Principal IT Security Manager (GRC)

HS2 (High Speed Two) Ltd

Birmingham

Hybrid

GBP 59,000 - 72,000

Full time

28 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Flexible benefits fund 20%
Flexible working
Personal and professional development

Job summary

HS2 Ltd is seeking a Principal IT Security Manager (GRC) to lead governance, risk and compliance within the Information & Cyber Security function. You will shape enterprise-wide security policies, manage third-party risk and oversee testing and assurance activities to protect critical systems.

The role requires translating business goals into security requirements, collaborating with legal, procurement and IT teams, and delivering executive risk reporting.

Qualifications

  • Experience with governance, risk and compliance within information security.
  • Ability to translate business goals into cyber governance requirements.
  • Knowledge of NCSC standards and Cabinet Office requirements.
  • Experience with third‑party risk management and supplier contracts.
  • Experience with security testing and assurance strategies.
  • Experience with risk management and audit remediation.

Responsibilities

  • Direct the development, implementation and maintaining organisation wide cybersecurity governance frameworks.
  • Own the enterprise wide Information & Cyber Security policy lifecycle, ensuring regular review, approval, and publication of security policies.
  • Defining, managing and maintaining security policies, standards, procedures and controls aligned with regulatory requirements.
  • Translate business goals into cyber governance requirements and embed into third-party and internal delivery frameworks.
  • Oversee the provision of security testing and assurance strategy and capability, including penetration testing and simulation exercises.
  • Own the information and cyber risk register and track mitigation progress.
  • Set direction for enterprise-wide risk assessment methodologies and ensure integration with corporate risk processes.
  • Lead the third-party risk management program, including vendor due diligence and ongoing monitoring.
  • Work with procurement, legal, and IT to embed security clauses in supplier contracts.
  • Maintain a risk profile for critical suppliers and support risk treatment or exit strategies.
  • Ensure ongoing compliance with cybersecurity-related legal, regulatory, and contractual obligations.
  • Manage responses to audits and reporting of KRIs.

Skills

Governance
Governance & Assurance
Problem definition
Stakeholder communication
Team management
GRC knowledge
Cybersecurity frameworks
Security testing
Public sector standards

Job description

Job Description

Base salary from £65,474pa. Depending on skills and experience. In addition, we offer flexible benefits fund of 20% which is paid on top base salary and is fully pensionable, as well as a range of competitive benefits - check them out in the Benefits section on our website.
HS2 Ltd endeavours to ensure everyone working for us and with us feels included, thrives and achieves their full potential. In practice, this means we are positive and inclusive about making adjustments, providing flexible working, encouraging our staff networks to flourish and providing personal and professional development opportunities.

Job Purpose

The Principal IT Security Manager (GRC) is accountable for the effective management of the Governance, Risk, Compliance (GRC) within the Information & Cyber Security function. This includes ensuring that Information & technology controls are appropriately tested and risk assessed to mitigate threats, and to monitor that standards and obligations are being appropriately adopted through all delivery activity.

This role is responsible for using and applying knowledge of business goals and security requirements to frame problems and set priorities for internal and external delivery teams.

