Supervisor, IT Security, Governance, Risk & Compliance

Hollister Incorporated

Wokingham

On-site

GBP 70,000 - 110,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Hollister Incorporated, located in Winnersh, seeks a Supervisor for Governance, Risk & Compliance (GRC) to lead cybersecurity governance, risk management, regulatory compliance, and audit readiness programs. The role coordinates with IT, Legal, Privacy, and Internal Audit to ensure controls align with business objectives and risk appetite.

You will supervise a GRC and data protection team, drive program maturity, and report risk trends and remediation progress to senior leadership.

Qualifications

  • Bachelor's degree with 8–12 years of related experience.
  • 3+ years of people leadership or demonstrated workstream leadership.
  • Experience supporting ISO 27001, SOC 2, HIPAA, privacy or similar compliance programs.
  • Experience with risk assessments, audits, remediation, and third‑party security risks.

Responsibilities

  • Lead governance program development, policies, standards, and guidelines.
  • Oversee cybersecurity risk assessments and risk register maintenance.
  • Coordinate compliance programs and evidence collection for audits.
  • Manage third‑party risk assessments and remediation activities.
  • Lead security awareness, policy lifecycle, and culture initiatives.
  • Supervise GRC and data protection team members and staffing.
  • Engage stakeholders across Cybersecurity, IT, Legal, Privacy and Quality.
  • Provide status updates on risks, controls, and remediation progress.

Skills

Leadership
Governance
Risk management
Compliance management
Audit readiness
Regulatory knowledge
Vendor risk management
Security awareness
Policy management
Communication with leadership

Education

Bachelor's Degree with 8-12 years of related experience

Tools

Microsoft Purview
Azure security

Job description

We Make Life More Rewarding and Dignified
Location: Winnersh
Department: IT
Summary

The Supervisor, Governance, Risk & Compliance (GRC) leads and enhances the organization's cybersecurity governance, risk management, regulatory compliance, audit readiness, third-party risk, security awareness, privacy coordination, and policy management programs. The role provides both strategic direction and operational oversight while leading a team responsible for ensuring alignment with regulatory requirements, industry frameworks, contractual obligations, and internal security standards. The position serves as a key liaison across Cybersecurity, IT, Legal, Privacy, Compliance, Internal Audit, Quality, and business functions to ensure cybersecurity risks are effectively identified, assessed, communicated, and managed in accordance with business objectives and risk appetite.

Responsibilities
Governance & Security Program Management
  • Lead the development, implementation, and maintenance of cybersecurity governance programs, policies, standards, procedures, and guidelines.
  • Align governance activities with business objectives, cybersecurity strategy, and enterprise risk appetite.
  • Develop and maintain KPIs, KRIs, program metrics, and executive reporting.
  • Drive cybersecurity program maturity and continuous improvement initiatives.
Cybersecurity Risk Management
  • Lead enterprise cybersecurity risk assessments and maintain the cybersecurity risk register.
  • Facilitate risk reviews, mitigation planning, risk acceptance, and remediation efforts.
  • Evaluate cybersecurity risks associated with new technologies, cloud services, vendors, and business initiatives.
  • Ensure risk decisions are documented, approved, and periodically reviewed.
  • Communicate key risks, trends, and mitigation activities to leadership.
Compliance & Regulatory Oversight
  • Manage compliance programs related to ISO 27001, SOC 2, HIPAA, GDPR, UK Cyber Essentials, NIST Cybersecurity Framework, and other applicable regulations.
  • Coordinate control assessments, evidence collection, gap analyses, corrective actions, and compliance reporting.
  • Monitor regulatory and industry changes and assess organizational impacts.
  • Maintain an audit-ready cybersecurity compliance posture.
Audit & Assurance Management
  • Serve as the primary cybersecurity coordinator for internal and external audits, certifications, and regulatory assessments.
  • Lead audit preparation, evidence validation, stakeholder engagement, and responses.
  • Track audit findings, corrective actions, and remediation progress.
  • Provide status reporting and updates to leadership.
Third-Party Risk Management
  • Oversee cybersecurity due diligence and risk assessments for vendors, suppliers, and service providers.
  • Review security controls, certifications, contracts, and assessment responses for critical vendors.
  • Coordinate remediation activities with vendors, procurement, legal, and business stakeholders.
  • Establish ongoing monitoring and reporting practices for third-party security risks.
Security Awareness, Policy & Culture
  • Lead enterprise security awareness and compliance training initiatives.
  • Measure program effectiveness through participation and behavior-based metrics.
  • Partner with HR and business leaders to strengthen security culture and accountability.
  • Maintain cybersecurity policies through review, approval, communication, and lifecycle management processes.
People Leadership
  • Supervise, coach, mentor, and develop GRC and data protection team members.
  • Establish performance expectations, development plans, and accountability measures.
  • Manage workload prioritization, resource allocation, and operational coverage.
  • Promote collaboration, knowledge sharing, and continuous learning.
Stakeholder Engagement
  • Collaborate with Cybersecurity, IT, Legal, Privacy, Internal Audit, Quality, Regulatory Affairs, Data & AI, and business leaders.
  • Translate cybersecurity and compliance requirements into actionable business processes.
  • Present program updates, compliance status, risks, and recommendations to leadership.
Essential Functions of the Role
  • Communicate effectively via email, phone, and virtual platforms.
  • Collaborate across departments to support organizational goals.
  • Participate in cross-functional meetings and initiatives.
  • Prepare reports and dashboards for internal stakeholders.
  • Ensure data accuracy and confidentiality in compliance with company and legal standards.
  • Demonstrate initiative in identifying process improvements or automation opportunities.
  • Maintain secure handling of sensitive information.
  • Support audits and regulatory reporting as needed.
Education & Work Requirements
  • Bachelor's Degree with 8-12 years of related experience
Education & Work Preferences
  • Progressive experience in cybersecurity, governance, risk management, compliance, audit, or information security.
  • 3+ years of people leadership, supervisory, or demonstrated workstream leadership experience.
  • Experience supporting or leading ISO 27001, SOC 2, HIPAA, privacy, or similar compliance programs.
  • Experience conducting risk assessments, managing audits, tracking remediation activities, and performing third-party security risk assessments.
  • Experience within healthcare, medical device, manufacturing, life sciences, or other regulated industries.
  • Experience working within a global cybersecurity governance environment.
  • Experience building, implementing, or maturing enterprise GRC programs and reporting outcomes to leadership.
  • Preferred Certifications
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Internal Auditor (CIA)
  • ISO 27001 Lead Implementer or Lead Auditor
  • Certified Data Privacy Solutions Engineer (CDPSE)
  • Preferred Knowledge & Competencies
  • Cybersecurity governance frameworks (ISO 27001, SOC 2, NIST CSF)
  • Risk assessment and audit management methodologies
  • HIPAA, GDPR, privacy, and regulatory compliance requirements
  • Vendor risk management and continuous monitoring
  • Microsoft Purview, Azure security and compliance concepts, identity and access management, and data loss prevention
  • Strategic thinking, business acumen, executive communication, people development, cross-functional collaboration, and risk-based decision making.
Competencies
  • Be Agile - Innovates and adapts quickly, approaching change with curiosity while persisting through obstacles.
  • Be Customer Centric - Considers the needs, experiences and feedback of customers in all we do.
  • Be People-Focused - Builds trust and collaborates with an inclusive and empathetic approach.
  • Be Performance Driven - Operates with an ownership mindset, driving meaningful outcomes.
  • Live The Schneiders' Legacy, Our Noble Purpose - Passionately serves Our Mission and Vision, while demonstrating the Immutable Principles.
About Hollister Incorporated

