Cyber Governance Specialist - Ref 2863
Listed on 2026-08-19
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Join a people-centred technology team that thrives on innovation, collaboration, and delivering meaningful outcomes. We are seeking a talented and motivated Cyber Governance Specialist to join a growing Cyber Security team. In this role, you will play a key part in supporting the effective operation of a cyber governance programme, helping to translate cyber security strategy, policies, and standards into structured, repeatable governance processes across the organisation.
Working closely with stakeholders across enterprise IT, operational technology, and supply chain environments, you will support security reviews, track remediation activities, monitor performance metrics, and deliver insightful reporting to senior leadership and governance forums. If you enjoy bringing structure to complex environments, influencing positive security outcomes, and contributing to a strong culture of governance and continuous improvement, we'd love to hear from you.
Contract Type
:
Permanent preferred (contract considered)
- Operate the governance processes and calendar — review gates, reporting cycles, forum cadences, and evidence deadlines — that give effect to the Cyber Security Standard and its supporting policy suite
- Conduct cyber security reviews of IT and business projects at defined lifecycle gates in line with agreed process and approach, agreeing proportionate remediation actions with project owners and tracking them to closure
- Maintain the central registers of security actions and policy exceptions, validating evidence of completion to a standard suitable for internal audit and regulatory inspection
- Support cyber security risk management processes, including risk register administration and associated reporting
- Collect, validate, and trend cyber security KPIs and KRIs, and produce recurring report packs for the security steering group, executive risk committee, and project and portfolio boards
- Support the Assurance function in collating evidence for CAF self-assessment and regulatory inspection preparation; ownership of regulatory evidence and regulator engagement remains with Assurance
- Operate the supplier cyber assessment procedure and maintain the supplier assurance record.
- Contribute to the selection and administration of GRC tooling, and refine governance processes and templates as the programme matures
The role holder is accountable for:
- Governance forums receive accurate, complete report packs on time, every cycle
- Cyber reviews of projects are completed within agreed service levels and recorded consistently
- The action and evidence registers are current, complete, and audit-ready at all times
- KPI and KRI data presented to governance forums is accurate and traceable to source
- The exception register is current, with expiring exceptions escalated before lapse
- Governance processes are documented such that they can be operated by others, with no key-person dependency
- Risks, blockers, and material non-compliance identified through governance activity are escalated promptly
- Demonstrable experience operating cyber or information security governance processes
- Experience conducting security reviews or assessments of projects and change against defined policies and standards
- Working knowledge of at least one recognised security framework: NCSC Cyber Assessment Framework, ISO/IEC 27001, or NIST CSF
- Experience producing governance reporting
- Strong communication and stakeholder management skills
- Ability to work collaboratively across teams
- Strong analytical and problem-solving skills
- Ability to manage competing priorities effectively
- Commitment to continuous improvement and organisational values
- Experience with in an Operator of Essential Services or organisation subject to the NIS Regulations
- Experience of supplier or third-party cyber risk assessment
- Experience administering GRC tooling
Technology is constantly evolving, and so are we.
Since our beginnings as a managed IT services provider, prosource.it has grown alongside the organisations we support, adapting to changing technologies and business needs. Today, we deliver a broad range of technology and business services…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: