Governance, Risk Compliance Lead
Remote / Online - Candidates ideally in
City Of London, Central London, Greater London, England, UK
Listed on 2026-09-12
City Of London, Central London, Greater London, England, UK
Listing for:
Infosec
Full Time, Remote/Work from Home
position Listed on 2026-09-12
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Our client, an essential services operator within the utilities and technology sectors, is seeking a Cyber Security Governance, Risk & Compliance Lead for a permanent position based in London with hybrid working. The role will support regulatory engagement, cyber resilience and compliance activities, helping to ensure alignment with NIS Regulations, NIS2, Ofgem expectations, the Enhanced Cyber Assessment Framework (ECAF) and ISO 27001.
Occasional travel to Belgium and Norfolk may be required.
- Act as the primary point of contact for cyber security regulatory engagement with Ofgem, competent authorities, auditors and external stakeholders
- Coordinate regulatory submissions, NIS self-assessments, improvement plans, evidence packs and responses to regulatory enquiries, inspections and audits
- Lead assurance activities across NIS Regulations, NIS2, Ofgem cyber security requirements, ECAF, ISO 27001 and other relevant resilience frameworks
- Monitor emerging cyber security legislation, regulatory requirements and industry guidance, assessing their impact and recommending appropriate actions
- Maintain and review the Cyber Security Risk Register, ensuring threat scenarios, mitigations, treatment plans and governance arrangements remain current
- Support the governance and status reporting of the Cyber Security Roadmap, including risks, issues, actions, dependencies and third-party deliverables
- Develop and maintain a cyber security supply chain assurance programme, including supplier risk assessments, due diligence and ongoing third-party assurance
- Prepare dashboards, key performance indicators, reports and briefing materials for senior leadership and Board-level oversight
- Significant experience in cyber security governance, risk and compliance within a regulated or critical infrastructure environment
- Strong knowledge of risk assessments, risk analysis, risk registers and cyber security treatment plans
- Experience of third-party management, supplier risk assessments and supply chain assurance
- Understanding of NIS Regulations, NIS2, Ofgem requirements, ECAF and the regulatory obligations of an Operator of Essential Services
- Experience supporting audit and review activities, regulatory submissions, assurance programmes and improvement plans
- Knowledge of Information Security Management Systems, including cyber security policies, standards, procedures and governance
- Ability to interpret changing legislation and industry guidance, translating requirements into practical compliance actions
- Excellent report writing, stakeholder management and communication skills, with the confidence to present complex information clearly to senior audiences
- Hybrid working in line with the organisation's policy, combining office and remote working
- Occasional travel to Belgium, Norfolk and other locations as required
- Opportunity to contribute to the cyber resilience of essential national infrastructure
- Role with broad exposure to regulatory engagement, cyber risk management and strategic improvement programmes
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×