Head of IT Security Governance, Risk & Compliance

·
Full time
Location: Birmingham
·
Job offered by: GKN Automotive
·
Category:
Head of IT Security Governance, Risk & Compliance

United Kingdom Job Description

Head of IT Security Governance, Risk & Compliance The Head of IT Security Governance, Risk & Compliance is responsible for overseeing GKN Automotive’s cybersecurity governance framework, ensuring effective management of security risks, compliance with relevant regulations, and alignment with industry best practices across multiple international locations. You will lead the GRC team in a strategic and technical capacity, collaborating with other functions within GKN Automotive to embed security into the organisation’s culture and operations. You will play a critical role in defining policies, managing compliance initiatives, and identifying risks while implementing measures to address them. As the key authority for governance, risk, and compliance in cybersecurity, you will ensure that GKN Automotive meets its regulatory and legal obligations while fostering a proactive and resilient security posture. Reporting to the Director of IT Security you will provide regular KPI reporting including updates on the risk landscape and compliance. Key responsibilities Leadership and Coordination:

Lead the Security Governance, Risk & Compliance team to deliver best practice security capabilities globally. Ensure a consistent and repeatable approach to security across all regions and sites.

Compliance and Audits:

Ensure compliance with relevant regulations, frameworks, and standards (e.g., TISAX, ISO 27001, CIS, GDPR) across all operational regions.

Security Awareness, Training and Posture Improvement:

Drive security awareness and training programs to embed a culture of compliance and risk management across the organisation. Define program goals and roadmaps based on GKN Automotive’s needs and strategic direction and ensure that committed projects are delivered on schedule by the relevant team members.

Security Governance and Risk Management:

Develop, implement, and maintain GKN Automotive's IT security governance framework and associated policies, standards, and procedures. Monitor changes in the regulatory landscape and adapt policies and procedures to maintain compliance. Oversee the identification, assessment, and management of IT security risks to ensure the organisation’s resilience. Oversee security risk registers, ensuring regular assessments and timely risk treatment activities. Assist in implementing remediation actions to mitigate risks and meet best practice expectations. Collaborate with stakeholders to integrate risk management into business processes and technology solutions.

Consultancy and Advice:

Provide information security consultancy and advice to other GKN Automotive teams. Organise forums to share good practices and improvement initiatives for security enhancements.

Reporting:

Prepare and present reports on governance, risk, and compliance metrics to senior leadership and the board. Report to senior business stakeholders including IT Directors, VPs, and CIO.

Skills Experience and Knowledge:

Extensive experience in IT security governance, risk management, and compliance within a global organisation. Strong knowledge of regulatory requirements, standards, and frameworks (e.g., ISO 27001, CIS, GDPR, NIST). Strong analytical and problem-solving skills, with the ability to manage complex and competing priorities. Relevant certifications such as CISM, CRISC, CISSP, or ISO 27001 Lead Auditor/Implementer are highly desirable.

Leadership and Communication:

Proven leadership skills with experience managing and developing high-performing teams. Exceptional stakeholder management and communication skills, with the ability to influence at all organisational levels. Able to deputise for the Director of IT Security.

Organisational Skills:

Ability to work on own initiative and meet personal deadlines while contributing to global team objectives. Good organisational skills and attention to detail.

Education Bachelors or masters degree in computer science, IT security, information systems, or a related field. Experience At least 7 years of experience in information security, with a focus on leading security functions. Experience in deputising for CISO/director of IT Security. Experience with recognised security frameworks and standards, such as TISAX, ISO 27001, NIST and CIS. Must be able to demonstrate the ability to lead teams and manage global security governance, risk & compliance effectively. Proven track record in stakeholder and partner/vendor management and collaboration across various departments. Must have practical experience with GRC tools. Must have experience in presenting up to C-Suite level. Must have experience in enhancing Security GRC capabilities to align with the strategic objectives of the business and address the risks posed by an evolving threat landscape.

#J-18808-Ljbffr

Recent Jobs

London (On site) · Full time

Are you a smart, driven professional who takes pride in making a difference in local communities? Turner & Townsend’s Real Estate division is experiencing significant growth and we’re looking for an experienced industry professional with health project experience to join our high-performing and collaborative Project Management team. Why Join Us? Impactful Work: Contribute to social [...]Read More... from Assistant Project Manager – Healthcare See details

Chasetown (On site) · Full time

My client, Autosmart International are a manufacturing success story! Site Operations Manager – leading fast-paced manufacturing and warehousing About Our Client Autosmart International is a manufacturing success story, leading the field in vehicle cleaning products. We are the No.1 choice of automotive trade customers across the UK. We have doubled in size in the last [...]Read More... from Site Operations Manager See details

London (On site) · Full time

CSS are looking for an experienced duty officer to join our client’s team who are a local council responsible for all areas within the Tendering district. Working hours: All shifts are 8 hours long with various start times available: Monday to Friday – start times between 6AM – 3PM Saturday & Sunday – 6AM – [...]Read More... from Duty Officer See details