Cambridge, Cambridgeshire, United Kingdom Hybrid / WFH Options
Cambridge University Press & Assessment (CUPA)
Head of Security Governance, Risk & Compliance Salary: £70,400 - £94,100 Location: Cambridge/Hybrid Minimum 2 days a week in the office Contract: Permanent The Head of Security GRC is a senior leadership role within the Security SMT, tasked with driving the organisation's security governance, risk, and compliance strategy. This position engages across all levels of … the business, ensuring regulatorycompliance, effective risk management, and robust assurance processes to support decision-making by the Senior Leadership Team. You will deliver a robust Security Assurance Framework, oversee supplier assurance activities, and maintain relevant ISO and Cyber Essentials certifications. Additionally, you'll drive the implementation of security standards, policies, governance reporting, and audit programmes to ensure … academic publisher and assessment organisation and a proud part of the University of Cambridge. About the role The position involves engaging at all organisational levels, managing security risks, ensuring regulatorycompliance, and providing assurance on business practices to support informed decisions by the Senior Leadership Team and Security Board. Responsibilities include implementing and monitoring security standards, policies, AI More ❯
Cambridge, Cambridgeshire, United Kingdom Hybrid / WFH Options
Cambridge University Press
Job Title: Head of Security Governance, Risk & Compliance Salary: £70,400 - £94,100 Location: Cambridge/Hybrid Minimum 2 days a week in the office Contract: Permanent The Head of Security GRC is a senior leadership role within the Security SMT, tasked with driving the organisation's security governance, risk, and compliance strategy. This position engages across all … levels of the business, ensuring regulatorycompliance, effective risk management, and robust assurance processes to support decision-making by the Senior Leadership Team. You will deliver a robust Security Assurance Framework, oversee supplier assurance activities, and maintain relevant ISO and Cyber Essentials certifications. Additionally, you'll drive the implementation of security standards, policies, governance reporting, and audit programmes … academic publisher and assessment organisation and a proud part of the University of Cambridge. About the role The position involves engaging at all organisational levels, managing security risks, ensuring regulatorycompliance, and providing assurance on business practices to support informed decisions by the Senior Leadership Team and Security Board. Responsibilities include implementing and monitoring security standards, policies, AI More ❯
Watford, Hertfordshire, United Kingdom Hybrid / WFH Options
Wickes
experience in implementing significant change - including new products or platforms. You'll have good judgement, a sense of urgency and will have demonstrated commitment to high standards of ethics, regulatorycompliance, customer service and business integrity. Being a critical thinker, a strong problem-solving with excellent trouble-shooting skills, self-motivated and possessing of a high sense of More ❯
Cambourne, Cambridgeshire, United Kingdom Hybrid / WFH Options
Remotestar
about building world-class KYC and onboarding experiences for high-growth digital platforms. In this role, you'll own the strategy and delivery of seamless, compliant onboarding flows, balancing regulatory requirements with an exceptional user experience. You'll work closely with engineering, UX, compliance and business stakeholders to define, prioritise, and deliver scalable solutions that accelerate customer activation. … such as Onfido, Alloy, Jumio, or equivalent . Design onboarding journeys that minimise drop-off and increase activation rates, leveraging data to optimise flows. Ensure all workflows meet relevant regulatorycompliance (GDPR, LGPD, local ID laws). Work with UX to build frictionless, brand-consistent user experiences. Define success metrics (activation, conversion, time to onboard) and drive improvements … and scalability. Proven experience managing KYC, onboarding or similar regulated web application products (fintech, trading platforms, digital banks, e-commerce with AML requirements). Skilled at integrating 3rd-party compliance or identity platforms (Onfido, Alloy, Trulioo, etc). Excellent understanding of building user journeys to maximise conversion and reduce drop-offs. Familiar with global data privacy frameworks (GDPR, LGPD More ❯
Watford, Hertfordshire, England, United Kingdom Hybrid / WFH Options
Addition
benefits Industry: Energy & Utilities What You’ll Be Doing: Own and evolve the company-wide data strategy, aligning with business and IT goals. Lead data governance policies and ensure regulatorycompliance, including GDPR. Manage a cross-functional network of data specialists across departments. Collaborate with IT to design scalable data infrastructure and select the right tools. Champion data … stakeholder communication, translating complex insights simply and clearly. Comfortable juggling multiple initiatives with an eye on long-term value. Experience in energy/utilities, particularly with meter data or regulatory reporting, is a plus. What’s in It for You: Competitive pay and profit-sharing scheme. Enhanced pension and private medical cover. Generous holiday package including your birthday off. More ❯
Cambridge, Cambridgeshire, United Kingdom Hybrid / WFH Options
AVEVA Denmark
for security and increase the maturity of existing processes and systems. One area of focus of this 12 month work package is to improve transparency of security operations and compliance to customers. We will be improving our Trust Centre, and streamlining security engagement on customer contracts. The post holder will be expected to quickly integrate into the team, proactively … to monitor and report effectiveness of risk management within the product development lifecycle and supply chain. Ability to Gather and Review Evidence For Compliance. Complete discovery investigations to demonstrate compliance to regulations, standards and customer requirements and present evidence in a consumable format for customers, regulators etc. Implementation of Security Control Systems. Provide subject matter expert knowledge to business … thought leadership on risk best practice and assurance to technical and non-technical stakeholders. Essential requirements Experience . Preferable 7+ years relevant work experience in security governance, risk, and compliance with at least 3 years of working as a senior expert or manager of a significant department. Experience of fulfilling similar role in a software publishing or internet business More ❯
Loughton, Essex, South East, United Kingdom Hybrid / WFH Options
Profile 29
from Office (WFO) role. This role will focus on creating a business strategy, gap analysis and implementation, for securing their Azure-based infrastructure, integrating security automation, ensuring PCI DSS compliance, vulnerability and penetration testing and incident response. This role will focus on developing and maintaining secure, scalable Azure DevOps pipelines and Infrastructure as Code (IaC) using Terraform. Their ideal … Web Application Firewalls (WAF) and Intrusion Prevention Systems (IPS). Vulnerability & Penetration Testing: Review Penetration Testing, vulnerability assessments, and security scanning to proactively identify and remediate risks. PCI DSS Compliance: Conduct security audits, risk assessments, and ensure regulatory compliance. DNS Security: Implement and monitor DNS security solutions to prevent cyber threats. Incident Response: Formulating and documenting a solid … WAF, IPS, and DNS security solutions. Extensive experience with Terraform for IaC security automation. Knowledge of DevOps pipelines (CI/CD) and security hardening. Deep understanding of PCI DSS compliance, security frameworks, and audit processes. Familiarity with SIEM solutions, security orchestration platforms, and log management. Strong experience with incident response planning, threat detection, and mitigation. Ability to define security More ❯
Loughton, Essex, England, United Kingdom Hybrid / WFH Options
Profile 29
from Office (WFO) role. This role will focus on creating a business strategy, gap analysis and implementation, for securing their Azure-based infrastructure, integrating security automation, ensuring PCI DSS compliance, vulnerability and penetration testing and incident response. This role will focus on developing and maintaining secure, scalable Azure DevOps pipelines and Infrastructure as Code (IaC) using Terraform. Their ideal … Web Application Firewalls (WAF) and Intrusion Prevention Systems (IPS). Vulnerability & Penetration Testing: Review Penetration Testing, vulnerability assessments, and security scanning to proactively identify and remediate risks. PCI DSS Compliance: Conduct security audits, risk assessments, and ensure regulatory compliance. DNS Security: Implement and monitor DNS security solutions to prevent cyber threats. Incident Response: Formulating and documenting a solid … WAF, IPS, and DNS security solutions. Extensive experience with Terraform for IaC security automation. Knowledge of DevOps pipelines (CI/CD) and security hardening. Deep understanding of PCI DSS compliance, security frameworks, and audit processes. Familiarity with SIEM solutions, security orchestration platforms, and log management. Strong experience with incident response planning, threat detection, and mitigation. Ability to define security More ❯