Overview
In this role you will provide expert information security guidance across UCL, support risk assessments and assurance activities, and lead the development and improvement of security policies and standards. You will promote compliance with UCL’s security framework and drive GRC initiatives while mentoring colleagues. You’ll shape the university’s security posture through pragmatic, solution-focused leadership in collaboration with stakeholders. This is an opportunity to influence security across a leading HE institution and contribute to its digital transformation.
Pay / Benefits
- 41 Days holiday (27 days annual leave, 8 bank holidays, 6 closure days)
- 5 days annual leave purchase scheme
- CARE pension scheme
- Cycle to work scheme
- Relocation scheme for certain posts
- On-site nursery and gym
Responsibilities
- Provide expert advice on information security matters to a broad range of stakeholders
- Lead or contribute to security risk assessments, assurance reviews, audits, and compliance activities
- Develop, review, and implement information security policies, standards, guidance, or frameworks
- Promote and monitor compliance with UCL’s security framework in a pragmatic manner
- Provide leadership on GRC initiatives and mentor colleagues
- Build strong relationships with stakeholders at all levels and offer pragmatic, customer-focused security advice
- Support risk-based thinking across complex situations and contribute to the security governance agenda
Key requirements
- Experience in an Information Security or GRC team providing advisory services
- Experience leading or contributing to risk assessments, assurance reviews, audits, or compliance activities
- Strong knowledge of information security governance, risk management and compliance principles
- Experience developing or implementing information security policies, standards, guidance, or frameworks
- Excellent written and verbal communication with ability to present to technical and non-technical audiences
- Ability to build relationships with stakeholders at all levels and deliver pragmatic security guidance
- Relevant degree or equivalent professional qualifications and experience
- communication excellence
- stakeholder management
- pragmatic advisory mindset
- information security governance
- risk management
- compliance frameworks
…
