Head of Governance, Risk and Compliance (Information Security
Job in
Luton, Bedfordshire, EX14, England, UK
Listed on 2026-08-12
Listing for:
Leonardo DRS
Full Time
position Listed on 2026-08-12
Job specializations:
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Job Description & How to Apply Below
Experteer Overview In this role, you lead the Governance, Risk and Compliance function for Information Security at Leonardo UK, shaping security standards, risk decisions, and assurance across the business. You will collaborate with delivery teams, system owners, and senior risk owners to embed proportionate governance throughout the system lifecycle. You'll oversee assurance activities and drive improvements to the operating model, tooling, and data-led reporting.
This is a senior, cross-site role with potential travel, demanding strong leadership and stakeholder engagement in a regulated environment.
- Lead the Information Security Governance, Risk and Compliance function
- Own and maintain UK Information Security standards, assurance arrangements, and governance processes
- Ensure security controls, risk decisions, and assurance are evidenced and reported across the business
- Collaborate with delivery teams, system owners, and senior risk owners to support governance through the lifecycle
- Oversee assurance activities, including reviews and audits against security plans and controls
- Support continual improvement of the Information Security Operating Model, including tooling, automation and data-led reporting
- Deputise for the Head of Information Security in senior forums and leadership contexts
- Experience in information security governance, risk and compliance
- Professional security qualification such as CISSP, CISM or equivalent
- Strong knowledge of security control frameworks and risk management practices
- Knowledge of cyber and information risk frameworks or methodologies (e.g., FAIR)
- Experience developing, maintaining or assuring security standards, policies, control frameworks or risk artefacts
- Understanding of MoD and UK government security policy and frameworks
- Experience in regulated, defence, aerospace or complex environments
- Practical understanding of risk assessment, residual risk, risk acceptance and non-compliance management
- Experience supporting audit, assurance, control testing or compliance reporting
- Ability to work with technical and non-technical stakeholders to ensure security requirements are evidenced and understood
- Experience producing governance, risk or assurance reporting for senior stakeholders
- Knowledge of security governance tooling, automation, dashboards or data-led reporting (beneficial)
- Time to Recharge with up to 12 flexi-days
- Employer pension scheme with up to 15% employer contribution
- Mental health support
- Bonus scheme
- Access to Coursera and Linked In Learning
- Hybrid working
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×