Title: Head of Information Governance & Cyber Security
Location: East London – one day per week onsite
Contract: Initial six months, with potential to extend or become permanent/FTC
Rate: £550–£600 per day
IR35: Inside IR35
Start: As soon as possible
The Opportunity
We are working with a London local authority that requires an experienced Head of Service to lead its Information Governance and Cyber Security functions. This is a broad, hands‑on leadership role for someone who understands how an organisation should manage, protect and use its information. You will provide senior direction while remaining actively involved in complex governance, assurance and compliance matters. The position sits between traditional Information Governance and Cyber Security. It would suit someone with strong IG, data protection or information assurance experience who also understands Cyber Security governance, risk and compliance.
The Role
You will lead a service covering Information Governance and Cyber Security, supported by existing specialists within both areas.
- Providing advice on complex Information Governance, data protection, FOI and SAR matters.
- Reviewing and advising on DPIAs, data‑sharing arrangements and information risks.
- Overseeing DSPT and wider public‑sector compliance and assurance activity.
- Developing policies, governance processes and clear organisational standards.
- Ensuring information‑related decisions are lawful, proportionate and properly evidenced.
- Providing senior advice on sensitive cases and, where required, supporting regulatory or legal proceedings.
- Overseeing Cyber Security governance, risk and compliance.
- Reviewing the findings from IT health checks, penetration tests and security assessments.
- Challenging technical teams on identified risks and ensuring remediation is properly managed.
- Working across a significant portfolio of organisational and technology projects.
- Improving maturity across information management, data protection and Cyber Security.
- Reporting clearly to senior stakeholders on priorities, risks and progress.
- Leading and developing the service while remaining personally involved in important areas of work.
The role is not just focused on processing routine FOI or SAR requests, and you will not be expected to perform technical Cyber Security activity yourself. The emphasis is on handling complex matters, setting direction, providing assurance and making sure the right work is completed.
The Person
We are looking for someone who can demonstrate a credible balance across Information Governance and Cyber Security.
- Senior experience within Information Governance, data protection, Cyber Security GRC or information assurance.
- A good understanding of UK GDPR, the Data Protection Act, FOI and related information legislation.
- Experience advising on complex SARs, FOIs, DPIAs, breaches or data‑sharing questions.
- The confidence to explain and defend the reasoning behind sensitive information decisions.
- Experience of Cyber Security governance, risk, audit and compliance.
- The ability to interpret assurance findings and challenge technical teams on remediation.
- Experience developing policies, processes, controls and organisational governance.
- The ability to work independently, establish priorities and make progress quickly.
- A collaborative leadership style, with evidence of gaining cooperation and improving compliance.
- Strong communication skills and the credibility to advise senior managers and other stakeholders.
Local‑authority or wider public‑sector experience would be particularly useful, as would exposure to DSPT, Cabinet Office requirements, ICO engagement or formal legal proceedings.
You do not need to be an out‑and‑out technical Cyber Security specialist or to have formally managed every area of Information Governance. However, you must be able to provide informed, practical advice across both disciplines rather than relying entirely on other specialists.
Why Consider It?
This is an opportunity to take ownership of a developing service at an important point in its evolution. The successful person will have genuine scope to improve maturity, influence how the organisation manages information risk and shape the longer‑term structure of the function.
The initial appointment will be a contract, although the authority is considering how the role could develop into a longer‑term permanent or fixed‑term position for the right candidate
#J-18808-Ljbffr…