About The Role
  • Direct the development, implementation and maintaining organisation wide cybersecurity governance frameworks, defining and evolving the cyber governance operating model.
  • Own the enterprise-wise Information & Cyber Security policy lifecycle, ensuring the regular review, approval, and publication of security policies.
  • Defining, managing and maintaining security policies, standards, procedures and controls aligned with regulatory and legal requirements (e.g. the NCSC Cyber Assessment Framework, and Cabinet Office requirements.).
  • Accountable for translating business goals and requirements into cyber governance requirements, and embedding these into third-party and internal delivery frameworks, balancing the trade-offs between business outcomes and security posture.
  • Oversee the provision of security testing and assurance strategy and capability, including penetration testing, simulation exercises and continuous control validation.
  • Own the information and cyber risk register, ensuring risks are identified, assessed, prioritized, and tracked through mitigation.
  • Set the direction for enterprise-wide Information & Cyber Security risk assessment methodologies and ensure integration with corporate risk processes.
  • Lead the provision of an Information & Cyber Security third-party risk management program, including vendor due diligence, onboarding assessments, and ongoing monitoring.
  • Work with procurement, legal, and IT teams to ensure security clauses and risk requirements are embedded in supplier contracts.
  • Maintain a risk profile for critical suppliers and support risk treatment or exit strategies where necessary.
  • Ensure ongoing compliance with cybersecurity-related legal, regulatory, and contractual obligations.
  • Manage responses to internal and external audits, including but not limited to GIAA, NAO, Internal Audit and UK Government returns such s GovAssure.
  • Track and report compliance status, gaps, and remediation progress.
  • Provide executive-level reporting on risk metrics and key risk indicators (KRIs).
  • Promote a strong culture of security awareness and risk ownership throughout the organization.
  • Design and deliver GRC-related training and education programs to internal stakeholders.
  • Champion cross-functional collaboration with Legal, HR, IT, and Finance to embed security best practices.
  • Manage budget and resourcing requirements for the delivery of security testing activity.
  • Own strategic supplier relationships and drive value/performance outcomes from third-party contracts.
About You Skills
  • Security and Enterprise-wide Governance. Defining, embedding and evolving enterprise Information & Cyber governance aligned to risk appetite and regulatory expectations.
  • Governance and assurance. Ability to evolve and define governance and take responsibility for working with other stakeholders across HS2’s wider governance structure. Assure standards, guardrails and principles to effectively govern delivery.
  • Problem definition and shaping. Ability to define security-related strategies and policies, providing guidance to others on working within a strategic context.
  • Stakeholder communication. Confidence working with senior stakeholders, influencing decisions and providing clear, risk-based recommendations. Including excellent written and verbal communication skills, including the ability to prepare board-level reports and briefings.
  • Team Management and Organisational directive. Ability to lead multidisciplinary teams and influence change in matrixed or federated environments.
  • Knowledge of governance, risk, and compliance’s role with across Information & Cyber Security or Information Assurance in an Enterprise.
  • Knowledge of Cyber Security Frameworks, methodologies, and best practice / guidance such as NCSC standards.
  • Knowledge of common security testing methods (E.g., Penetration testing, breach & attack simulation tools etc.).
  • Understanding of UK public sector security expectations including NIS Regulations, NCSC guidance, and Cabinet Office policy.
Type Of Experience
  • Experience across industry frameworks and best practices (E.g., NCSC CAF, CIS CSC, etc.).
  • Experience of risk management and delivery of audit remediation activities.
  • Experience of partnering with supplier teams for managed services delivery of improvements.
  • Experience designing and implementing secure systems, leading review where necessary of complex security issues.
  • Experience of enabling and informing risk-based decisions.
  • Experience dealing with the security implications of transformation and day-to-day product changes.
  • Experience working with system architectures, displaying a strong understanding of the impact of vulnerabilities on varied systems.
About Us

High Speed 2 (HS2 Ltd) will be the UK’s new high speed rail network. As well as improving capacity, the new scheme will shorten journey times between a number of Britain’s major population centres, boost the economy and create thousands of jobs.

HS2 Ltd will create a skills legacy and develop a diverse range of talent. We aim to be a leader in EDI practice by creating a safe & inclusive working environment for all our staff - living our values of Safety, Respect, Integrity and Leadership.

In practice, this means we are positive and inclusive about making adjustments, providing flexible working, encouraging our staff networks to flourish and providing personal and professional development opportunities.

HS2 Ltd is also a safety-critical organisation. Employees are required to ensure reasonable care of their own and others’ health and safety by taking personal responsibility for working to our ‘Safe at Heart’ programme principles and following safe working procedures at all times.

HS2 Ltd endeavours to ensure everyone working for us and with us feels included, thrives and achieves their full potential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal IT Security Manager (GRC)
Principal IT Security Manager (GRC)

HS2 (High Speed Two) • Birmingham

On-site
GBP 59,000 - 72,000
Flexible benefits 20%
Health & Safety and Security Director
Health & Safety and Security Director

HS2 (High Speed Two) Ltd • Birmingham

Hybrid
GBP 130,000 - 180,000
IT Security & GRC Leader: Governance & Risk
IT Security & GRC Leader: Governance & Risk

HS2 (High Speed Two) • Birmingham

On-site
GBP 59,000 - 72,000
Flexible benefits 20%
Systems Manager
Systems Manager

HS2 (High Speed Two) • City Of London

On-site
GBP 50,000 - 59,000
Flexible benefits fund (20%)
Pensionable benefits
Systems Manager
Systems Manager

HS2 (High Speed Two) Ltd • Greater London

On-site
GBP 50,000 - 59,000
Flexible benefits fund (20%)
Pensionable benefits package
Competitive overall package
Senior Programme Assurance Manager
Senior Programme Assurance Manager

High Speed Two (HS2) • Greater London

Hybrid
GBP 59,000 - 70,000
Flexible benefits fund (20% on top of
Cyber Security Governance and Risk Management Principal
Cyber Security Governance and Risk Management Principal

Government Digital Service • Manchester

On-site
GBP 110,000 - 140,000
Cyber Security Governance & Risk Management Principal
Cyber Security Governance & Risk Management Principal

Government Digital Service • Greater London, Manchester, West of England

On-site
GBP 90,000 - 120,000
Cyber Security Governance and Risk Management Principal
Cyber Security Governance and Risk Management Principal

Government Digital Service • Greater London

On-site
GBP 70,000 - 90,000
Principal Cyber Security Governance & Risk Leader
Principal Cyber Security Governance & Risk Leader

Government Digital Service • Manchester

On-site
GBP 110,000 - 140,000