on governance, oversight, and assurance, ensuring Onsi operates in line with best practices and applicable laws, particularly within cybersecurity, data protection, and operational risk. What you will do: Lead and support the implementation of key compliance and cybersecurity frameworks (e.g. UK GDPR, ISO27001, Cyber Essentials), while developing regulatory risk frameworks … management, information security, or cybersecurity governance - ideally within a regulated environment such as financial services or fintech. The ability to understand and apply regulatory frameworks (e.g. UK GDPR, ISO27001) and translate them into business-friendly policies, controls, and processes. Confidence working with regulatory frameworks like UK GDPR, ISO27001 … the discipline to manage your learning and growth. Desirable Qualifications and / or knowledge (any of the following): Certifications or practical experience as / in CISMP, CompTIA Security+, ISO27001LeadImplementer, CISM, CISSP, or PCI DSS QSA. Awareness of key regulations, including UK GDPR, Data Protection Act More ❯
Information Security Risk and Governance Lead Location: London or Lausanne Type: Full-time | Hybrid (3 days / week onsite) Company Overview Join a pioneering AI-first biotech company that’s redefining how we discover and develop medicines. This organisation leverages cutting-edge machine learning to unlock new possibilities in drug discovery, aiming to solve some of humanity … role offers a unique opportunity to architect and operationalise a best-in-class information security governance framework. Reporting directly to the Chief Information Security Officer (CISO), you will lead strategic efforts to embed security, trust, and regulatory readiness into a platform that supports world-leading biomedical research and drug design. You will play a pivotal role in … ML experimentation at scale. Key Responsibilities Design and implement a unified compliance framework across AI, cyber, and life sciences regulatory domains. Own and drive the strategic programme for ISO27001 certification and ongoing ISMS operations. Develop and maintain security policies and procedures, tailored for an AI-first, GxP-regulated organisation. LeadMore ❯
City of London, London, United Kingdom Hybrid / WFH Options
Hlx Life Sciences
Information Security Risk and Governance Lead Location: London or Lausanne Type: Full-time | Hybrid (3 days / week onsite) Company Overview Join a pioneering AI-first biotech company that’s redefining how we discover and develop medicines. This organisation leverages cutting-edge machine learning to unlock new possibilities in drug discovery, aiming to solve some of humanity … role offers a unique opportunity to architect and operationalise a best-in-class information security governance framework. Reporting directly to the Chief Information Security Officer (CISO), you will lead strategic efforts to embed security, trust, and regulatory readiness into a platform that supports world-leading biomedical research and drug design. You will play a pivotal role in … ML experimentation at scale. Key Responsibilities Design and implement a unified compliance framework across AI, cyber, and life sciences regulatory domains. Own and drive the strategic programme for ISO27001 certification and ongoing ISMS operations. Develop and maintain security policies and procedures, tailored for an AI-first, GxP-regulated organisation. LeadMore ❯
london, south east england, united kingdom Hybrid / WFH Options
Hlx Life Sciences
Information Security Risk and Governance Lead Location: London or Lausanne Type: Full-time | Hybrid (3 days / week onsite) Company Overview Join a pioneering AI-first biotech company that’s redefining how we discover and develop medicines. This organisation leverages cutting-edge machine learning to unlock new possibilities in drug discovery, aiming to solve some of humanity … role offers a unique opportunity to architect and operationalise a best-in-class information security governance framework. Reporting directly to the Chief Information Security Officer (CISO), you will lead strategic efforts to embed security, trust, and regulatory readiness into a platform that supports world-leading biomedical research and drug design. You will play a pivotal role in … ML experimentation at scale. Key Responsibilities Design and implement a unified compliance framework across AI, cyber, and life sciences regulatory domains. Own and drive the strategic programme for ISO27001 certification and ongoing ISMS operations. Develop and maintain security policies and procedures, tailored for an AI-first, GxP-regulated organisation. LeadMore ❯
london (city of london), south east england, united kingdom Hybrid / WFH Options
Hlx Life Sciences
Information Security Risk and Governance Lead Location: London or Lausanne Type: Full-time | Hybrid (3 days / week onsite) Company Overview Join a pioneering AI-first biotech company that’s redefining how we discover and develop medicines. This organisation leverages cutting-edge machine learning to unlock new possibilities in drug discovery, aiming to solve some of humanity … role offers a unique opportunity to architect and operationalise a best-in-class information security governance framework. Reporting directly to the Chief Information Security Officer (CISO), you will lead strategic efforts to embed security, trust, and regulatory readiness into a platform that supports world-leading biomedical research and drug design. You will play a pivotal role in … ML experimentation at scale. Key Responsibilities Design and implement a unified compliance framework across AI, cyber, and life sciences regulatory domains. Own and drive the strategic programme for ISO27001 certification and ongoing ISMS operations. Develop and maintain security policies and procedures, tailored for an AI-first, GxP-regulated organisation. LeadMore ❯
Information Security strategies and initiatives, focusing on supporting the Governance, Risk, and Compliance (GRC) function and implementing the NIST Cyber Security Framework (CSF) throughout the organization. You will lead day-to-day GRC activities, including designing security controls, enforcing requirements from the Group Information Security Framework, and proactively managing non-compliance issues and mitigating Information Security risks. … desirable. Proven track record of security transformation and delivery of security projects, particularly within a federated organisation. Strong knowledge of Information Security and compliance frameworks, including NIST CSF, ISO27001, Cyber Essentials, PCI DSS, and DORA, and the ability to design controls that align with these standards. Ability to analyse data and generate reports … Bachelor’s degree in Information Security, Computer Science, or a related field. A Master’s degree is a plus. Relevant certifications such as CISSP, CCSP, CRISC, CISM, or ISO27001LeadImplementer are highly desirable. More ❯
