Governance, Risk & Regulatory Compliance Director, Quality Risk & Security, Enabling Functions

Company: Deloitte
Apply for the Governance, Risk & Regulatory Compliance Director, Quality Risk & Security, Enabling Functions
Location: Cardiff
Job Description:

Overview

As GRRC Director within Deloitte Business Security, you will lead the second line of defence for governance, risk and regulatory compliance across confidentiality, privacy and security. You own the integrated framework, produce executive risk insights for leadership and boards, and lead a multidisciplinary team to embed robust GRC and risk management. You will monitor forward-looking regulatory developments and ensure alignment with the Enterprise Risk Management framework. You collaborate across CPS, QRS, Enabling Functions and global risk teams to drive impactful risk outcomes.

Pay / Benefits

  • hybrid working
  • wellbeing emphasis
  • career development
  • return-to-work coaching
  • inclusive team culture
  • supportive leadership

Responsibilities

  • Develop and own the integrated GRC framework for CPS pillars (confidentiality, privacy, security) including taxonomy, risk appetite, KRIs, and reporting
  • Translate CPS risk for non-technical executives and assess residual risk based on threat exposure and control effectiveness
  • Provide second-line GRC challenge to first-line information security and relevant business teams
  • Oversee ISMS, ISO certifications, and CPS-related ISQM1/QC1000 components with audit governance
  • Lead regulatory radar for UK/EU developments and implement changes into BAU operations
  • Foster collaboration across three lines of defence and enable effective information sharing
  • Lead emerging risks, translate to actionable risk register changes and control framework, drive scenario analysis
  • Manage central CPS operations and drive delivery of strategic priorities
  • Develop and inspire a high-performing, inclusive GRRC team and talent development programs
  • Collaborate with CPS, QRS, Enabling Functions, Enterprise and global risk teams

Key requirements

  • Track record of executive and board-level risk reporting
  • Strong leadership and people management across multi-functional teams
  • Working knowledge of UK GDPR, NIS2, ISO 27001, ISO 42001, ISQM1, QC1000 and FCA rules relevant to in-scope entities
  • In-depth knowledge of risk assessment methodologies and change leadership in risk landscapes
  • Strong influence without authority and cross-team collaboration
  • Excellent communication and stakeholder management skills
  • Relevant professional certifications (e.g., ISO 27001 Lead Implementer/Lead Auditor, IRM) are highly desirable
  • Experience in horizon scanning and regulatory radar for CPS or similar domains
  • leadership
  • stakeholder management
  • communication
  • UK GDPR
  • NIS2
  • ISO 27001

…

Posted: September 27th, 2026