Lead Information Security Officer

Company: University College London
Apply for the Lead Information Security Officer
Location: London
Job Description:

Overview

In this role you will lead the Governance, Risk, and Compliance function within UCL’s Information Security Group and head a new Information Security Consulting Team. You’ll set security standards for the university and help teams meet them, mentoring junior staff and translating security concepts for non-technical colleagues. You will collaborate with central IT, departments, and researchers to enable secure, advancement-oriented work at scale. This is a mission-driven opportunity to strengthen security while supporting innovation across the university.

Pay / Benefits

  • 41 days holiday (incl. 27 days annual leave, 8 bank holidays, 6 closure days)
  • CARE pension scheme
  • Cycle to work scheme and season ticket loan
  • On-site nursery
  • On-site gym
  • Enhanced maternity, paternity and adoption pay

Responsibilities

  • Set and maintain university-wide security standards and controls
  • Lead and mentor the Information Security Consulting Team
  • Provide security support and guidance to non-security teams
  • Build trust with stakeholders across central IT, departments, and research units
  • Drive security-related change programmes and ensure adoption across the university
  • Foster knowledge sharing and capability development within the team

Key requirements

  • Significant experience in a GRC role within a large complex organisation
  • In-depth information security knowledge and ability to explain it to non-security and non-technical colleagues
  • Strong stakeholder confidence-building and communication skills
  • Willingness to share knowledge and mentor junior colleagues
  • Strategic thinking with ability to address immediate needs
  • Experience with security-focused and broader IT or organisational change programmes
  • Passion for working in a research-driven, knowledge-expansive environment
  • Strategic thinking
  • Excellent communication
  • Stakeholder management
  • GRC expertise
  • Information security principles
  • Security standards development

Posted: September 14th, 2026