Information Security strategies and initiatives, focusing on supporting the Governance, Risk, and Compliance (GRC) function and implementing the NIST Cyber Security Framework (CSF) throughout the organization. You will lead day-to-day GRC activities, including designing security controls, enforcing requirements from the Group Information Security Framework, and proactively managing non-compliance issues and mitigating Information Security risks. … desirable. Proven track record of security transformation and delivery of security projects, particularly within a federated organisation. Strong knowledge of Information Security and compliance frameworks, including NIST CSF, ISO27001, Cyber Essentials, PCI DSS, and DORA, and the ability to design controls that align with these standards. Ability to analyse data and generate reports … Bachelor’s degree in Information Security, Computer Science, or a related field. A Master’s degree is a plus. Relevant certifications such as CISSP, CCSP, CRISC, CISM, or ISO27001LeadImplementer are highly desirable. More ❯
Information Security strategies and initiatives, focusing on supporting the Governance, Risk, and Compliance (GRC) function and implementing the NIST Cyber Security Framework (CSF) throughout the organization. You will lead day-to-day GRC activities, including designing security controls, enforcing requirements from the Group Information Security Framework, and proactively managing non-compliance issues and mitigating Information Security risks. … desirable. Proven track record of security transformation and delivery of security projects, particularly within a federated organisation. Strong knowledge of Information Security and compliance frameworks, including NIST CSF, ISO27001, Cyber Essentials, PCI DSS, and DORA, and the ability to design controls that align with these standards. Ability to analyse data and generate reports … Bachelor’s degree in Information Security, Computer Science, or a related field. A Master’s degree is a plus. Relevant certifications such as CISSP, CCSP, CRISC, CISM, or ISO27001LeadImplementer are highly desirable. More ❯
london (city of london), south east england, united kingdom
Sanderson
Information Security strategies and initiatives, focusing on supporting the Governance, Risk, and Compliance (GRC) function and implementing the NIST Cyber Security Framework (CSF) throughout the organization. You will lead day-to-day GRC activities, including designing security controls, enforcing requirements from the Group Information Security Framework, and proactively managing non-compliance issues and mitigating Information Security risks. … desirable. Proven track record of security transformation and delivery of security projects, particularly within a federated organisation. Strong knowledge of Information Security and compliance frameworks, including NIST CSF, ISO27001, Cyber Essentials, PCI DSS, and DORA, and the ability to design controls that align with these standards. Ability to analyse data and generate reports … Bachelor’s degree in Information Security, Computer Science, or a related field. A Master’s degree is a plus. Relevant certifications such as CISSP, CCSP, CRISC, CISM, or ISO27001LeadImplementer are highly desirable. More ❯
strategies. Identify, assess, and mitigate information security risks within Heat UK Work as part of the BA Customers & Solutions Security & Resilience team to implement policies, standards, and controls. Lead security risk assessments, audits, and compliance initiatives and promote security awareness and training programs tailored to business needs. Support business continuity planning and incident response, including participation in … translate security policies into actionable controls for IT / OT environments. Drive cybersecurity awareness and training tailored to business and OT users. Ensure compliance with industry regulations (e.g. ISO/IEC 62443, GDPR, etc). Company Description Vattenfall is a European energy company with approximately employees. For more than 100 years we have electrified industries, supplied … the fields of computer science, engineering or business informatics. Strong understanding of industrial control systems (ICS), SCADA, and business IT systems. Familiarity with cybersecurity frameworks (e.g., NIST CSF, ISO27001, IEC 62443). Relevant certificates for proof of competence are an advantage: CISSP, GICSO, CRISC CISM, CISA, ISO27001More ❯
we looking for? Strong experience delivering end-to-end security assurance in complex, fast-paced environments Broad knowledge of IT and security frameworks, regulations, and best practices (e.g., ISO27001, DPA, GDPR) Familiarity with security tools such as vulnerability scanners, SIEM, DDoS protection, remote access, authentication / authorisation technologies, and data loss prevention Understanding … risk to technical and non-technical stakeholders Self-driven, collaborative, and confident operating both independently and within teams Desirable Qualifications & Experience: Certifications such as CISSP, CISM, CISA, or ISO27001Lead Auditor /Implementer Knowledge of the NIST Cybersecurity Framework Experience with Smart Metering or highly regulated environments … and Public Key Infrastructure (PKI) Understanding of Hardware Security Modules (HSMs) About the DCC: At the DCC, we believe in making Britain more connected, so we can all lead smarter, greener lives. That desire to make a difference is what drives us every day and it wouldn't be possible without our people. Each person at the More ❯
exciting growth journey to become the UK's most loved retirement expert. Purpose We're looking for a Senior Data Protection Manager & Deputy Data Protection Officer to help lead and shape our organisation's data protection strategy. This is a key, business-facing role with significant responsibility, including supporting the Group DPO and providing strategic oversight across … privacy requirements into clear, practical advice. Key Accountabilities Support strategic data protection planning alongside the Group DPO, including representing the function in governance forums and during DPO absence. Lead day-to-day operations of the Data Protection Team, including workload management, team stand-ups, and quality assurance. Manage key privacy processes, including DPIAs, ROPAs, client rights requests … a team of 3-5 Data Protection Specialists Examples of Key Activities Engage regularly with stakeholders across meetings, steering committees, forums, and projects Act as the data protection lead on key initiatives and assess compliance with privacy controls Review and approve DPIAs, and oversee the accuracy of ROPAs Provide expert guidance on GDPR, data sharing, retention, and More ❯