> Markdown version of [/jobs/ext/1579784-it-governance-lead](https://www.wearedevelopers.com/jobs/ext/1579784-it-governance-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Governance Lead - **Company:** ICP Worldwide, Inc. - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Software System Penetration Testing, Audit Trail, Microsoft Azure, Data Governance, Data Security, IT Management, Information Technology Operations, Knowledge Management, Runbook, Software Vulnerability Management, Information Security Management System, SARS Software Products, Microsoft InTune, Microsoft Fabric, Information Technology - **Published:** July 31, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=8ab9e28dd0585539 ## About the Role * Experience in IT operations, technical governance, service management or technology leadership. * Good working knowledge of Microsoft 365, Azure, Entra ID, Intune, Defender and Purview. * Experience with ISO 27001, audit evidence, IT risk management, compliance and change control. * Strong documentation, stakeholder management and business communication skills. * Ability to translate technical risk and control requirements into clear business language. Key attributes Structured, documentation-focused, security-conscious, risk-aware, commercially pragmatic, calm under pressure, accountable and comfortable working with senior stakeholders. ## Description Are you a relationship-focused, driven professional with a growth mindset? Do you thrive on breaking through challenges and excelling in competitive environments? You're not expected to have all the answers, but your passion for uncovering solutions and building strong partnerships makes you the perfect fit for this role. We'd love to hear from you! The IT Operations & Technical Governance Lead ensures ICP's IT environment remains secure, well-governed, documented, auditable and operationally resilient. The role focuses on IT governance, ISO 27001 maintenance, Microsoft 365 and Azure governance, risk management, documentation, compliance, and project-to-BAU transitions. Purpose of the role * Maintain effective IT governance, operational continuity and control evidence. * Support ISO 27001 post-certification activity, surveillance readiness and continual improvement. * Keep technical documentation, runbooks, architecture records and ownership models current. * Coordinate IT risk tracking, change control, Microsoft Purview activity and secure data collection. * Ensure new projects transition cleanly into business-as-usual support with clear ownership., IT Operations & Governance * Own and enhance IT governance processes, ensuring clear service ownership, support models, escalation pathways, and operational reporting across the technology estate. Technical Documentation & Knowledge Management * Maintain and continuously improve technical documentation, including architecture diagrams, runbooks, SOPs, design records, and project handover materials, ensuring operational resilience and knowledge retention. ISO 27001 & Compliance * Support the ongoing management of the Information Security Management System (ISMS), coordinating evidence collection, control ownership, audit readiness, surveillance activities, and continual improvement initiatives. Microsoft Purview & Data Governance * Coordinate Microsoft Purview and eDiscovery activities, supporting Subject Access Requests (SARs), evidence collection, audit trails, and the secure handling of sensitive information. Microsoft 365, Azure & Security Governance * Monitor and report on security and compliance metrics across Microsoft 365 and Azure, including Secure Score, Exposure Score, Defender recommendations, vulnerability management, and remediation progress. Change, Risk & Control Management * Ensure high-risk technology changes are appropriately documented, risk assessed, approved, and supported by auditable evidence, maintaining strong governance and regulatory compliance. Risk, Incident & Supplier Assurance * Maintain technology risk registers, supplier assurance records, penetration testing results, and incident follow-up actions, driving remediation and reducing organisational risk exposure. Project Transition & Operational Readiness * Ensure new technologies and projects transition seamlessly into Business-as-Usual support, with clear ownership, support processes, documentation, and operational accountability in place., * IT services and control processes are clearly documented, owned and resilient. * ISO 27001 evidence remains current and surveillance-ready. * Risks, vulnerabilities, recommendations and remediation actions are tracked and visible. * Purview/SAR activity is repeatable, secure and auditable. * Leadership has clear visibility of IT risk, operational maturity and open actions. Someone who exemplifies our ICP Values: * Curious: Always learning, eager to explore endless possibilities. * Inclusive: Diversity is our strength. Every voice matters and we can achieve more when we do it together. * Focused: With clear vision and unwavering dedication, we progress forward and deliver excellence. ## Related Videos - [Responsible AI @ Microsoft - Governance, Standards, Learnings](https://www.wearedevelopers.com/videos/1544-responsible-ai-microsoft-governance-standards-learnings) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift)