5 дней назад
Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) (Cybersecurity): Leading enterprise cybersecurity governance, risk management, accreditation, compliance, and data protection across UK operations with an accent on security controls, regulatory requirements, and classified information. Focus on assessing cyber risks, coordinating assurance activities, advising architecture and project governance forums, and delivering executive-level security reporting.
Location: Hybrid working based in Leatherhead or Swindon, United Kingdom
Company
delivers engineering, science, technology, and mission support solutions for government, defence, intelligence, space, aviation, and critical infrastructure customers.
What you will do
- Lead enterprise information security, data protection, privacy, and cybersecurity governance activities across UK operations.
- Manage risk assessments, security categorisation, waivers, exceptions, compliance, accreditation, and assurance activities.
- Coordinate penetration testing, audits, certification activities, security assessments, and third-party assurance.
- Provide cybersecurity expertise for network, infrastructure, enterprise security architecture, Architecture Review Boards, Change Control Boards, and project governance forums.
- Support incident response, formal investigations, privacy impact assessments, and the protection of OFFICIAL-SENSITIVE and classified information.
- Prepare executive-level briefings and reports on security risks, control effectiveness, compliance posture, and the overall security programme.
Requirements
- Security clearance: SC Clearance required.
- UK residency and nationality restrictions apply because of the secure nature of the project.
- Bachelor’s degree in Cybersecurity, Information Security, Information Assurance, Computer Science, Information Technology, or a related field; relevant experience may be considered instead.
- Experience leading information security initiatives in complex enterprise environments, including governance, risk management, compliance, accreditation, and security programme oversight.
- Knowledge of information security frameworks and standards, including ISO 27001 and NIST.
- Experience working with UK government, defence, or other highly regulated environments.
Nice to have
- Master’s degree in Cybersecurity, Information Security, or a related field.
- CISSP, CISM, CCSP, or an equivalent cybersecurity certification.
- Experience with accreditation, auditing, compliance, defence, aerospace, enterprise risk assessments, executive reporting, and technical documentation.
Culture & Benefits
- People-first environment built around the Belong, Connect and Grow philosophy.
- Zero Harm culture and focus on employee development and connection.
- Hybrid working arrangement.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →