Cyber Security Governance & Risk Management Principal

Reference: x0fdxcwet07a1cendmqe

We are seeking an experienced Cyber Security Governance & Risk Management Principal to lead the development, implementation and continual improvement of enterprise-wide cyber security governance and risk management practices. This senior role will provide strategic direction on security policies, standards, frameworks and controls, ensuring they support business objectives, regulatory obligations and evolving threat landscapes. You will act as a trusted adviser to senior stakeholders, translating complex cyber security risks into clear business impacts, priorities and practical remediation plans.

Key responsibilities include maintaining the cyber security governance framework; overseeing risk identification, assessment, treatment and acceptance processes; and reporting risk exposure, control effectiveness and compliance outcomes to executive and governance forums. You will lead the development and review of policies, procedures and control requirements, coordinate internal and external assurance activities, and support the management of audits, regulatory reviews and security certifications. The role will also contribute to third-party and supply-chain risk management, information security architecture reviews, major technology initiatives, incident preparedness and organisational resilience. You will mentor security professionals, promote a strong risk-aware culture and drive continuous improvement through meaningful metrics, maturity assessments and industry benchmarking.

To succeed, you will bring extensive experience in cyber security governance, enterprise risk management, information security or a closely related discipline, together with a strong understanding of recognised frameworks such as ISO 27001, NIST, COBIT or equivalent. Professional certifications such as CISSP, CISM, CRISC, CGEIT or relevant risk and audit qualifications are highly desirable. You will demonstrate experience engaging executives, boards, auditors and technical teams, with the ability to influence outcomes without direct authority. Strong analytical, communication, negotiation and documentation skills are essential, as is the ability to manage competing priorities and make sound, evidence-based decisions in a complex environment.

COMPETITIVE SALARY
Added 01/09/2026
Reference: x0fdxcwet07a1cendmqe

Cyber Security Governance & Risk Management Principal

London, England, United Kingdom Permanent Governance and Compliance

Other similar jobs

Head of Cyber Security Risk Management, Digital Identity

Added 18/08/2026

We are seeking a highly skilled and strategic Head of Cyber Security Risk Management, Digital Identity to lead our efforts in safeguarding digital identities and ensuring robust risk management practices. In this pivotal role, you will be responsible for developing and implementing a comprehensive cyber security risk management framework, specifically focused on digital identity threats and vulnerabilities. You will work closely with cross-functional teams to identify risks, assess their impact, and create effective mitigation strategies to protect sensitive information and maintain compliance with industry standards. Your key responsibilities will include overseeing the evaluation of existing digital identity systems and protocols,...

Learn more

Head of Vulnerability Management

Added 14/09/2026

We are seeking an experienced Head of Vulnerability Management to lead the development and delivery of a comprehensive, risk-based vulnerability management programme. This is a strategic leadership role responsible for reducing cyber risk across a complex technology environment, including cloud platforms, on-premises infrastructure, applications, endpoints and third-party services. You will define the vulnerability management vision, establish effective governance and ensure that security risks are identified, prioritised and remediated in line with business objectives and regulatory expectations. You will lead a team of vulnerability management specialists and work closely with Security Operations, Infrastructure, Engineering, Architecture, Risk, Compliance and Technology leadership. Responsibilities...

Learn more

Senior Cyber Risk Partnering Manager

Added 08/09/2026

We are seeking a Senior Cyber Risk Partnering Manager to strengthen cyber risk management across a complex, evolving organisation. This role will act as a trusted partner to senior business and technology stakeholders, helping them understand cyber risks, make informed decisions and embed effective controls into strategic initiatives and day-to-day operations. You will bring a pragmatic, collaborative approach to risk management, balancing security requirements with business objectives. Your responsibilities will include building strong relationships with senior leaders and acting as a key point of contact for cyber risk advice, assurance and escalation. You will identify, assess and articulate cyber risks...

Learn more

Vice President, Enterprise Risk Management & Legal Entity Risk

Added 25/08/2026

We are seeking a Vice President, Enterprise Risk Management & Legal Entity Risk to provide strategic leadership across the enterprise risk framework and legal entity governance environment. This senior role will oversee the identification, assessment, monitoring and management of key risks, ensuring that risk practices support business objectives, regulatory expectations and sustainable growth. The successful candidate will serve as a trusted adviser to senior leaders and governance committees, providing clear, independent insight into the organisation’s risk profile and emerging exposures. Key responsibilities include leading the development and ongoing enhancement of the enterprise risk management framework, risk appetite statement, policies, standards...

Learn more

Principal IAM Consultant, Identity Governance and Data Access

Added 07/09/2026

We are seeking a Principal IAM Consultant specialising in Identity Governance and Data Access to lead the design, delivery and continuous improvement of enterprise identity and access management capabilities. This is a senior advisory role for an experienced professional who can translate business, regulatory and security requirements into practical, scalable solutions. You will work with technology, risk, compliance, data and business stakeholders to strengthen access controls, improve governance and support secure digital transformation across complex environments. Your responsibilities will include defining IAM and identity governance strategies; developing target operating models, standards, policies and control frameworks; and leading initiatives covering joiner,...

Learn more

Senior Cyber Security Governance, Risk & Compliance (GRC) Engineer

Added 17/09/2026

We are seeking a Senior Cyber Security Governance, Risk & Compliance (GRC) Engineer to strengthen enterprise-wide security governance and support the continuous improvement of cyber risk management practices. This role will provide expert guidance across security frameworks, policies, controls and assurance activities, helping to ensure that technology, business processes and third-party services meet regulatory, contractual and organisational requirements. Key responsibilities include developing, maintaining and reviewing information security policies, standards and procedures; conducting risk assessments and control reviews; supporting audit and compliance programmes; and tracking remediation activities through to completion. You will coordinate evidence gathering, prepare clear reports for senior stakeholders,...

