Cyber Security Risk & Governance Manager
Listed on 2026-07-21
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, IT Project Manager
Cyber Security Risk & Governance Manager Role Purpose
The Cyber Security Risk & Assurance Lead is responsible for defining, implementing, and governing IT security policies, standards, and compliance frameworks across the organisation. This role ensures that security controls are embedded into IT architecture and delivery, while maintaining alignment with regulatory requirements and organisational risk appetite.
Operating as part of a central horizontal IT Security function, this role works closely with Architecture, Delivery, and Service teams, providing oversight, assurance, and governance rather than hands‑on operational security execution. The role is governance‑led, focusing on defining what “good” looks like and ensuring it is consistently applied. The Cyber Security Risk & Assurance Lead provides oversight and assurance, while operational security execution remains with IT Security Engineers within the Service Delivery function.
Key Responsibilities- Security Policy & Standards
- Governance & Compliance
- Audit & Assurance
- Security Architecture Alignment
- Risk Management
- Stakeholder Engagement
- Vendor & Third‑Party Security
- Continuous Improvement & Awareness
- Holder of relevant Cyber Security certifications – e.g., CISM, CCSP or CISSP
- Strong knowledge of security frameworks (ISO
27001, NIST, CIS Controls) - Understanding of cloud security principles (Azure, AWS, or GCP)
- Familiarity with identity and access management, data protection, resilience & loss prevention, and network security tools and concepts
- Experience with risk management and compliance tooling (GRC platforms desirable)
- Experience with selecting, deploying, maintaining and securing IT systems in a mid‑sized UK organisation
- Familiarity with popular UK law firm applications and services is advantageous
- Ideally 7–10 years in IT and security, with a focus on governance, risk, and compliance
- Experience managing audits and regulatory requirements
- Experience working within enterprise IT environments and architecture governance structures, ideally in a legal setting
- Experience in regulated industries (preferred)
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: