Supervisor, IT Security, Governance, Risk & Compliance
Listed on 2026-10-07
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Location(s):
Winnersh, GB, RG41 5TS
We Make Life More Rewarding and Dignified
Location
:
Winnersh
Department
: IT
The Supervisor, Governance, Risk & Compliance (GRC) leads and enhances the organization's cybersecurity governance, risk management, regulatory compliance, audit readiness, third-party risk, security awareness, privacy coordination, and policy management programs. The role provides both strategic direction and operational oversight while leading a team responsible for ensuring alignment with regulatory requirements, industry frameworks, contractual obligations, and internal security standards. The position serves as a key liaison across Cybersecurity, IT, Legal, Privacy, Compliance, Internal Audit, Quality, and business functions to ensure cybersecurity risks are effectively identified, assessed, communicated, and managed in accordance with business objectives and risk appetite.
ResponsibilitiesTeam Leadership & Management:
- Lead, develop, and support a high-performing team of Cybersecurity Analysts.
- Set goals, monitor performance, provide feedback, and support professional development.
- Recruit, interview, onboard, and coach team members.
- Foster a collaborative team environment and work effectively with internal teams, business partners, and external vendors.
Security GRC Oversight:
- Oversee day-to-day Cybersecurity GRC activities, including risk assessments, compliance activities, audits, and security assessment coordination.
- Develop and maintain SOPs, playbooks, and runbooks for GRC processes with a focus on repeatability and automation.
- Evaluate and coordinate security GRC vendors, tools, and services.
Data Protection, DLP & Insider Risk:
- Oversee data protection governance, including data classification, sensitivity labeling, data handling standards, and protection of regulated, confidential, proprietary, and sensitive information.
- Partner with Privacy, Legal, Compliance, Infrastructure, Enterprise Architecture, and business teams to maintain data protection requirements across cloud, SaaS, endpoint, collaboration, and on-premises environments.
- Guide Data Loss Prevention control design, implementation, monitoring, tuning, exception handling, alert review, and risk-based escalation.
- Support insider risk management by reviewing sensitive data movement, coordinating investigations, recommending corrective actions, and reporting DLP and data protection trends to leadership.
AI Security Governance:
- Support AI security governance policies, standards, control requirements, and review processes.
- Assess risks from Generative AI, AI agents, machine learning platforms, third-party AI tools, prompt-based attacks, data leakage, shadow AI, and insecure AI integrations.
- Partner with AI governance, Privacy, Legal, Enterprise Architecture, application, and business teams to enable secure and responsible AI adoption.
- Define expectations for AI access, data inputs and outputs, logging, auditability, human oversight, and protection of intellectual property and sensitive data.
Governance:
- Develop and maintain cybersecurity policies, standards, and procedures, including requirements for data protection, DLP, insider risk, and AI security governance.
- Align cybersecurity governance activities with business objectives, regulatory requirements, and applicable security frameworks.
- Conduct regular reviews and updates of governance frameworks, controls, and reporting processes.
Risk Management:
- Identify, assess, prioritize, and report cybersecurity risks, including data protection, third-party, cloud, vulnerability, and AI-related risks.
- Develop and track risk mitigation plans and monitor remediation effectiveness.
- Perform risk assessments, vendor and software reviews, and vulnerability analyses.
Compliance & Reporting:
- Support compliance with relevant security, privacy, data protection, and AI governance regulations and standards, including PCI-DSS, ISO 27001, SOC, NIST Cybersecurity Framework, HIPAA, GDPR, and emerging AI regulatory expectations.
- Produce reports covering risk assessments, compliance posture, DLP trends, insider risk activity, AI governance status, incidents, vulnerabilities, and security awareness metrics.
- Participate in internal and external audits, prepare compliance materials, and perform other duties as assigned.
Perform other duties as required and assigned
May be required to work outside of normal business hours to respond to urgent cybersecurity matters.
Essential Functions of the Role- Communicate effectively via email, phone, and virtual…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).