Oxford, Oxfordshire, South East, United Kingdom Hybrid / WFH Options
Unipart
Head of Cybersecurity GovernanceRiskandCompliance Location: Mainly remote based working in the UK with travel to Oxford, Cowley (OX4 2GQ) occasionally Contract: Permanent Hours: Full time Salary: £70,000 per annum, plus car/car allowance Benefits: 33 days holiday, pension, life assurance, employee assistance programme, wellbeing support, and flexible benefits scheme About the Job As our Head … of Cybersecurity GovernanceRiskandCompliance youll work closely with business and technology teams, helping to articulate and communicate the InfoSec governance program, identify risks and evaluate and help implement controls and improvements. As part of your key responsibilities youll: Manage the day to day of the function and team Support the management of Information Security governance for the organisation … following skills and experience, but please apply if you think youd be able to perform well in this role! Excellent written and verbal communication skills Previous experience within a GRC function, IT Security/Cyber team, Internal Audit or an IT environment Hands on practical experience of ensuring full compliance with legal & regulatory frameworks including ISO 27001 Riskmanagement Strong More ❯
Reading, Berkshire, United Kingdom Hybrid / WFH Options
Deloitte LLP
you possess the following?: Proven related experience in cybersecurity riskmanagement in organizations of a similar scale. Experience in the identification and evaluation of risk, as well as using GRC tools and guidance developed for Risk mitigation. Practical knowledge of information security standards andrisk assessment frameworks such as ISO 27001, SOC 2, NIST 800-32 Strong knowledge of cyber More ❯
Guildford, Surrey, United Kingdom Hybrid / WFH Options
Deloitte LLP
you possess the following?: Proven related experience in cybersecurity riskmanagement in organizations of a similar scale. Experience in the identification and evaluation of risk, as well as using GRC tools and guidance developed for Risk mitigation. Practical knowledge of information security standards andrisk assessment frameworks such as ISO 27001, SOC 2, NIST 800-32 Strong knowledge of cyber More ❯
Tunbridge Wells, Kent, South East, United Kingdom Hybrid / WFH Options
Robert Walters Direct Sourcing EMEA
experts, to ensure our business commitments are delivered with quality and to expectation. Assessing new technology solutions Ensuring our non-functional requirements are met regarding performance, scalability, resilience, andGRC requirements (Information security, risk, industry regulation compliance) Helping to encourage collaboration and product ownership across developers and testers Ensuring continual shift of secure, quality and tested code activity left Working More ❯
East Grinstead, Sussex, United Kingdom Hybrid / WFH Options
Spectrum IT Recruitment
Identify and implement emerging technologies that enhance performance and security. Leadership & People Development Build and develop a high-performing, collaborative team culture. Support team members' personal and professional development. Governance, Risk & Compliance Maintain the infrastructure and security risk register, ensuring compliance with all relevant regulations and policies. Supplier & Stakeholder Management Manage supplier relationships to maximise service quality and value. Collaborate More ❯
East Grinstead, West Sussex, South East, United Kingdom Hybrid / WFH Options
Spectrum It Recruitment Limited
Identify and implement emerging technologies that enhance performance and security. Leadership & People Development Build and develop a high-performing, collaborative team culture. Support team members' personal and professional development. Governance, Risk & Compliance Maintain the infrastructure and security risk register, ensuring compliance with all relevant regulations and policies. Supplier & Stakeholder Management Manage supplier relationships to maximise service quality and value. Collaborate More ❯
Reading, Berkshire, United Kingdom Hybrid / WFH Options
Thames Water Utilities Limited
implementation of data classification methodologies to ensure appropriate protection based on sensitivity and importance. The role will be based in Reading and will report directly to the Head of Governance, RiskandCompliance, working to deliver the company's goals for a fit-for-purpose critical asset and classification framework. This is a role that requires independence, a proactive approach … riskmanagement practices. Desirable Technical Skills & Qualifications: Industry Certifications: Certifications such as CISSP, CISM, or CISA. Key Relationships & Interactions: CISO direct reports: Security Operations Manager, Security Architecture Manager, Security Governance Manager, Cyber Security Programme Manager, Cyber Resilience Manager CIO and CIO Direct Reports: Operational Technology, Enterprise Architects, PMO and Programme Delivery, Business Change and Engagement Key Business Stakeholders Service Owners More ❯
Winchester, Hampshire, United Kingdom Hybrid / WFH Options
Arqiva
Join our Cyber Security Team as a Governance, RiskandCompliance Analyst. If you have been involved in practical aspects of GRC including ISO270001, want to work with a team of dedicated professionals and are able to understand wider business impacts of GRC on a business, please read more and apply. Location We operate a flexible, hybrid working environment with … wellness and employee assistance programmes, gymflex, buy and sell annual leave, travel and dental insurance Work. Life. Smarter. Our commitment to a flexible and hybrid working culture As a GRC Analyst you will: Support the development and maintenance of our Information Security Management System (ISMS) including policies, objectives, andrisk assessments Assist with internal audits and help prepare for external More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Sanderson
gap analysis, remediation, certification readiness, and continual improvement. You'll collaborate with senior stakeholders across industries to deliver strategic advisory and hands-on implementation of information security governance, riskmanagement, andcompliance Key Responsibilities Lead ISO 27001 implementation projects from initial assessment through to certification Conduct gap analysis tailored to private sector risk profiles and commercial priorities Facilitate risk assessments More ❯
