At a Glance
- Tasks: Lead cybersecurity governance, risk and compliance strategy while collaborating with key stakeholders.
- Company: Join a forward-thinking organisation prioritising cybersecurity and compliance.
- Benefits: Comprehensive health benefits, generous leave policies, and retirement plans.
- Other info: Diverse and inclusive workplace with opportunities for professional growth.
- Why this job: Make a significant impact on cybersecurity strategy and drive organisational change.
- Qualifications: 10 years in cybersecurity with strong knowledge of GRC frameworks.
The predicted salary is between 110000 - 140000 £ per year.
The Head, GRC is a senior cybersecurity leader responsible for defining and operating the governance, risk and compliance strategy for the organization. This role partners closely with the CISO, technology leaders, legal, risk, compliance and business stakeholders to ensure cyber risk is governed effectively, regulatory obligations are met, and security controls are aligned to business priorities.
The role will lead policy and standards governance, cyber risk management, control assurance, audit and regulatory engagement, and third-party risk oversight while building a culture of accountability and continuous improvement.
- Lead and continuously improve the cybersecurity GRC framework, operating model, governance forums and reporting cadence.
- Own the lifecycle of cybersecurity policies, standards, procedures and exception management, ensuring alignment to business objectives and regulatory expectations.
- Establish and maintain a risk-based control environment aligned to recognized frameworks such as NIST CSF, ISO 27001 and other applicable regulatory requirements.
- Direct enterprise cyber risk assessments, risk treatment planning, control testing and issue remediation tracking.
- Oversee internal and external audits, customer assurance activities and regulatory examinations related to information security and cyber controls.
- Partner with legal, privacy, compliance and enterprise risk teams to interpret and operationalize changing cyber and data protection obligations.
- Oversee third-party cyber risk governance, including due diligence, control reviews and ongoing monitoring of critical suppliers.
- Develop meaningful metrics, KRIs and executive reporting to communicate cyber risk posture, compliance status and remediation progress to senior leadership.
Company Benefits:
- Health and Welfare Benefits: Medical, Dental, Vision, Health Savings Account, Commuter Benefits, Health Care and Dependent Care Flexible Spending Accounts, Accident Insurance, Critical Illness Insurance, Life Insurance, AD&D, Financial wellbeing support, Wellbeing Program and Work/Life Resources (including Employee Assistance Program).
- Leave Benefits: Paid Holidays, Annual Paid Time Off (includes paid state/local paid leave where required), Short-Term Disability, Long-Term Disability, Other Leaves (e.g., Bereavement, FMLA, ADA, Jury Duty, Military Leave, and Parental and Adoption Leave), Paid Time Off (Washington State only).
- Retirement Benefits: Salvage Plan (401k).
Compensation: The salary benchmark for this role is US (New York): $220,000 – $250,000 – $280,000.
About You: You are a strategic and hands-on cybersecurity GRC leader who can translate regulatory, audit and risk requirements into practical actions for technology and business teams. You are comfortable operating at executive level while also driving program execution, control maturity and measurable outcomes. You bring strong judgment, clear communication and the ability to influence across complex stakeholder groups.
- Proven experience leading cybersecurity governance, risk and compliance programs in a complex enterprise environment.
- Strong knowledge of cybersecurity and control frameworks, including NIST CSF 2.0, ISO 27001, SOC 2 and relevant regulatory expectations.
- Demonstrated experience with cyber risk assessments, policy governance, control assurance, audit management and issue remediation.
- Ability to communicate cyber risk and control effectiveness in clear business terms to executives and non-technical stakeholders.
- Experience partnering with audit, enterprise risk, legal, privacy, procurement and technology teams.
- 10 years of experience in cybersecurity, information security, information technology, risk management or a related field.
- Relevant certifications such as CISM, CRISC or CISA are desirable.
We provide equal opportunity to all qualified individuals regardless of race, colour, religion, age, gender, gender expression, national origin, veteran status, disability, orientation, or any other legally protected categories. If you have a need that requires accommodation, please email us at.
Head, Governance, Risk and Compliance (Head Security GRC) in London employer: Willis Re (UK) Limited
As a leading employer in the cybersecurity sector, we offer a dynamic work environment that fosters innovation and collaboration. Our commitment to employee well-being is reflected in our comprehensive benefits package, which includes health and welfare benefits, generous leave policies, and robust retirement plans. Located in New York, we provide ample opportunities for professional growth and development, ensuring that our team members are equipped to excel in their roles while contributing to a culture of accountability and continuous improvement.
StudySmarter Expert Advice🤫
We think this is how you could land Head, Governance, Risk and Compliance (Head Security GRC) in London
✨Tip Number 1
Network like a pro! Reach out to your connections in the cybersecurity field, especially those who are already in governance, risk, and compliance roles. A friendly chat can lead to insider info about job openings or even a referral.
✨Tip Number 2
Show off your expertise! Attend industry events, webinars, or workshops related to GRC. Not only will you learn something new, but you'll also meet potential employers and make a lasting impression.
✨Tip Number 3
Tailor your approach! When reaching out to companies, including us at StudySmarter, make sure to highlight your experience with frameworks like NIST CSF and ISO 27001. Show how your skills align with their needs and values.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining our team and contributing to our mission.
We think you need these skills to ace Head, Governance, Risk and Compliance (Head Security GRC) in London
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in governance, risk, and compliance. We want to see how your skills align with the specific requirements of the Head, GRC role.
Showcase Your Leadership Skills:As a senior cybersecurity leader, it's crucial to demonstrate your ability to lead teams and influence stakeholders. Share examples of how you've successfully managed GRC initiatives and driven change in previous roles.
Be Clear and Concise:When writing your application, keep it straightforward and to the point. Use clear language to explain your experience and achievements, making it easy for us to see your fit for the role.
Apply Through Our Website:We encourage you to submit your application through our website. This ensures that your application is reviewed promptly and gives you the best chance to stand out in the process!
How to prepare for a job interview at Willis Re (UK) Limited
✨Know Your Frameworks
Make sure you’re well-versed in cybersecurity frameworks like NIST CSF and ISO 27001. Be ready to discuss how you've applied these in previous roles, as this will show your practical understanding of the governance, risk, and compliance landscape.
✨Speak Their Language
When discussing cyber risk and compliance, use clear business terms that resonate with non-technical stakeholders. Practice explaining complex concepts simply, as this will demonstrate your ability to bridge the gap between technical and executive teams.
✨Showcase Your Leadership Skills
Prepare examples of how you've led GRC initiatives in the past. Highlight your experience in driving program execution and improving control maturity, as this role requires a strategic leader who can influence across various stakeholder groups.
✨Prepare for Scenario Questions
Expect scenario-based questions that assess your problem-solving skills in real-world situations. Think about past challenges you've faced in cybersecurity governance or risk management, and be ready to explain your thought process and the outcomes.