Governance, Risk & Compliance Lead

InfoSec People Ltd

Greater London

Hybrid

GBP 90,000 - 130,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid working

Job summary

InfoSec People Ltd client seeks a Cyber Security Governance, Risk & Compliance Lead in London on a permanent, hybrid basis. You will drive regulatory engagement, cyber resilience and assurance across NIS Regulations, NIS2, Ofgem and ISO 27001.

You will coordinate self-assessments, evidence packs and responses, while maintaining risk registers and senior leadership dashboards. Occasional travel to Belgium and Norfolk may be required.

Qualifications

  • Significant experience in cyber security governance, risk and compliance within regulated environments.
  • Strong knowledge of risk assessments, risk registers and treatment plans.
  • Experience with third-party management and supplier risk assurance.
  • Understanding of NIS Regulations, NIS2, Ofgem, ECAF and operators of essential services obligations.
  • Experience supporting audits, regulatory submissions and assurance programmes.

Responsibilities

  • Act as the primary point of contact for cyber security regulatory engagement with Ofgem and regulatory bodies.
  • Coordinate submissions, self-assessments, improvement plans and responses to regulatory inquiries and audits.
  • Lead assurance activities across NIS Regulations, NIS2, Ofgem requirements, ECAF and ISO 27001.
  • Monitor evolving cyber security legislation and guidance and advise on actions.
  • Maintain the Cyber Security Risk Register and governance for threat mitigation and actions.
  • Support governance and status reporting of the Cyber Security Roadmap and third-party deliverables.
  • Develop supply chain cyber security assurance programmes and due diligence processes.
  • Prepare dashboards and reports for senior leadership and Board oversight.

Skills

Governance & Compliance
Risk Management
NIS Regulations/NIS2
ISO 27001
Supplier Risk
Stakeholder Management
Audit & Assurance
Regulatory Reporting

Job description

Our client, an essential services operator within the utilities and technology sectors, is seeking a Cyber Security Governance, Risk & Compliance Lead for a permanent position based in London with hybrid working.

The role will support regulatory engagement, cyber resilience and compliance activities, helping to ensure alignment with NIS Regulations, NIS2, Ofgem expectations, the Enhanced Cyber Assessment Framework (ECAF) and ISO 27001. Occasional travel to Belgium and Norfolk may be required.

Key Responsibilities:
  • Act as the primary point of contact for cyber security regulatory engagement with Ofgem, competent authorities, auditors and external stakeholders
  • Coordinate regulatory submissions, NIS self-assessments, improvement plans, evidence packs and responses to regulatory enquiries, inspections and audits
  • Lead assurance activities across NIS Regulations, NIS2, Ofgem cyber security requirements, ECAF, ISO 27001 and other relevant resilience frameworks
  • Monitor emerging cyber security legislation, regulatory requirements and industry guidance, assessing their impact and recommending appropriate actions
  • Maintain and review the Cyber Security Risk Register, ensuring threat scenarios, mitigations, treatment plans and governance arrangements remain current
  • Support the governance and status reporting of the Cyber Security Roadmap, including risks, issues, actions, dependencies and third-party deliverables
  • Develop and maintain a cyber security supply chain assurance programme, including supplier risk assessments, due diligence and ongoing third-party assurance
  • Prepare dashboards, key performance indicators, reports and briefing materials for senior leadership and Board-level oversight
Job Requirements:
  • Significant experience in cyber security governance, risk and compliance within a regulated or critical infrastructure environment
  • Strong knowledge of risk assessments, risk analysis, risk registers and cyber security treatment plans
  • Experience of third-party management, supplier risk assessments and supply chain assurance
  • Understanding of NIS Regulations, NIS2, Ofgem requirements, ECAF and the regulatory obligations of an Operator of Essential Services
  • Experience supporting audit and review activities, regulatory submissions, assurance programmes and improvement plans
  • Knowledge of Information Security Management Systems, including cyber security policies, standards, procedures and governance
  • Ability to interpret changing legislation and industry guidance, translating requirements into practical compliance actions
  • Excellent report writing, stakeholder management and communication skills, with the confidence to present complex information clearly to senior audiences
Additional Information:
  • Hybrid working in line with the organisation’s policy, combining office and remote working
  • Occasional travel to Belgium, Norfolk and other locations as required
  • Opportunity to contribute to the cyber resilience of essential national infrastructure
  • Role with broad exposure to regulatory engagement, cyber risk management and strategic improvement programmes
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk Compliance Lead
Governance, Risk Compliance Lead

Infosec • City Of London

Hybrid
GBP 90,000 - 120,000
Governance, Risk Compliance Lead
Governance, Risk Compliance Lead

Matchtech • Greater London

Hybrid
GBP 90,000 - 125,000
Cyber GRC Lead for Regulated Utilities
Cyber GRC Lead for Regulated Utilities

InfoSec People Ltd • Greater London

Hybrid
GBP 90,000 - 130,000
Hybrid working
Cyber GRC Lead - Hybrid, Regulated & Resilient
Cyber GRC Lead - Hybrid, Regulated & Resilient

Infosec • City Of London

Hybrid
GBP 90,000 - 120,000
Cyber GRC Lead – Hybrid, Regulated Infrastructure
Cyber GRC Lead – Hybrid, Regulated Infrastructure

Matchtech • Greater London

Hybrid
GBP 90,000 - 125,000
Regulatory Cyber Assurance Principal
Regulatory Cyber Assurance Principal

Ofgem • Glasgow, Cardiff, Greater London

Hybrid
GBP 60,000 - 67,000
Civil Service Pension
Hybrid working
Training and development opportunities
Cyber Governance Specialist - Ref 2863 UK Aberdeen
Cyber Governance Specialist - Ref 2863 UK Aberdeen

Prosource • Aberdeen City

Hybrid
GBP 60,000 - 90,000
Company pension
Private medical insurance
Dental insurance
+3
Governance, Risk & Compliance Lead
Governance, Risk & Compliance Lead

Elevation Recruitment Group • Leeds

Hybrid
GBP 50,000 - 60,000
Car Allowance
Bonus
Benefits
Cyber security Lead
Cyber security Lead

Vallum Associates • Greater London

On-site
GBP 85,000 - 120,000
Cyber Risk & Security Manager
Cyber Risk & Security Manager

Spirit UK Ltd • Greater London

Hybrid
GBP 50,000 - 70,000