Free with a WorkJio account: we compare your profile with this job and show what you already meet.
Share with a friend
Start
Not stated
Work mode
On-site
Experience
Experienced
About the role
A senior group-level leadership position accountable for the cyber security policy, standards and compliance posture across the organisation and its operating companies. The role reports to the Group Chief Information Security Officer and suits an experienced governance, risk and compliance leader who can influence executives and Boards. It bridges business, technology and security by embedding disciplined policy governance and assurance into the operating model.
What you'll do
Own and govern the group cyber security policies, standards and control libraries, ensuring consistent application across operating companies and associates
Establish and evolve group-wide minimum cyber security requirements, including approving material policy updates, standards enhancements and control baselines
Assess policies and standards against industry best practice and regulatory expectations such as ISO/IEC, NIST, CIS Controls and GSMA
Own the policy exception and risk acceptance process, including escalation thresholds, decision authorities and documentation of residual risk
Drive security culture and controls adoption through stakeholder engagement, training and enablement
Define and own the group cyber security controls and risk framework, including methodologies for inherent risk, control effectiveness, control maturity and residual risk
Develop and maintain controls risk metrics, KRIs and gap indicators for consistent visibility of cyber posture
Translate controls and compliance outcomes into executive and Board-level insights to support prioritisation, remediation planning and risk decisions
Own the group compliance assurance framework, defining how compliance is assessed, validated and reported across operating companies and associates
Lead the shift from point-in-time assessments to continuous controls assurance using technology for near-real-time visibility
Establish and execute a group-wide digital GRC platform strategy as the single source of truth for governance, risk, compliance, exceptions and audit evidence
Drive adoption of automation and agentic AI to scale compliance assessments, evidence collection and controls monitoring while maintaining auditability and traceability
Serve as group authority on cyber governance and risk, advising and challenging senior management and Boards on risk posture and material exposures
Track emerging cyber threats, technologies such as AI and quantum, and regulatory developments, translating them into governance and control enhancements
Act as key interface with auditors and external assessors on cyber governance, compliance and assurance matters
Provide thought leadership and stakeholder engagement, balancing business enablement with risk discipline
Assist in planning and managing budgets for GRC programmes and recommend resource allocation strategies
Lead and contribute to cross-functional governance and collaborate with GRC leads across operating companies on policy interpret
Requirements
Bachelor's degree in computer science, information technology, cybersecurity or a related field
At least 10 years of experience in cybersecurity, technology risk or GRC roles
Experience operating in group-level, regional or multi-entity environments overseeing policy, risk and compliance
Experience leading and governing large-scale cybersecurity or technology risk initiatives
Experience setting group standards, driving compliance programmes and managing material risk issues
Experience engaging senior executives and Boards
Jio can write this application for you
Jio reads this job and your profile, then writes a short letter in your words. You read it, change anything, and send it yourself. Nothing is sent until you say so.