Learn more

Senior IT Cyber Governance, Risk & Compliance Analyst

Added 18/08/2026

We are seeking a highly skilled Senior IT Cyber Governance, Risk & Compliance Analyst to join our dynamic team. In this role, you will be responsible for developing, implementing, and maintaining an effective governance, risk management, and compliance framework to ensure the organization meets all regulatory requirements and industry standards. You will conduct thorough risk assessments, identify vulnerabilities, and recommend appropriate mitigation strategies. Additionally, you will collaborate with cross-functional teams to enhance cybersecurity policies and procedures, ensuring alignment with overall business objectives. The ideal candidate will have a strong background in IT security, risk management, and compliance, with a proven...

Learn more

Information Security Governance, Risk, and Compliance (GRC) Specialist

Added 09/09/2026

An opportunity is available for an Information Security Governance, Risk, and Compliance (GRC) Specialist to support the development, implementation, and continuous improvement of information security governance and risk management practices. The successful candidate will help ensure that security policies, controls, and processes align with business objectives, regulatory obligations, and recognised industry frameworks. This role will work closely with technology, operational, legal, privacy, and business stakeholders to promote a consistent and effective approach to managing information security risk. Key responsibilities will include maintaining information security policies, standards, procedures, and control documentation; coordinating risk assessments and tracking remediation activities; supporting internal and...

Learn more

Security Governance, Risk, Compliance Lead

Added 18/08/2026

We are seeking a dynamic and experienced Security Governance, Risk, Compliance Lead to enhance our organization's security framework. In this role, you will be responsible for developing, implementing, and maintaining security governance policies and procedures that align with industry standards and regulatory requirements. You will lead risk assessments to identify potential vulnerabilities, ensuring that appropriate measures are in place to mitigate risks and protect sensitive information. Collaborating with cross-functional teams, you will facilitate compliance audits and ensure adherence to relevant laws and regulations, providing guidance on best practices in security and risk management. The ideal candidate will have a strong...

Learn more

Information Security Governance, Risk, and Compliance (GRC) Specialist

Added 18/08/2026

We are seeking a dedicated Information Security Governance, Risk, and Compliance (GRC) Specialist to join our team. In this role, you will be responsible for developing and maintaining the organization's information security policies and procedures, ensuring compliance with applicable regulations and standards. You will conduct risk assessments, identify vulnerabilities, and implement effective mitigation strategies to protect sensitive data. Collaborating with cross-functional teams, you will lead initiatives to enhance the organization’s overall security posture and ensure that all security measures align with business objectives. Your expertise will be crucial in conducting regular audits and assessments to evaluate the effectiveness of current...

Learn more

Head of Governance, Risk and Compliance (Information Security)

Added 10/08/2026

We are seeking a dynamic and experienced professional to take on the role of Head of Governance, Risk and Compliance (Information Security). In this leadership position, you will be responsible for developing and implementing a robust governance framework that ensures compliance with relevant laws, regulations, and industry standards. You will lead the organization’s risk management strategy, identifying potential risks and developing mitigation plans to protect sensitive information and maintain operational integrity. Your expertise will guide the creation and enforcement of policies and procedures to enhance the organization’s information security posture. The ideal candidate will possess strong analytical skills and a...

Learn more

Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC)

Added 18/09/2026

We are seeking a Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) to lead the development and continuous improvement of a mature cybersecurity governance and risk management framework. This role will provide strategic direction, independent challenge and practical guidance to ensure security controls, policies and processes align with business objectives, regulatory obligations and recognised industry standards. The successful candidate will work closely with technology, risk, legal, audit and operational teams to strengthen cyber resilience across the organisation. Key responsibilities include owning and maintaining cybersecurity policies, standards, procedures and control frameworks; overseeing enterprise cyber risk assessments, risk registers, remediation plans and...

Learn more

InfoSec Governance, Risk and Compliance Analyst

Added 10/08/2026

We are seeking a qualified InfoSec Governance, Risk and Compliance Analyst to join our dynamic team. In this role, you will be responsible for developing, implementing, and maintaining the organization's information security governance framework. You will work closely with various departments to ensure compliance with relevant regulations and standards, while promoting a culture of security awareness throughout the organization. Your expertise will be crucial in identifying and assessing risks, as well as implementing effective strategies to mitigate them. Key responsibilities include conducting regular audits and assessments of information security policies and procedures, ensuring adherence to industry standards such as ISO...

Learn more

Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC)

Added 04/08/2026

We are seeking a seasoned professional to join our team as a Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC). In this role, you will be responsible for developing, implementing, and maintaining an effective cybersecurity governance framework. Your primary duties will include overseeing risk assessments, compliance audits, and policy development to ensure alignment with industry standards and regulations. You will collaborate with various departments to identify and mitigate potential risks, ensuring that the organization remains compliant with all relevant laws and best practices. Additionally, you will lead a team of cybersecurity professionals, providing guidance and support in the execution of...

Learn more

Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC)

Added 03/08/2026

We are seeking a highly skilled Senior Manager of Cybersecurity Governance, Risk & Compliance (GRC) to join our team. In this pivotal role, you will lead efforts to establish, implement, and manage our cybersecurity governance framework. You will be responsible for developing and maintaining policies, procedures, and standards to ensure compliance with applicable regulations and frameworks. Collaborating with cross-functional teams, you will assess risks, recommend mitigation strategies, and ensure that all cybersecurity initiatives align with business objectives. Your duties will include conducting regular risk assessments, audits, and compliance reviews to identify vulnerabilities and recommend necessary improvements. You will also oversee...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.