Global Cyber Security and Compliance Director

Kent

Greater London

On-site

GBP 80,000 - 120,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Kent is seeking a Global IT Security and Compliance Director to develop and oversee a comprehensive cybersecurity and IT risk management program. This role requires at least 10 years of experience in cybersecurity compliance and risk management, along with certifications like CISM or CISSP. Responsibilities include managing enterprise risk, establishing cyber strategies, and ensuring compliance with regulations. The position is based in the UK and requires a strategic leader to support digital and engineering initiatives.

Qualifications

  • Minimum 10 years of experience in a related role within the past 12 years.
  • Demonstrated management skills in policy development and personnel administration.
  • Knowledge of energy-sector security requirements and regulations.

Responsibilities

  • Act as a strategic partner to enable secure innovation.
  • Conduct risk assessments to identify vulnerabilities.
  • Develop and own overall security strategy.

Skills

Leadership
Cybersecurity
Emotional intelligence
IT governance
Risk management

Education

Bachelor’s degree in Computer Science or related field
Master’s preferred

Tools

CISM certification
CISSP certification
ITIL knowledge

Job description

About Kent

We are a future‑focused company in the energy sector committed to responsible energy solutions. Our core beliefs include playing big, embracing emotional agility, driving performance, and infinite thinking. We celebrate diversity, inclusion, belonging, and offer flexible working arrangements and supportive employee networks.

About the job

Global IT Security and Compliance Director – responsible for developing, implementing, and monitoring a strategic, comprehensive enterprise cybersecurity and IT risk management program. The role provides vision and leadership to manage risk to Kent and ensures business alignment, effective governance, system integrity, and confidentiality. Reports directly to the Chief Digital and Information Officer and focuses on governance, risk, and compliance across the organization.

Responsibilities
  • Act as a strategic partner to digital, engineering, and delivery leaders to enable secure innovation while managing enterprise, technology, and operational risk.
  • Establish cyber strategy and roadmap.
  • Maintain governance and compliance standards.
  • Conduct risk assessments to identify vulnerabilities internally and in third‑party vendor or supplier products.
  • Create, maintain, communicate, and enforce information security policies.
  • Advise executive leadership on risk management – mitigation, reduction, transfer, exceptions, residual risk analysis.
  • Work with technical teams to ensure adequate cyber protection.
  • Measure and drive maturity improvements, adoption, and create security roadmaps.
  • Chair Kent’s security council.
  • Represent as a forward‑thinking leader on secure adoption of new application and AI technologies.
  • Support the CDIO and external advisory consultancy on executing the Information & Cyber Security strategy.
  • Develop and own overall security strategy.
  • Own and manage the process for Incident Detection, Containment, Analysis, and Response.
  • Evaluate new cybersecurity threats, IT trends, and develop effective controls.
  • Oversee security awareness program development.
  • Evaluate potential security breaches, coordinate response, and recommend corrective actions.
  • Define and report on information security metrics.
  • Review technology architectures and ensure alignment with security best practices.
  • Provide governance for the secure and responsible adoption of AI technologies, ensuring data privacy, model risk, ethics, and regulatory compliance.
  • Oversee security governance for engineering platforms, automation tools, and integrations, ensuring appropriate controls, access management, and resilience.
  • Ensure secure application development practices are embedded across the software development lifecycle and modern DevOps delivery models.
  • Maintain current knowledge of industry and regulatory trends and developments.
  • Develop and oversee disaster recovery and BCP policies and standards.
  • Develop, implement and maintain a monthly security risk reporting framework.
  • Design technical, administrative, and physical controls to ensure compliance with regulatory obligations.
  • Prepare for and facilitate external audit examinations.
  • Create and manage an information security program.
  • Identify, analyze, evaluate, and document information security risks and controls.
  • Conduct security risk assessments of planned and installed systems; recommend controls to mitigate risks.
  • Communicate risk findings and actionable recommendations.
  • Support workforce security activities – culture, awareness, and training.
  • Collect evidence to support investigations of security or policy violations.
  • Analyze security incidents in collaboration with stakeholders.
  • Coordinate remediation and awareness training.
  • Research, recommend, and contribute to information security policies, standards, and procedures.
  • Support lifecycle management of information security policies and documents.
  • Collaborate to implement policies across the organization.
  • Perform third‑party supplier risk assessments and manage supply chain risk throughout the lifecycle.
  • Assess and report on risks and benefits for the business and supplier compliance mandates.
  • Articulate assessment results to business stakeholders, sponsors, and internal parties.
  • Review information security sections within supplier and client contracts, identify gaps, and recommend security and data privacy content to close gaps.
  • Additional ad‑hoc tasks as required by the supervisor or management within reasonable scope.
Skills, qualifications and experience
  • Bachelor’s degree in Computer Science, Information Technology, Systems Security or related field; Master’s preferred.
  • Minimum 10 years of experience in a related role within the past 12 years.
  • Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP).
  • Knowledge of ITIL, including security administration and information technology governance in a multi‑platform environment.
  • Experience establishing cybersecurity and risk metrics for reporting.
  • Strong emotional intelligence and proven leadership in a large, multi‑stakeholder organization.
  • Demonstrated management skills in policy development, implementation, personnel administration, staff training, and development.
  • Knowledge of energy‑sector security requirements and regulations.
  • Emergency, health, safety, sustainability, environment, and quality (HSSEQ) knowledge and compliance with company rules.
Benefits & working conditions
  • Location: UK based – must be a current resident.
  • Relocation required: No.
  • Travel required: Yes.
  • Contract type: Permanent.
  • Experience level: 10+ years.

As an Equal Opportunities Employer, we value applications from all backgrounds, cultures, and abilities. We are a disability‑friendly employer and can make adjustments to support you during the recruitment process.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Global Cybersecurity & Compliance Director
Global Cybersecurity & Compliance Director

Kent • Greater London

On-site
GBP 80,000 - 120,000
Digital Publishing & Community Coordinator - Part-Time
Digital Publishing & Community Coordinator - Part-Time

Kent • Greater London

On-site
GBP 17,000 - 25,000
Head of Cyber Security and Productivity Solutions
Head of Cyber Security and Productivity Solutions

M+C Saatchi UK • Greater London

On-site
GBP 120,000 - 180,000
Cultural stimulation allowance – £250 per person per year
Half days off before bank holidays
Emergency care days for dependants
+5
Cyber Security Manager
Cyber Security Manager

CONSUMERS' ASSOCIATION • Greater London

On-site
GBP 73,000 - 80,000
35 hour working week
28 days holiday + bank holidays
Excellent pension scheme
+1
Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC)
Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC)

KBR, Inc. • Leatherhead

Hybrid
GBP 120,000 - 160,000
Cyber Risk & Security Manager
Cyber Risk & Security Manager

Spirit UK Ltd • Greater London

Hybrid
GBP 50,000 - 70,000
HR Coordinator
HR Coordinator

Kent • Woking

Hybrid
GBP 28,000 - 34,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Dunelm • Leicester

Hybrid
GBP 45,000 - 65,000
Cyber & Technology Security Manager - Data Center
Cyber & Technology Security Manager - Data Center

AirSearch • London

On-site
GBP 90,000 - 125,000
Competitive salary
Substantial benefits
Career development opportunities
Digital Publishing & Community Coordinator
Digital Publishing & Community Coordinator

Kent Plc • Glasgow

Hybrid
GBP 1,653,000 - 2,480,000