Eastleigh, Hampshire, United Kingdom Hybrid / WFH Options
Ageas
our security controls. Reporting into the Assurance and Architecture Manager, you will be responsible for supporting and operating the day-to-day activities relating to security, initiatives, controls andgovernance processes. This role is a combination of internal consultancy, change managementand assurance activities to provide confidence to the business that we are meeting our security goals. You will act … Support on the delivery of the Information Security assurance plan on an annual basis to confirm the ongoing effectiveness of security controls across the business. Work closely with our GRC team to provide input into company standards for them to deploy as governance, whilst then using the frameworks as a baseline for assurance checks. Conduct security assurance reviews and security … relevant certifications including ISO27001, CISMP, CISSP, knowledge of Data Protection/GDPR, Information Security Forum, CiiSec Understanding of information security controls in particular those relating to assurance, business process, governance, security riskand education Good analysis and decision-making skills, work well under pressure with excellent team working capabilities Excellent stakeholder management skills and the ability to engage with colleagues More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Morgan Philips Specialist Recruitment
and internal policies across multiple jurisdictions. You will implement compliance programs, monitor adherence, provide risk-based legal advice, and help shape a compliance-focused culture. Key Accountabilities: ComplianceandGovernance Ensure the organisation adheres to corporate governance standards, codes of conduct and relevant laws across all jurisdictions. Monitor regulatory developments and interpret their relevance and impact on the business, providing … not limited to anti-bribery and corruption, competition, whistleblowing, data protection and ethical conduct. Monitor adherence and manage internal reporting mechanisms by liaising with internal Global RiskandCompliance (GRC) function. Global Regulatory Compliance Ensure compliance with international legal and regulatory frameworks (e.g. GDPR, FCPA, local employment laws). Liaise with external counsel where jurisdiction-specific advice is needed with More ❯
Cyber Strategy Manager to lead the design and execution of cyber programmes for complex, large-scale clients. You'll work directly with C-level stakeholders, shaping cyber operating models, governance structures, and transformation initiatives. Key Responsibilities Own end-to-end delivery of cyber strategy and transformation engagements Define and execute security roadmaps, operating models, andrisk frameworks Lead teams delivering … GRC, cyber maturity, andcompliance workstreams Communicate with client execs (CISO, CTO, Audit) and manage internal delivery teams Contribute to business development, team mentorship, and capability growth What We're Looking For 5+ years in cybersecurity or cyber advisory Experience leading cyber transformation in a consulting or enterprise environment Deep understanding of frameworks: NIST, ISO27001, GDPR, NIS2, CAF Track record More ❯
Hemel Hempstead, Hertfordshire, South East, United Kingdom Hybrid / WFH Options
Sopra Steria Limited
It would be great if you had: Experience of domain separation. Certifications indicating experience of other ServiceNow modules such as Customer Service Management (CSM), Employee Workflow, Security Operations (SecOps), Governance, Risk, andCompliance (GRC), IT Operations Management (ITOM), or IT Asset Management (ITAM). If you are interested in this role but not sure if your skills and experience are More ❯
Basingstoke, Hampshire, England, United Kingdom Hybrid / WFH Options
Career Concept
Cyber Security and Cloud Resilience Analyst Hybrid working. 1-2 days per month in the office. Buzz words you should identify with: Cyber Security, GRC, AWS, DevOps, DevSecOps, Dockers, ISO27001, NIST, Cyber Essentials, CISSP, Technical Architecture Work for a Not-for-Profit compliance company working in the green sector. Responsible for: 1) Cyber Security governanceand delivery across the company … and their suppliers. Covering: Governance, threat detection, reports, SIEM, DevSecOps 2) Cloud Architecture and Resilience. AWS estate and the platform applications. Assessment of riskand resilience. AWS cloud costs, technical debt, overview of architecture. This is not a technical hands-on position (other than maybe some config and creation of threat reports). However, you will need a technical background More ❯
Reading, Oxfordshire, United Kingdom Hybrid / WFH Options
Project People
Manager Reading - Hybrid working Permanent Are you passionate about embedding a culture of complianceand integrity across an organisation? We're looking for a Compliance Manager to join our Governance, Risk, andCompliance (GRC) function. Reporting to the Lead GRC, you'll play a key role in shaping and evolving our compliance framework while ensuring the business operates in line More ❯
Worting, Basingstoke, Hampshire, England, United Kingdom Hybrid / WFH Options
InfoSec People Ltd
supports both public and private sector clients across a range of industries, helping them understand their security risks and maintain compliance with evolving regulations. Their services include security consultancy, GRC support, and accreditation for information systems. As part of a close-knit and collaborative commercial team, the successful candidate will take ownership of the technical components of proposals and contribute … technical content for bids, particularly in a Cyber Risk environment. Understanding of UK public sector procurement and frameworks (e.g. MOD, government clients) Prior experience in cyber security, ideally with GRC knowledge Excellent written and verbal communication skills, able to translate complex concepts for different audiences Strong attention to detail and ability to manage multiple bids simultaneously Comfortable using Microsoft Office More ❯