Supervisor, IT Security, Governance, Risk & Compliance
Listed on 2026-09-13
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Select how often (in days) to receive an alert:
Date:
Aug 27, 2026
Location(s):
Winnersh, GB, RG41 5TS
We Make Life More Rewarding and Dignified
Location
:
Winnersh
Department
: IT
The Supervisor, Governance, Risk & Compliance (GRC) leads and enhances the organization's cybersecurity governance, risk management, regulatory compliance, audit readiness, third-party risk, security awareness, privacy coordination, and policy management programs. The role provides both strategic direction and operational oversight while leading a team responsible for ensuring alignment with regulatory requirements, industry frameworks, contractual obligations, and internal security standards. The position serves as a key liaison across Cybersecurity, IT, Legal, Privacy, Compliance, Internal Audit, Quality, and business functions to ensure cybersecurity risks are effectively identified, assessed, communicated, and managed in accordance with business objectives and risk appetite.
ResponsibilitiesGovernance & Security Program Management
- Lead the development, implementation, and maintenance of cybersecurity governance programs, policies, standards, procedures, and guidelines.
- Align governance activities with business objectives, cybersecurity strategy, and enterprise risk appetite.
- Develop and maintain KPIs, KRIs, program metrics, and executive reporting.
- Drive cybersecurity program maturity and continuous improvement initiatives.
Cybersecurity Risk Management
- Lead enterprise cybersecurity risk assessments and maintain the cybersecurity risk register.
- Facilitate risk reviews, mitigation planning, risk acceptance, and remediation efforts.
- Evaluate cybersecurity risks associated with new technologies, cloud services, vendors, and business initiatives.
- Ensure risk decisions are documented, approved, and periodically reviewed.
- Communicate key risks, trends, and mitigation activities to leadership.
Compliance & Regulatory Oversight
- Manage compliance programs related to ISO 27001, SOC 2, HIPAA, GDPR, UK Cyber Essentials, NIST Cybersecurity Framework, and other applicable regulations.
- Coordinate control assessments, evidence collection, gap analyses, corrective actions, and compliance reporting.
- Monitor regulatory and industry changes and assess organizational impacts.
- Maintain an audit-ready cybersecurity compliance posture.
Audit & Assurance Management
- Serve as the primary cybersecurity coordinator for internal and external audits, certifications, and regulatory assessments.
- Lead audit preparation, evidence validation, stakeholder engagement, and responses.
- Track audit findings, corrective actions, and remediation progress.
- Provide status reporting and updates to leadership.
Third-Party Risk Management
- Oversee cybersecurity due diligence and risk assessments for vendors, suppliers, and service providers.
- Review security controls, certifications, contracts, and assessment responses for critical vendors.
- Coordinate remediation activities with vendors, procurement, legal, and business stakeholders.
- Establish ongoing monitoring and reporting practices for third-party security risks.
Security Awareness, Policy & Culture
- Lead enterprise security awareness and compliance training initiatives.
- Measure program effectiveness through participation and behavior-based metrics.
- Partner with HR and business leaders to strengthen security culture and accountability.
- Maintain cybersecurity policies through review, approval, communication, and lifecycle management processes.
- Supervise, coach, mentor, and develop GRC and data protection team members.
- Establish performance expectations, development plans, and accountability measures.
- Manage workload prioritization, resource allocation, and operational coverage.
- Promote collaboration, knowledge sharing, and continuous learning.
Stakeholder Engagement
- Collaborate with Cybersecurity, IT, Legal, Privacy, Internal Audit, Quality, Regulatory Affairs, Data & AI, and business leaders.
- Translate cybersecurity and compliance requirements into actionable business processes.
- Present program updates, compliance status, risks, and recommendations to leadership.
- Communicate effectively via email, phone, and virtual platforms.
- Collaborate across departments to support organizational goals.
- Participate in cross-functional meetings and initiatives.
- Prepare reports and dashboards for internal stakeholders.
- Ensure data accuracy and confidentiality in compliance with company and legal standards.
- Demonstrate initiative in identifying process…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).