compliance and security initiatives.

Apply Through Our Website:We encourage you to apply through our website for a smoother application process. It’s the best way for us to receive your application and ensure it gets the attention it deserves!

How to prepare for a job interview at Willis Re (UK) Limited

Know Your Frameworks

Make sure you’re well-versed in cybersecurity frameworks like NIST CSF and ISO 27001. Be ready to discuss how you've applied these in past roles, as this will show your practical understanding and ability to align with the company's governance and compliance strategies.

Showcase Your Leadership Skills

As a senior leader, it’s crucial to demonstrate your experience in leading GRC programmes. Prepare examples of how you've influenced stakeholders and driven change in complex environments. This will highlight your strategic thinking and hands-on approach.

Communicate Clearly

Practice explaining technical concepts in simple terms. You’ll need to convey cyber risk and compliance issues to non-technical stakeholders, so being able to articulate these points clearly will set you apart from other candidates.

Prepare for Scenario Questions

Expect scenario-based questions that assess your problem-solving skills in real-world situations. Think about past challenges you've faced in governance, risk management, or compliance, and be ready to discuss how you navigated them successfully.