{bc}
oracle

Principal IT Security Manager (GRC)

High Speed Two (HS2) Ltd
Birmingham, GBR
Full-time
Senior
Onsite
GBP 65474-65474 yearly / year
Discovered Yesterday
NCSC Cyber Assessment FrameworkGovAssureCIS CSCpenetration testingbreach & attack simulation tools
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

NCSC Cyber Assessment FrameworkGovAssureCIS CSC
Smart Apply

Full Job Posting

About the Role

Direct the development, implementation and maintaining organisation wide cybersecurity governance frameworks, defining and evolving the cyber governance operating model.

Own the enterprise-wise Information & Cyber Security policy lifecycle, ensuring the regular review, approval, and publication of security policies.

Defining, managing and maintaining security policies, standards, procedures and controls aligned with regulatory and legal requirements (e.g. the NCSC Cyber Assessment Framework, and Cabinet Office requirements.).

Accountable for translating business goals and requirements into cyber governance requirements, and embedding these into third-party and internal delivery frameworks, balancing the trade-offs between business outcomes and security posture.

Oversee the provision of security testing and assurance strategy and capability, including penetration testing, simulation exercises and continuous control validation.

Own the information and cyber risk register, ensuring risks are identified, assessed, prioritized, and tracked through mitigation.

Set the direction for enterprise-wide Information & Cyber Security risk assessment methodologies and ensure integration with corporate risk processes.

Lead the provision of an Information & Cyber Security third-party risk management program, including vendor due diligence, onboarding assessments, and ongoing monitoring.

Work with procurement, legal, and IT teams to ensure security clauses and risk requirements are embedded in supplier contracts.

Maintain a risk profile for critical suppliers and support risk treatment or exit strategies where necessary.

Ensure ongoing compliance with cybersecurity-related legal, regulatory, and contractual obligations.

Manage responses to internal and external audits, including but not limited to GIAA, NAO, Internal Audit and UK Government returns such s GovAssure.

Track and report compliance status, gaps, and remediation progress.

Provide executive-level reporting on risk metrics and key risk indicators (KRIs).

Promote a strong culture of security awareness and risk ownership throughout the organization.

Design and deliver GRC-related training and education programs to internal stakeholders.

Champion cross-functional collaboration with Legal, HR, IT, and Finance to embed security best practices.

Manage budget and resourcing requirements for the delivery of security testing activity.

Own strategic supplier relationships and drive value/performance outcomes from third-party contracts.

About You Skills

Security and Enterprise-wide Governance. Defining, embedding and evolving enterprise Information & Cyber governance aligned to risk appetite and regulatory expectations.

Governance and assurance. Ability to evolve and define governance and take responsibility for working with other stakeholders across HS2’s wider governance structure. Assure standards, guardrails and principles to effectively govern delivery.

Problem definition and shaping. Ability to define security-related strategies and policies, providing guidance to others on working within a strategic context.

Stakeholder communication. Confidence working with senior stakeholders, influencing decisions and providing clear, risk-based recommendations. Including excellent written and verbal communication skills, including the ability to prepare board-level reports and briefings.

Team Management and Organisational directive. Ability to lead multidisciplinary teams and influence change in matrixed or federated environments.

Knowledge of governance, risk, and compliance’s role with across Information & Cyber Security or Information Assurance in an Enterprise.

Knowledge of Cyber Security Frameworks, methodologies, and best practice / guidance such as NCSC standards.

Knowledge of common security testing methods (E.g., Penetration testing, breach & attack simulation tools etc.).

Understanding of UK public sector security expectations including NIS Regulations, NCSC guidance, and Cabinet Office policy.

Type of Experience

Experience across industry frameworks and best practices (E.g., NCSC CAF, CIS CSC, etc.).

Experience of risk management and delivery of audit remediation activities.

Experience of partnering with supplier teams for managed services delivery of improvements.

Experience designing and implementing secure systems, leading review where necessary of complex security issues.

Experience of enabling and informing risk-based decisions.

Experience dealing with the security implications of transformation and day-to-day product changes.

Experience working with system architectures, displaying a strong understanding of the impact of vulnerabilities on varied systems.

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at High Speed Two (HS2) Ltd