Head of Governance Risk and Compliance
Listed on 2026-07-19
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
About the Role
The Head of Governance, Risk & Compliance is a senior leadership role within NESO's Security function, reporting directly to the Chief Information Security Officer (CISO).
This role is responsible for developing, implementing and continually enhancing NESO's security governance framework, threat-led cyber risk management framework and assurance strategy across one of the UK's most critical national infrastructure organisations.
This is a strategic role that requires close working with Executive stakeholders, the CIO leadership team, Enterprise Risk Management, Internal Audit, regulators and industry partners to ensure cyber and physical security risks are effectively understood, governed and managed in line with NESO's risk appetite and regulatory obligations.
The successful candidate will play a pivotal role in embedding a proactive risk culture, strengthening regulatory confidence, and ensuring security is integrated into NESO's digital, operational and business transformation agenda.
his role is designated as requiring a National Security Vetting (NSV) clearance. The level of clearance associated with this role (SC) will usually need you to have been a resident in the UK for the last five years to apply. We would invite any applicants who do not currently meet this residency requirement to still express an interest in the role.
This role can be based from Wokingham or Warwick and we continue to offer hybrid working from office and home.
Key Accountabilities Governance & Strategy- Lead the development and continual evolution of NESO's Security Governance Framework, ensuring alignment with organisational strategy, risk appetite and regulatory obligations.
- Develop and maintain security policies, standards, control frameworks and governance processes across cyber, technology and operational environments.
- Act as a strategic advisor to the CISO on governance, risk and assurance matters.
- Develop and operate NESO's enterprise cyber risk management framework, aligned to NIS Regulations, and external standards such as CAF, ISO 27001, and enterprise risk management processes.
- Drive a threat-informed approach to risk identification, assessment, prioritisation and treatment.
- Establish clear risk ownership and accountability across the organisation.
- Lead development of Board and Executive Committee cyber risk reporting.
- Provide independent challenge and assurance to major technology and business programmes.
- Develop and implement a comprehensive cyber assurance strategy covering technology, operational environments, third parties and critical suppliers.
- Lead NESO's compliance activities relating to NIS Regulations, CAF, ISO
27001 and other applicable regulatory obligations. - Manage relationships with regulators, auditors and external assurance providers.
- Establish metrics and reporting that provide meaningful insight into control effectiveness and organisational resilience.
- Ensure governance, risk and assurance activities support NESO's digital, data, AI and technology transformation agenda.
- Embed secure-by-design and risk-based decision-making into technology delivery, cloud adoption and Dev Sec Ops practices.
- Provide strategic oversight and challenge to major change programmes.
- Provide governance, risk and assurance oversight for emerging technologies, including Artificial Intelligence (AI), ensuring their adoption aligns with NESO's risk appetite, regulatory obligations and security requirements.
- Lead and develop a high-performing Governance, Risk & Compliance function.
- Foster a proactive security culture that promotes accountability, transparency and continuous improvement.
- Build strong relationships across operational, technology and business teams to drive shared ownership of risk.
Applicants must have the right to work in the UK by the start of employment. Visa sponsorship may not be available for this role and will be considered in line with business requirements.
About YouWe are seeking a strategic security leader with the ability to operate at both executive and technical levels. You will combine strong governance and risk leadership capabilities with sufficient technical credibility to challenge technology decisions, understand emerging threats and influence security outcomes across complex environments.
Essential- Significant experience leading Cyber Security Governance, Risk and Compliance functions within critical national infrastructure, highly regulated or complex operational environments.
- Demonstrable experience designing and implementing enterprise security governance and threat-led risk management frameworks.
- Proven track record leading NIS Regulations and CAF compliance programmes.
- Experience providing cyber risk reporting and strategic advice to Boards, Executive Committees and regulators.
- Experience operating within digital transformation, cloud, data, AI and Dev Sec Ops environments.
- Experience leading assurance…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: