Overview
In this role, you strengthen Ricoh’s European IT security, governance and resilience. You will work across infrastructure, cloud, identity and operations teams to shape policies, drive risk-based decisions and report on security maturity. You’ll translate frameworks into practical standards and partner with stakeholders to improve governance and controls. This is an opportunity to influence security at scale within a purpose-driven, inclusive organisation that values development and cross-functional collaboration. You’ll join a mission‑driven team that values voice, learning, and measurable impact on risk and resilience.
Pay / Benefits
- flexible working
- wellbeing resources
- recognition programmes
- Imagine. Change. Awards
- volunteering and sustainability initiatives
Responsibilities
- Develop and maintain IT security policies, standards and control requirements
- Build compliance dashboards and executive reporting using Power BI
- Measure and report IT security compliance across key technology domains
- Manage and maintain the IT Security Risk Register
- Facilitate risk assessments and work with technical teams on mitigations
- Support audit, assurance and compliance activities including ISO 27001, Cyber Essentials and internal control programmes
- Translate security frameworks into practical operational standards
- Identify opportunities to improve governance, reporting and control effectiveness across the IT function
Key requirements
- Experience in IT Security, Information Security Governance, IT Risk or Compliance with stakeholder engagement at senior levels
- Experience developing security policies, standards and governance documentation
- Solid understanding of ISO 27001, NIST CSF and security control frameworks
- Experience producing compliance reporting and dashboards (Power BI)
- Knowledge of vulnerability management, patching, identity and access management, privileged access management and backup governance
- Excellent analytical, communication and stakeholder management skills
- Relevant certifications such as CISSP, CISM, CRISC or ISO 27001 Lead Auditor/Implementer are advantageous
- Analytical thinking
- Strong communication
- Stakeholder management
- IT Security
- IT Risk
- Security Governance
…
