Head of Information Security Governance, Risk and Compliance
2 weeks ago
- Leads the improvement and enforcement of enterprise-wide Information Security Policies and Standards, including technical standards.
- Manages the UK Business Information Security Officer to support GRC and awareness activities across the UK businesses, as well as the governance of the wider European teams in the Netherlands and Mainland Europe business units.
- Maintains and develops Information Security Management System in line with ISO27001.
- Drives organisation-wide security governance and cyber maturity through standards compliance, assurance reviews, and gap analysis, be that Arriva policies and standards or industry recognised certifications such as ISO/IEC 27001, Cyber Essentials, NIS CAF, NIST CSF, CIS Controls.
- Oversees the development of a scalable Operational Technology (OT) Security Assurance Framework, including the management of day to day activities of the Operational Technology Compliance Manager.
- Develops and implements the enterprise Information Security Risk Methodology, including owning the Information Security, ensuring residual risk declarations are completed, prioritised, reviewed, and remediated with accountable stakeholders.
- Manages the third party due diligence process, including subject matter expertise in technical security requirements, supporting the on boarding of new suppliers, as well as the ongoing assessment of existing suppliers, including contract reviews with support from the data protection team.
- Leads key technical assurance activities such as the Arriva UK annual penetration test and red teaming exercises, working with Technology and Systems and the business, where appropriate, to ensure critical, high and medium risk findings are remediated.
- Provides IT audit support, including evidence coordination, control validation, and remediation planning.
- Leads assurance and compliance monitoring across information technology systems to include system security, malware Protection, network and endpoint security, cloud security and identity and access management activities.
- Improves and manages the Group-level Information Security Awareness Programme, including training strategy, annual compliance training content, communications plan, roadshows, and ongoing engagement.
- Practitioner qualifications e.g. CISSP certification, CESG Listed Advisor (CLAS), ISO27001 Lead Auditor, Certified Information Security Manager (CISM) Knowledge of all areas of Cyber Security
- Evidencable extensive experience in information security or IT governance roles, including proven experience working in large, federated, and complex enterprise environments.
- Experience developing and maintaining security policies, standards, and risk management frameworks, including experience in managing third-party risk.
- Track record of successful security awareness campaigns, measurable cultural change, and increased risk literacy across organisations.
- Familiarity with audit lifecycles, regulatory compliance, control assurance, and data protection including a deep understanding of security control frameworks (e.g., ISO/IEC 27001, Cyber Essentials, NIS CAF, NIST CSF, CIS Controls, PCI-DSS).
- Knowledge of all areas of IT Security, including cyber security for digital technologies, identity and access management, authentication and single sign-on, authorisation, logging and monitoring, audit, secure communications and cryptographic services, network and endpoint protection, hosting and cloud, vulnerability management, platform security, and systems development lifecycle.
- Provides clear vision and direction, inspiring and engaging individuals and the wider team to deliver excellence.
- Written and verbal communication and presentation skills. Influencing and negotiating skills.
- Possesses a proactive and solution-focused attitude, being capable of analysing business problems and delivering real solutions.
- Experience supporting IT audits and regulatory inspections.
- Group, divisional, and country business colleagues in Arriva
- Group, divisional, and country technology colleagues in Arriva
- External industry and security experts
- External consultants and suppliers
- Data Protection Authorities (UK and Europe)
- Internal and external risk, compliance, and audit teams
- Third party training providers and internal communications teams
-
London, Greater London, United Kingdom Arriva Group Full time £60,000 - £120,000 per yearArriva is a leading European passenger transport partner, operating in 11 countries across the UK and Europe. The company employs around 35,000 people, delivering more than 1.5 billion passenger journeys connecting people and communities safely, reliably and sustainably.We have strong roots dating back to 1938, an ambitious growth and sustainability agenda,...
-
London, Greater London, United Kingdom London Borough of Redbridge Full time £70,000 - £85,000 per yearPermanent –Full TimeLocation:Hybrid (Lynton House, Ilford, with flexible working)*About The Role*Are you passionate about data protection, compliance, and driving a culture of information security? We are seeking an experienced and visionary Head of Information Governance and Compliance to lead our Information Governance team and ensure the Council's...
-
London, Greater London, United Kingdom GWP Full time £60,000 - £120,000 per yearWhy work for us?A career at Janus Henderson is more than a job, it's about investing in a brighter future together. Our Mission at Janus Henderson is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service. We will do this by protecting and growing our core business,...
-
London, Greater London, United Kingdom Janus Henderson Investors Full time £60,000 - £120,000 per yearWhy work for us?A career at Janus Henderson is more than a job, it's about investing in a brighter future together.Our Mission at Janus Henderson is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service. We will do this by protecting and growing our core business,...
-
Head of Information Security
2 weeks ago
London, Greater London, United Kingdom Clayton Davies Full time £100,000 - £150,000 per yearHead of Information SecurityBirmingham, Reading or LondonCompetitive SalaryOur client is a leading organisation in the financial services industry, committed to innovation, integrity, and excellence in everything we do. With a growing national presence and an unwavering focus on protecting our clients' trust, they are seeking an exceptional Head of...
-
Head of Information Security
5 days ago
London, Greater London, United Kingdom Diesta Full time £80,000 - £120,000 per yearAbout Diesta:Diesta is building the next-generation payment processor for the global insurance industry. We are a fast-growing startup solving complex data challenges for top-tier insurers and brokers across the UK, EU, and soon the US. Our platform transforms how insurance payments are managed, making them faster, smarter, and more transparent.The Role:The...
-
Head of Information Security GRC
18 hours ago
London, Greater London, United Kingdom Trainline Full time £50,000 - £120,000 per yearAbout usWe are champions of rail, inspired to build a greener, more sustainable future of travel. Trainline enables millions of travellers to find and book the best value tickets across carriers, fares, and journey options through our highly rated mobile app, website, and B2B partner channels. Great journeys start with Trainline Now Europe's number 1...
-
Head of Information Security
3 days ago
London, Greater London, United Kingdom Checkatrade Full timeJoin us as Head of Information Security**Want to do work that really matters?At Checkatrade, we're building the UK's go-to home improvement marketplace. Every day, we help millions of homeowners find therighttradesperson for the job, fast, fair, and without the faff.We're looking for an experienced and highly motivatedHead of Information Security**to join...
-
London, Greater London, United Kingdom Duffel Full time £80,000 - £120,000 per yearSecurity Engineer, Governance, Risk and Compliance Create the future of travel with us Whether it's to visit the people closest to us, starting an exciting adventure, or a career-defining business trip, travel is an essential part of our lives. Yet we've all experienced the aches and pains of getting to our destination. Today, more than 4 billion airline...
-
London, Greater London, United Kingdom Duffel Full time £90,000 - £120,000 per yearSecurity Engineer, Governance, Risk and ComplianceCreate the future of travel with usWhether it's to visit the people closest to us, starting an exciting adventure, or a career-defining business trip, travel is an essential part of our lives. Yet we've all experienced the aches and pains of getting to our destination. Today, more than 4 billion airline...