Head of Cyber Security Governance, Risk and Compliance

7 days ago


London, Greater London, United Kingdom BAE Systems Full time

Job Title: Head of Cyber Security Governance, Risk and Compliance (GRC)

Location: London, Frimley, or Preston (Other BAE sites can be considered), we offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role.

Salary: £90,000 + depending on skills and experiences plus executive benefits

What you'll be doing:

Being the line manager of the Group Cyber Security GRC Team. This team is expected to protect BAE Systems and ensure contractual compliance through activities not limited to:

  • Setting policies, monitoring compliance, and following defined procedures to identify, assess and manage risks from external and internal threats
  • Maintaining a risk register of relevant cyber security risks
  • Proposing measures - including avoidance, mitigation, sharing and acceptance - to manage cyber security risks in alignment with the company risk appetite
  • Implementing and maintaining Cyber Security Standards and the Cyber Security Assurance Framework
  • Managing the Cyber Security Governance Framework to ensure transparency, accuracy and speed of decision making
  • Assuring the implementation, operation, and maintenance of security controls
  • Assessing the correctness of our cyber security risk assessments and risk management plans, taking account our business goals and compliance obligations
  • Reviewing compliance with legal and regulatory requirements, managing the relationships with key regulatory stakeholders including MOD Cyber Defence & Risk (CyDR)Providing expert advice on governance, assurance, and risk management
  • Prioritising the closure of findings on a risk informed basis
  • Sponsoring GRC capability development, keeping current capabilities relevant, effective, efficient, and anticipating future needs
  • Providing oversight and guidance to wider technology assurance activities, ensuring alignment across Digital, Data and Cyber Security in both IT and Operational Technology domains

Your skills and experiences:

Essential:

  • Business Knowledge and Experience
  • Cyber Security Expert, understanding across a range of cyber security disciplines including GRCExpert understanding of the security paradigm of both IT and OT systems
  • Legal and Regulatory experience of the requirements for handling Government classified data, Export Controls and PII

Desirable:

  • Hold a number of compliance framework related certifications (e.g., ISO or NIST)Capable of achieving UK Cyber Security Council chartered status

Benefits:

You'll receive benefits including a competitive pension scheme, enhanced annual leave allowance and a Company contributed Share Incentive Plan. You'll also have access to additional benefits such as flexible working, an employee assistance programme, Cycle2work and employee discounts - you may also be eligible for an annual incentive.

The team:

The team has gone through a large transformation. In order to maintain stability and promote the improvement and integration of the new core processes (such as Secure by Design), leadership is now required.

As the Head of Cyber Security Governance, Risk and Compliance (GRC) you will lead Cyber Security GRC in BAE Systems (UK & International, excluding BAE Systems Inc.), advising the CISO, and other senior leaders, on all matters related to Cyber Security GRC, providing the necessary leadership and management of GRC capabilities (people, processes, tools, supporting contracts and services etc) to enable them to be effective and efficient and to provide senior leadership with the confidence that Cyber Security GRC in BAE Systems is appropriate and robust.

This role provides you will global exposure giving you the opportunity to develop and enhance your skills and knowledge.

Why BAE Systems?

This is a place where you'll be able to make a real difference. You'll be part of an inclusive culture that values diversity, rewards integrity, and merit, and where you'll be empowered to fulfil your potential.

We welcome candidates from all backgrounds and particularly from sections of the community who are currently underrepresented within our industry, including women, ethnic minorities, people with disabilities and LGBTQ+ individuals.

We also want to make sure that our recruitment processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments.

Please be aware that many roles working for BAE Systems will be subject to both security and export control restrictions. These restrictions mean that factors including your nationality, any previous nationalities you have held, and your place of birth may limit those roles you can perform for the organisation.

Closing Date: 28th June 2024

We reserve the right to close this vacancy early if we receive sufficient applications for the role. Therefore, if you are interested, please submit your application as early as possible.



  • London, Greater London, United Kingdom BAE Systems Full time £90,000

    Job Description - Head of Cyber Security Governance, Risk and Compliance (GRC Head of Cyber Security Governance, Risk and Compliance (GRC Job Title: Head of Cyber Security Governance, Risk and Compliance (GRC) Location: London, Frimley, or Preston (Other BAE sites can be considered), we offer a range of hybrid and flexible working arrangements - please...


  • London, Greater London, United Kingdom Workingmums Full time

    Job Title: Head of Cyber Security Governance, Risk and Compliance (GRC)Location: London, Frimley, or Preston (Other BAE sites can be considered), we offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role.Salary: £90,000 + depending on skills and experiences plus executive...


  • London, Greater London, United Kingdom Lifeways Full time £90,000

    Head of Cyber Security and Information Governance Location: Home based with UK travel as required The Lifeway's Group is one of the UK's leading providers of specialist support services for people with complex needs. We are striving to be revolutionary in our sector and currently on a transformational journey to become the Care Provider of Choice by through...


  • London, Greater London, United Kingdom Direct Line Group Full time

    About usWe are Direct Line Group - home to some of the country's best-known brands including Direct Line, Churchill, Privilege, Greenflag and NIG. Our vision is to create a world where insurance is personal, inclusive, and a force for good, and our purpose is to help people carry on with their lives, giving them peace of mind now and in the future.DLG is at...


  • London, Greater London, United Kingdom Oliver James Full time

    Cyber Governance, Risk and Compliance Manager - FTCOliver James have been appointed to recruit a Cyber Governance, Risk and Compliance Manager for a specialty Insurance business. They are looking for the Cyber Governance, Risk and Compliance Manager to establish a control framework over security threats,as well as operationalise control assessments.Key...


