Head of Information Governance & Cyber Security

JLA Resourcing Ltd
Greater London, UK
4 days ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£143,000.0 - £156,000.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cyber Security Data Sharing Information Management SARS Software Products

Job description

We are working with a London local authority that requires an experienced Head of Service to lead its Information Governance and Cyber Security functions. This is a broad, hands-on leadership role for someone who understands how an organisation should manage, protect and use its information. You will provide senior direction while remaining actively involved in complex governance, assurance and compliance matters. The position sits between traditional Information Governance and Cyber Security. It would suit someone with strong IG, data protection or information assurance experience who also understands Cyber Security governance, risk and compliance.

The Role

You will lead a service covering Information Governance and Cyber Security, supported by existing specialists within both areas. Key responsibilities will include:

  • Providing advice on complex Information Governance, data protection, FOI and SAR matters.
  • Reviewing and advising on DPIAs, data-sharing arrangements and information risks.
  • Overseeing DSPT and wider public-sector compliance and assurance activity.
  • Developing policies, governance processes and clear organisational standards.
  • Ensuring information-related decisions are lawful, proportionate and properly evidenced.
  • Providing senior advice on sensitive cases and, where required, supporting regulatory or legal proceedings.
  • Overseeing Cyber Security governance, risk and compliance.
  • Reviewing the findings from IT health checks, penetration tests and security assessments.
  • Challenging technical teams on identified risks and ensuring remediation is properly managed.
  • Working across a significant portfolio of organisational and technology projects.
  • Improving maturity across information management, data protection and Cyber Security.
  • Reporting clearly to senior stakeholders on priorities, risks and progress.
  • Leading and developing the service while remaining personally involved in important areas of work.

The role is not just focused on processing routine FOI or SAR requests, and you will not be expected to perform technical Cyber Security activity yourself. The emphasis is on handling complex matters, setting direction, providing assurance and making sure the right work is completed.

Requirements

  • Senior experience within Information Governance, data protection, Cyber Security GRC or information assurance.
  • A good understanding of UK GDPR, the Data Protection Act, FOI and related information legislation.
  • Experience advising on complex SARs, FOIs, DPIAs, breaches or data-sharing questions.
  • The confidence to explain and defend the reasoning behind sensitive information decisions.
  • Experience of Cyber Security governance, risk, audit and compliance.
  • The ability to interpret assurance findings and challenge technical teams on remediation.
  • Experience developing policies, processes, controls and organisational governance.
  • The ability to work independently, establish priorities and make progress quickly.
  • A collaborative leadership style, with evidence of gaining cooperation and improving compliance.
  • Strong communication skills and the credibility to advise senior managers and other stakeholders.

Local-authority or wider public-sector experience would be particularly useful, as would exposure to DSPT, Cabinet Office requirements, ICO engagement or formal legal proceedings.

You do not need to be an out-and-out technical Cyber Security specialist or to have formally managed every area of Information Governance. However, you must be able to provide informed, practical advice across both disciplines rather than relying entirely on other specialists.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:18 min

Utilizing AI and public data sharing for urban planning

Christian Wiegand +3 · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

55 sec

Managing information overload during complex production system incidents

Anthony Alaribe Anthony Alaribe · World Congress 2025

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

3:42 min

Applying the satellite architecture for machine learning isolation

Christoph Fassbach Christoph Fassbach +1 · World Congress 2024

Videos

See all

Related articles

See all