Hollister Incorporated is an independent, employee-owned company that develops, manufactures and markets healthcare products worldwide. The company spearheads the advancement of innovative products for ostomy care, continence care and critical care, and also creates educational support materials for patients and healthcare professionals. Headquartered in Libertyville, Illinois, Hollister has manufacturing and distribution centers on three continents and sells in nearly 80 countries. Hollister is a wholly owned subsidiary of The Firm of John Dickinson Schneider, Inc., and is guided both by its Mission to make life more rewarding and dignified for people who use our products and services and as well as its Vision to grow and prosper as an independent, employee-owned company, and in the process, to become better human beings.

EOE Statement

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Supervisor, It Security, Governance, Risk & Compliance
Supervisor, It Security, Governance, Risk & Compliance

Hollister Incorporated • Winnersh

On-site
GBP 70,000 - 100,000
Senior Manager European Compliance
Senior Manager European Compliance

Hollister Incorporated • Winnersh

Hybrid
GBP 100,000 - 120,000
Base salary £100k-£120k
Bonus scheme
Salary reviews
+7
Clinical Services Strategic Administrator
Clinical Services Strategic Administrator

Hollister Incorporated • Winnersh

On-site
GBP 26,000 - 34,000
Salary review annually
Pension 8.5% employer contribution
Private healthcare
+5
Clinical Services Strategic Administrator
Clinical Services Strategic Administrator

Hollister Incorporated • Aylesbury

On-site
GBP 26,000 - 34,000
Group Personal Pension Scheme with 8.5
Private Healthcare Insurance
Life Insurance Cover at x10 base
+5
Senior Company Nurse
Senior Company Nurse

Hollister Incorporated • Aylesbury

Hybrid
GBP 46,000 - 56,000
Discretionary bonus scheme
Pension
Life Insurance
+4
Demand Planner UK & Ireland
Demand Planner UK & Ireland

Hollister Incorporated • Winnersh

On-site
GBP 38,000 - 54,000
Corporate Bonus Scheme
Pension Scheme with 8.5% employer
Private Healthcare
+5
Company Nurse
Company Nurse

Hollister Incorporated • Winnersh

On-site
GBP 42,000 - 52,000
Competitive salary
Corporate bonus scheme
Pension scheme
+2
GRC Security & Compliance Lead — Supervisor
GRC Security & Compliance Lead — Supervisor

Hollister Incorporated • Wokingham

On-site
GBP 70,000 - 110,000
Company Nurse
Company Nurse

Hollister Incorporated • Aylesbury

On-site
GBP 42,000 - 52,000
Corporate bonus scheme
Annual salary review
Pension scheme with 8.5% employer
+1
GRC Security Lead — Governance, Risk & Compliance
GRC Security Lead — Governance, Risk & Compliance

Hollister Incorporated • Winnersh

On-site
GBP 70,000 - 100,000