  • London, Greater London, United Kingdom eFinancialCareers Full time

    Technology / Cyber Governance, Risk and Compliance Manager12 month Fixed term contractExciting opportunity to join a leading insurer in the city of London as a Technology / Cyber Governance, Risk and Compliance Manager. If you have experience on the development/implementation of technology risk framework and processes this could be the idealrole for you.This...


  • London, Greater London, United Kingdom Technet IT Recruitment Limited Full time

    Cyber Security Compliance ManagerRemote UKUp to £55,000We are currently working with a well-known arm of the government within the public sector. A Cyber Security Compliance Manager is responsible for the confidentiality and integrity of business assets, improving compliance, security risk management, and adherencewith technology policies.The role will...


  • London, Greater London, United Kingdom The McLean Partnership Full time

    Our client is a leading financial services organisation employing c1,000 staff across a number of key global office locations. The majority of headcount is situated in London and the organisation is part of a larger global financial services organisation employing 45,000 staff in the U.S and across major financial services hubs worldwide. The CISO (Head of...


  • London, Greater London, United Kingdom Head Resourcing Full time

    Cyber Security Consultant Up to £55,000 + benefits (including 10% bonus) Head Resourcing is looking for a Cyber Security Consultant to join one of Scotland's biggest success stories. This role will be worked on a hybrid basis in Glasgow and will be working closely with our clients third-party suppliers and internal stakeholders to ensure all security...


  • London, Greater London, United Kingdom Blinx Technology Ltd Full time

    The Role Position: Cyber Security Governance Manager Contract Type: Full-Time Reporting To: Group Cyber Security Officer Location: London About the Role The role will be responsible for a number of activities and take ownership of the continued improvement of cybersecurity capabilities on behalf of the Group Cyber Security Officer. The role will liaise with...

  • Governance, Risk

    7 days ago


    London, Greater London, United Kingdom LegalAndGeneral Full time

    Security Governance, Risk & Compliance Manager Legal & General are a leading UK financial services provider, offering life insurance, pensions, retirement and investment services. Helping over ten million people around the world manage their savings, retirement plans and life insurance requires a lot of people behind-the-scenes. It's up to us in L&G Group...


  • London, Greater London, United Kingdom Partners Capital Full time

    London- Job Description:The key purpose of this role is to create and support a robust Information Security programme and framework. You will focus on core areas such as risk management, data governance, third-party security due-diligence reviews, ensuring compliance with legal, regulatory, and relevant security standards such as ISO 27001.The role requires...


  • London, Greater London, United Kingdom King's College Hospital NHS Foundation Trust Full time

    The ICT Head of Cyber Security will act as the Trust's expert on cyber security protection, detection, response, and recovery. The ICT Head of Cyber Security will be responsible for the strategic approach to cyber threat management, the strategic planning of current and future IT security solutions. The post holder will manage, support and develop the Trust...


  • London, Greater London, United Kingdom ubs Full time

    Information Technology (IT)Full TimeDo you have a strong technical cyber security background? Do you have proven experience in cyber risk governance?We're looking for a Cyber Security Risk Governance Specialist to:serve as a subject matter expert in a number of Cyber and Information Security (CIS) domains and capabilities, providing active risk oversight for...


  • London, Greater London, United Kingdom ASOS Full time

    Company DescriptionWe're ASOS. We blend our flair for fashion with our love of cutting- edge technology, but more importantly were interested in how we can bring the best out of you.We exist to give people the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you're free to be your true self without judgment, and channel...


  • London, Greater London, United Kingdom Blinx Technology Ltd Full time

    Cyber Security Governance Manager Contract Type: Full-Time Reporting To: Group Cyber Security Officer The role will be responsible for a number of activities and take ownership of the continued improvement of our cybersecurity capabilities on behalf of the Group Cyber Security Officer. This is an opportunity for the successful candidate to shape...


  • London, Greater London, United Kingdom InfraView Ltd Full time £110,000

    Head of Cyber Security in a Leading Company in LondonThis is a fantastic opportunity to join a dynamic team as the Head of Cyber Security in a London-based company. The salary for this position is GBP110,000 plus a bonus.Key Responsibilities:Take complete ownership of the Cyber practiceBuild, develop, and shape the Security practiceDefine a strategy aligning...


  • London, Greater London, United Kingdom UBS Full time

    Your role Do you have a strong technical cyber security background? Do you have proven experience in cyber risk governance? We're looking for a Cyber Security Risk Governance Specialist to: serve as a subject matter expert in a number of Cyber and Information Security (CIS) domains and capabilities, providing active risk oversight for these areas ...


  • London, Greater London, United Kingdom Lifeways Group Full time £90,000

    Head of Cyber Security and Information GovernanceSalary: Up to £90kLocation: Home based with UK travel as requiredA Chance to Shape the Future at Lifeways GroupThe Lifeways Group is revolutionizing the way it provides support services for individuals with complex needs. We are on a transformative journey to becoming the Care Provider of Choice by...

  • Security Governance

    1 week ago


    London, Greater London, United Kingdom Arc IT Recruitment Full time

    About the Job:Are you passionate about Security Governance & Data Management? A renowned financial services company is looking for a Security Governance & Data Management Lead to join their team. In this role, you will play a key part in developing, implementing, and maintaining the organization's security governance framework and data protection policies....