IT Security & GRC Leader: Governance & Risk

HS2 (High Speed Two)

Birmingham

On-site

GBP 59,000 - 72,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Flexible benefits 20%

Job summary

HS2 Ltd is seeking a Principal IT Security Manager (GRC) to lead enterprise cybersecurity governance, risk and compliance. You will define policies, manage risk registers, and drive third-party risk management while collaborating with Legal, HR, IT and Finance to embed security across projects.

The role focuses on developing governance frameworks, testing and assurance, and executive risk reporting to protect critical systems in a complex, public-sector environment.

Qualifications

  • Experience in governance, risk and compliance within IT security.
  • Ability to translate business goals into cyber governance requirements.
  • Knowledge of NCSC standards and CAF/CIS controls.
  • Experience with third-party risk management and vendor due diligence.
  • Ability to present risk-based recommendations to senior stakeholders and board-level audiences.
  • Experience coordinating audits and risk reporting across complex environments.

Responsibilities

  • Direct enterprise cybersecurity governance frameworks and evolve the governance operating model.
  • Own the information & cyber security policy lifecycle with reviews, approvals and publications.
  • Define, manage and maintain security policies, standards, procedures and controls.
  • Translate business goals into governance requirements and embed into delivery frameworks.
  • Oversee security testing and assurance strategy, including pen tests and simulations.
  • Own the information and cyber risk register and track mitigations.
  • Set risk assessment methodologies and integrate with corporate risk processes.
  • Lead third-party risk management and vendor due diligence.
  • Embed security requirements in supplier contracts with procurement and legal.
  • Maintain risk profiles for critical suppliers and plan remediations.
  • Ensure ongoing compliance with cybersecurity obligations and audits.
  • Provide executive reporting on risk metrics and KRIs.
  • Promote security awareness and risk ownership across the organisation.
  • Design and deliver GRC training for internal stakeholders.
  • Collaborate with Legal, HR, IT and Finance to embed security best practices.
  • Manage budget and resources for security testing activities.
  • Own strategic supplier relationships and drive value from third-party contracts.

Skills

Security governance
Governance & assurance
Problem definition & shaping
Stakeholder communication
Team management
Risk management
NCSC standards
Penetration testing familiarity
NIS Regulations knowledge

Job description

HS2 Ltd is seeking a Principal IT Security Manager (GRC) to lead enterprise cybersecurity governance, risk and compliance. You will define policies, manage risk registers, and drive third-party risk management while collaborating with Legal, HR, IT and Finance to embed security across projects.

The role focuses on developing governance frameworks, testing and assurance, and executive risk reporting to protect critical systems in a complex, public-sector environment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal IT Security Manager (GRC)
Principal IT Security Manager (GRC)

HS2 (High Speed Two) Ltd • Birmingham

Hybrid
GBP 59,000 - 72,000
Flexible benefits fund 20%
Flexible working
Personal and professional development
Principal IT Security Manager (GRC)
Principal IT Security Manager (GRC)

HS2 (High Speed Two) • Birmingham

On-site
GBP 59,000 - 72,000
Flexible benefits 20%
Security Architect & GRC Lead
Security Architect & GRC Lead

LHH • Scotland

On-site
GBP 90,000 - 130,000
Cyber Governance & Risk Advisor (GRC Specialist)
Cyber Governance & Risk Advisor (GRC Specialist)

Cyber UK • Greater London, Woking, Manchester

Hybrid
GBP 50,000 - 70,000
Well-being initiatives including Mental Health Champions
Professional community support
Inclusive and diverse workplace
Security & GRC Lead: Cyber Risk, Audit & Compliance
Security & GRC Lead: Cyber Risk, Audit & Compliance

Amiqus • United Kingdom

On-site
GBP 60,000 - 85,000
Lead Cyber GRC Consultant — Hybrid, High-Impact Governance
Lead Cyber GRC Consultant — Hybrid, High-Impact Governance

Jacobs • Reading

Hybrid
GBP 70,000 - 110,000
Health Cover
Life Assurance
Income Protection
+2
Lead Cyber GRC Architect
Lead Cyber GRC Architect

Jacobs • Birmingham

Hybrid
GBP 65,000 - 90,000
Health Cover
Life Assurance
Income Protection
+2
Senior Cyber GRC Lead - Governance & Compliance
Senior Cyber GRC Lead - Governance & Compliance

Cyber UK • United Kingdom

On-site
Information Security Specialist
Information Security Specialist

Michael James Associates • Greater London

On-site
GBP 90,000 - 120,000
Senior InfoSec GRC Lead — Hybrid, Equity Eligible
Senior InfoSec GRC Lead — Hybrid, Equity Eligible

BMS Group • Greater London

Hybrid
GBP 90,000 - 130,000
27 days holiday
Bonus scheme
Private medical cover
+2