Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC)

KBR, Inc.

Leatherhead

Hybrid

GBP 120,000 - 160,000

Full time

32 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

KBR, Inc. seeks a Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) to lead governance, risk management, information assurance, and data protection across the United Kingdom.

As the senior information security representative for UK operations, you will drive security policies, standards, controls, and assurance activities, reporting to executives. Based in Leatherhead or Swindon with a hybrid work arrangement, you will collaborate with business, technology, and security leaders,

Qualifications

  • Bachelor's degree in Cybersecurity, Information Security, or related field.
  • Experience leading security initiatives in complex enterprise environments.
  • Experience in cybersecurity governance, risk management, compliance, and accreditation.
  • Knowledge of ISO 27001, NIST, and related governance controls.
  • Experience with UK government, defence, or regulated environments.

Responsibilities

  • Lead enterprise information security governance and policy implementation.
  • Oversee accreditation, compliance, and assurance activities.
  • Provide executive reporting on security risks and control effectiveness.
  • Collaborate with business, technology, and security leaders.
  • Support incident response and data protection efforts.

Skills

Security leadership
Governance experience
Regulatory compliance
Communication with stakeholders
Risk management

Education

Bachelor's degree in Cybersecurity or related field
Master's degree (preferred)

Tools

ISO 27001
NIST
Governance tools

Job description

Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC)

KBR is seeking a Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) to lead cybersecurity governance, risk management, information assurance, and data protection activities across the United Kingdom. As the senior information security representative for UK operations, this role is responsible for driving the implementation of security policies, standards, and controls while overseeing accreditation, compliance, and assurance activities. Working closely with business, technology, and security leaders, the successful candidate will identify, assess, and mitigate cyber risks across the enterprise. This position provides strategic security leadership, ensures compliance with regulatory and contractual requirements, and delivers executive-level reporting on security risks, control effectiveness, and the organisation's overall security posture. In September 2025, KBR announced that we are spinning our Mission Technology Solutions business into a separate public company. This role will ultimately be part of the new company. The Mission Technology Solutions business partners with governments and defence, intelligence, space, aviation, and critical infrastructure customers to deliver advanced engineering, science, technology, and mission support solutions.

What You’ll Be Doing
  • Lead the implementation and oversight of enterprise information security, data protection, and privacy policies across the business.
  • Manage security governance processes and ensure alignment with Office of the CISO policies, standards, and procedures.
  • Plan and manage network certification, accreditation, and compliance activities in coordination with the Office of the CISO, government customers, auditors, certification bodies, and third-party assessors.
  • Coordinate and support penetration testing, security assessments, and related assurance activities.
  • Assist in the management and coordination of regional regulatory compliance and data privacy initiatives.
  • Collaborate with Security Operations and IT teams to ensure appropriate governance and protection of OFFICIAL-SENSITIVE and classified information.
  • Assess security threats and risks and develop appropriate mitigation strategies.
  • Serve as a cybersecurity subject matter expert, providing guidance on security architecture, governance, and risk management.
  • Provide consulting and security oversight for current and future projects involving network, infrastructure, and enterprise security architecture.
  • Support the development and delivery of security awareness training, data protection education, and best practice guidance.
  • Author, review, and maintain information security policies, standards, procedures, and supporting documentation.
  • Provide security representation and guidance for Architecture Review Boards, Change Control Boards, and project governance forums.
  • Respond to customer security inquiries and support security-related requirements for business programs and projects.
  • Support formal investigations involving security incidents, policy violations, and misconduct in coordination with Human Resources, Corporate Security, Finance, Business Integrity, and Office of the CISO teams.
  • Participate in cybersecurity incident response activities and support incident investigations as required.
  • Manage and respond to Data Privacy and Information Security support requests across the business.
  • Provide security advice, guidance, and risk-based recommendations to management, stakeholders, and customers.
  • Participate in Privacy Impact Assessments and support the review and development of data protection requirements and contractual language.
  • Review and approve information security governance activities including risk assessments, security categorization, waivers, exceptions, and variances in accordance with CISO directives.
  • Provide regular reporting and executive-level briefings regarding security risks, compliance posture, and the effectiveness of security controls.
Qualifications & Experience
Essential
  • Bachelor's degree in Cybersecurity, Information Security, Information Assurance, Computer Science, Information Technology, or a related field; additional relevant experience may be considered in lieu of a degree.
  • Experience in Information Security, Information Assurance, Cybersecurity, or a related discipline, including leadership of security initiatives within complex enterprise environments.
  • Experience in cybersecurity governance, risk management, compliance, accreditation, and information security programme oversight.
  • Knowledge of information security frameworks and standards, including ISO 27001, NIST, and related governance controls.
  • Experience working with UK government, defence, or other highly regulated environments.
Preferred
  • Master's degree in Cybersecurity, Information Security, or a related field
  • CISSP, CISM, CCSP, or equivalent cybersecurity certification
  • Experience supporting accreditation, auditing, and compliance activities within defence, aerospace, or regulated industry environments.
  • Experience conducting enterprise cybersecurity risk assessments and developing risk mitigation strategies.
  • Experience preparing executive-level reports, security assessments, and technical documentation
Location

This role can be based in either Leatherhead or Swindon and offers a hybrid working arrangement.

Security Requirements

SC Clearance. Due to the secure nature of this project, restrictions in relation to UK residency and nationality will apply.

KBR Benefits & More

Belong. Connect. Grow. At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow.

KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, colour, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

R2126902
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Leader: Cybersecurity & Compliance (UK)
Senior GRC Leader: Cybersecurity & Compliance (UK)

KBR, Inc. • Leatherhead

Hybrid
GBP 120,000 - 160,000
Senior Counsel, Legal - AI Governance, Data Privacy, & Cybersecurity
Senior Counsel, Legal - AI Governance, Data Privacy, & Cybersecurity

KBR, Inc. • Leatherhead

Hybrid
GBP 120,000 - 180,000
Senior IT Security Principal
Senior IT Security Principal

KBR, Inc. • Leatherhead

On-site
GBP 90,000 - 120,000
Senior Counsel, Legal – AI Governance, Data Privacy, & Cybersecurity
Senior Counsel, Legal – AI Governance, Data Privacy, & Cybersecurity

KBR, Inc • Leatherhead

On-site
GBP 120,000 - 180,000
Solutions Architect (Business Development)
Solutions Architect (Business Development)

KBR, Inc. • Leatherhead

Hybrid
GBP 70,000 - 95,000
Programme Integration Governance Lead
Programme Integration Governance Lead

KBR, Inc. • Glasgow

Hybrid
GBP 65,000 - 95,000
Senior Commercial Manager
Senior Commercial Manager

KBR, Inc. • Leatherhead

Hybrid
GBP 80,000 - 120,000
Risk Manager
Risk Manager

KBR, Inc. • Plymouth

Hybrid
GBP 55,000 - 75,000
Project Controls Manager
Project Controls Manager

KBR, Inc. • England

On-site
GBP 70,000 - 105,000
Senior GRC / Security Assurance Officer
Senior GRC / Security Assurance Officer

Rowden • West of England

Hybrid
GBP 60,000 - 80,000