About the Role
The Head of Governance, Risk & Compliance is a senior leadership role within NESO’s Security function, reporting directly to the Chief Information Security Officer. The role is responsible for developing, implementing and continually enhancing NESO’s security governance framework, threat‑led cyber risk management framework and assurance strategy across one of the UK’s most critical national infrastructure organisations.
The successful candidate will embed a proactive risk culture, strengthen regulatory confidence and ensure security is integrated into NESO’s digital, operational and business transformation agenda. This role requires a National Security Vetting clearance (SC). Applicants who do not currently meet the residency requirement may still express interest. The role is based in Wokingham or Warwick, with hybrid working options.
Key Accountabilities
Governance & Strategy
- Lead the development and continual evolution of NESO’s Security Governance Framework, ensuring alignment with organisational strategy, risk appetite and regulatory obligations.
- Develop and maintain security policies, standards, control frameworks and governance processes across cyber, technology and operational environments.
- Act as a strategic advisor to the CISO on governance, risk and assurance matters.
Threat‑Led Risk Management
- Develop and operate NESO’s enterprise cyber risk management framework, aligned to NIS Regulations, CAF, ISO27001 and enterprise risk management processes.
- Drive a threat‑informed approach to risk identification, assessment, prioritisation and treatment.
- Establish clear risk ownership and accountability across the organisation.
- Lead development of Board and Executive Committee cyber risk reporting.
- Provide independent challenge and assurance to major technology and business programmes.
Compliance & Assurance
- Develop and implement a comprehensive cyber assurance strategy covering technology, operational environments, third parties and critical suppliers.
- Lead NESO’s compliance activities relating to NIS Regulations, CAF, ISO27001 and other regulatory obligations.
- Manage relationships with regulators, auditors and external assurance providers.
- Establish metrics and reporting that provide meaningful insight into control effectiveness and organisational resilience.
Secure by Design & Transformation
- Ensure governance, risk and assurance activities support NESO’s digital, data, AI and technology transformation agenda.
- Embed secure‑by‑design and risk‑based decision‑making into technology delivery, cloud adoption and DevSecOps practices.
- Provide strategic oversight and challenge to major change programmes.
- Provide governance, risk and assurance oversight for emerging technologies, including AI, ensuring their adoption aligns with NESO’s risk appetite, regulatory obligations and security requirements.
Leadership & Culture
- Lead and develop a high‑performing Governance, Risk & Compliance function.
- Foster a proactive security culture that promotes accountability, transparency and continuous improvement.
- Build strong relationships across operational, technology and business teams to drive shared ownership of risk.
Applicants must have the right to work in the UK by the start of employment. Visa sponsorship may not be available for this role.
About You
You are a strategic security leader with the ability to operate at both executive and technical levels. You combine strong governance and risk leadership capabilities with sufficient technical credibility to challenge technology decisions, understand emerging threats and influence security outcomes across complex environments.
Essential
- Significant experience leading Cyber Security Governance, Risk and Compliance functions within critical national infrastructure, highly regulated or complex operational environments.
- Demonstrable experience designing and implementing enterprise security governance and threat‑led risk management frameworks.
- Proven track record leading NIS Regulations and CAF compliance programmes.
- Experience providing cyber risk reporting and strategic advice to Boards, Executive Committees and regulators.
- Experience operating within digital transformation, cloud, data, AI and DevSecOps environments.
- Experience leading assurance activities across technology and third‑party ecosystems.
- Strong understanding of modern cyber threats, threat intelligence and risk management methodologies.
- Experience building and leading high‑performing teams.
Desirable
- Energy sector experience.
- Experience working closely with NCSC, Ofgem or other regulatory bodies.
- Holding CISSP, CISM, CRISC, ISO27001 Lead Implementer/Auditor or equivalent.
- Experience developing governance, risk management and assurance approaches for emerging technologies, including AI, Generative AI and advanced analytics, with understanding of associated security, ethical and regulatory considerations.
What You’ll Get
- Competitive salary of £85,000 – £100,000, dependent on experience and capability.
- Benefits allowance, bonus up to 20% of salary for stretch performance, private medical insurance and 28 days annual leave.
- Competitive contributory pension scheme with company match up to 12% of contribution.
- Flexible benefits programme including:
- Flexible Bank Holidays & Holiday Trading
- Additional Birthday Day Off
- Cycle to Work Scheme, Retail & Gym Discounts
- Critical Illness Insurance & Personal Accident Insurance
NESO is an equal opportunity employer. We are committed to building a workforce that represents the communities we serve and to creating an environment in which every individual feels valued, respected, fairly treated and able to reach their full potential.
#J-18808-Ljbffr…
