Overview
In this role within UCL’s Chief Information Security Office, you will advise on information security, support risk assessments and assurance activities, and help develop policies and standards. You will promote compliance with UCL’s security framework and lead GRC initiatives while mentoring colleagues. You’ll help strengthen UCL’s security posture across the university through pragmatic, solution-oriented collaboration with stakeholders. This is a chance to shape security governance in a sizable research and education environment.
Pay / Benefits
- 41 Days holiday
- Defined benefit career average revalued earnings pension scheme (CARE)
- Cycle to work scheme
- Relocation scheme for certain posts
- On-Site nursery
- On-site gym
Responsibilities
- Provide expert information security guidance to diverse stakeholders
- Lead or contribute to security risk assessments, assurance reviews, audits, and governance initiatives
- Develop, review, and implement information security policies, standards, and frameworks
- Promote and ensure compliance with UCL’s security framework
- Provide leadership on GRC initiatives and mentor colleagues
- Foster strong stakeholder relationships and deliver pragmatic security advice
Key requirements
- Experience in Information Security or Governance, Risk and Compliance teams
- Experience leading or contributing to risk assessments, assurance reviews, audits, or compliance activities
- Strong knowledge of information security governance, risk management and compliance principles
- Ability to apply risk-based thinking to complex situations
- Experience developing or implementing security policies, standards, or frameworks
- Excellent written and verbal communication for technical and non-technical audiences
- Experience building relationships with stakeholders at all levels and providing customer-focused security advice
- Relevant degree or equivalent professional qualifications and experience
- Excellent communication
- Stakeholder management
- Pragmatic problem-solving
- Information security governance
- Risk management and compliance
- Policy development and standards implementation
…
