At a Glance
- Tasks: Lead cybersecurity governance, risk and compliance strategy while collaborating with key stakeholders.
- Company: Willis Re, a diverse and inclusive tech-driven organisation.
- Benefits: Competitive salary, comprehensive health benefits, flexible work options, and generous leave policies.
- Other info: Join a dynamic team focused on continuous improvement and career growth.
- Why this job: Make a significant impact in cybersecurity while shaping the future of risk management.
- Qualifications: 10 years in cybersecurity with strong knowledge of frameworks like NIST CSF and ISO 27001.
The predicted salary is between 110000 - 130000 £ per year.
The Head, GRC is a senior cybersecurity leader responsible for defining and operating the governance, risk and compliance strategy for the organization. This role partners closely with the CISO, technology leaders, legal, risk, compliance and business stakeholders to ensure cyber risk is governed effectively, regulatory obligations are met, and security controls are aligned to business priorities.
The role will lead policy and standards governance, cyber risk management, control assurance, audit, regulatory engagement, and third-party risk oversight while building a culture of accountability and continuous improvement. Key responsibilities include:
- Leading and continuously improving the cybersecurity GRC framework, operating model, governance forums and reporting cadence.
- Owning the lifecycle of cybersecurity policies, standards, procedures and exception management, ensuring alignment to business objectives and regulatory expectations.
- Establishing and maintaining a risk-based control environment aligned to recognized frameworks such as NIST CSF, ISO 27001 and other applicable regulatory requirements.
- Directing enterprise cyber risk assessments, risk treatment planning, control testing and issue remediation tracking.
- Overseeing internal and external audits, customer assurance activities and regulatory examinations related to information security and cyber controls.
- Partnering with legal, privacy, compliance and enterprise risk teams to interpret and operationalise changing cyber and data protection obligations.
- Overseeing third-party cyber risk governance, including due diligence, control reviews and ongoing monitoring of critical suppliers.
- Developing meaningful metrics, KRIs and executive reporting to communicate cyber risk posture, compliance status and remediation progress to senior leadership.
Company Benefits: Willis Re provides a competitive benefit package which includes Health and Welfare Benefits, Leave Benefits, and Retirement Benefits.
Compensation: The salary benchmark for this role is: US (New York): $220,000 - $250,000 - $280,000.
About You: You are a strategic and hands-on cybersecurity GRC leader who can translate regulatory, audit and risk requirements into practical actions for technology and business teams. You are comfortable operating at executive level while also driving program execution, control maturity and measurable outcomes. You bring strong judgement, clear communication and the ability to influence across complex stakeholder groups.
Proven experience leading cybersecurity governance, risk and compliance programs in a complex enterprise environment is essential. Strong knowledge of cybersecurity and control frameworks, including NIST CSF 2.0, ISO 27001, SOC 2 and relevant regulatory expectations is required. Demonstrated experience with cyber risk assessments, policy governance, control assurance, audit management and issue remediation is necessary. The ability to communicate cyber risk and control effectiveness in clear business terms to executives and non-technical stakeholders is crucial. Experience partnering with audit, enterprise risk, legal, privacy, procurement and technology teams is important. A minimum of 10 years of experience in cybersecurity, information security, information technology, risk management or a related field is expected. Relevant certifications such as CISM, CRISC or CISA are desirable.
About Willis Re: Willis Re is committed to embracing a diverse, inclusive, and flexible work environment. We provide equal opportunity to all qualified individuals regardless of race, colour, religion, age, gender, gender expression, national origin, veteran status, disability, orientation, or any other legally protected categories.
Head, Governance, Risk and Compliance (Head Security GRC) in London employer: Willis Re
Willis Re is an exceptional employer that fosters a diverse and inclusive work environment, offering competitive benefits such as comprehensive health coverage, generous leave policies, and a robust retirement plan. The company prioritises employee growth through continuous improvement initiatives and provides opportunities to engage with senior leadership on critical cybersecurity governance, risk, and compliance strategies, making it an ideal place for professionals seeking meaningful and rewarding careers in a dynamic field.
StudySmarter Expert Advice🤫
We think this is how you could land Head, Governance, Risk and Compliance (Head Security GRC) in London
✨Tip Number 1
Network like a pro! Reach out to your connections in the cybersecurity field, especially those who work in governance, risk, and compliance. A friendly chat can lead to insider info about job openings or even a referral.
✨Tip Number 2
Prepare for interviews by brushing up on your knowledge of frameworks like NIST CSF and ISO 27001. Be ready to discuss how you've applied these in past roles, as this will show you're not just familiar with the concepts but can also implement them effectively.
✨Tip Number 3
Showcase your leadership skills! When discussing your experience, highlight instances where you’ve led teams or initiatives in cybersecurity GRC. This will demonstrate your capability to operate at an executive level and drive program execution.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who take that extra step to connect directly with us.
We think you need these skills to ace Head, Governance, Risk and Compliance (Head Security GRC) in London
Some tips for your application 🫡
Tailor Your CV:Make sure your CV speaks directly to the Head, GRC role. Highlight your experience in cybersecurity governance, risk management, and compliance. Use keywords from the job description to show we’re on the same page!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Share your passion for cybersecurity and how your skills align with our needs. Don’t forget to mention your experience with frameworks like NIST CSF and ISO 27001.
Showcase Your Leadership Skills:We want to see your leadership style! Include examples of how you’ve led teams or projects in the past, especially in complex environments. This will help us understand how you can drive our GRC strategy forward.
Apply Through Our Website:Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team!
How to prepare for a job interview at Willis Re
✨Know Your Frameworks
Make sure you’re well-versed in cybersecurity frameworks like NIST CSF and ISO 27001. Be ready to discuss how you've applied these in previous roles, as this will show your practical understanding of the governance, risk, and compliance landscape.
✨Showcase Your Leadership Skills
As a senior leader, it’s crucial to demonstrate your ability to influence and lead teams. Prepare examples of how you've successfully driven GRC initiatives and improved control maturity in past positions. This will highlight your strategic mindset and hands-on approach.
✨Communicate Clearly
You’ll need to translate complex cyber risk concepts into business terms. Practice explaining technical details in a way that non-technical stakeholders can understand. This skill is vital for engaging with executives and ensuring alignment with business objectives.
✨Prepare for Scenario Questions
Expect scenario-based questions that assess your problem-solving skills in real-world situations. Think about challenges you've faced in governance or compliance and how you resolved them. This will showcase your critical thinking and decision-making abilities.