> Markdown version of [/jobs/ext/2727349-supervisor-it-security](https://www.wearedevelopers.com/jobs/ext/2727349-supervisor-it-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Supervisor, IT Security - **Company:** Hollister Incorporated - **Location:** Winnersh, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Agile Methodology, Artificial Intelligence, Microsoft Azure, Cyber Security, Information Systems, Information Leak Prevention, Identity and Access Management, Information Systems Security Architecture Professional, Cloud Services - **Published:** September 5, 2026 - **Apply:** https://www.careerjet.co.uk/job/gb5b02ccd642311c162aa0b040207e0a28/eaa ## About the Role * Bachelor's Degree with 8-12 years of related experience, * Progressive experience in cybersecurity, governance, risk management, compliance, audit, or information security. * 3+ years of people leadership, supervisory, or demonstrated workstream leadership experience. * Experience supporting or leading ISO 27001, SOC 2, HIPAA, privacy, or similar compliance programs. * Experience conducting risk assessments, managing audits, tracking remediation activities, and performing third-party security risk assessments. * Experience within healthcare, medical device, manufacturing, life sciences, or other regulated industries. * Experience working within a global cybersecurity governance environment. * Experience building, implementing, or maturing enterprise GRC programs and reporting outcomes to leadership. * Preferred Certifications * Certified Information Security Manager (CISM) * Certified Information Systems Security Professional (CISSP) * Certified in Risk and Information Systems Control (CRISC) * Certified Internal Auditor (CIA) * ISO 27001 Lead Implementer or Lead Auditor * Certified Data Privacy Solutions Engineer (CDPSE) * Preferred Knowledge & Competencies * Cybersecurity governance frameworks (ISO 27001, SOC 2, NIST CSF) * Risk assessment and audit management methodologies * HIPAA, GDPR, privacy, and regulatory compliance requirements * Vendor risk management and continuous monitoring * Microsoft Purview, Azure security and compliance concepts, identity and access management, and data loss prevention * Strategic thinking, business acumen, executive communication, people development, cross-functional collaboration, and risk-based decision making., * Be Agile - Innovates and adapts quickly, approaching change with curiosity while persisting through obstacles. * Be Customer Centric - Considers the needs, experiences and feedback of customers in all we do. * Be People-Focused - Builds trust and collaborates with an inclusive and empathetic approach. * Be Performance Driven - Operates with an ownership mindset, driving meaningful outcomes. * Live The Schneiders' Legacy, Our Noble Purpose - Passionately serves Our Mission and Vision, while demonstrating the Immutable Principles. ## Description The Supervisor, Governance, Risk & Compliance (GRC) leads and enhances the organization's cybersecurity governance, risk management, regulatory compliance, audit readiness, third-party risk, security awareness, privacy coordination, and policy management programs. The role provides both strategic direction and operational oversight while leading a team responsible for ensuring alignment with regulatory requirements, industry frameworks, contractual obligations, and internal security standards. The position serves as a key liaison across Cybersecurity, IT, Legal, Privacy, Compliance, Internal Audit, Quality, and business functions to ensure cybersecurity risks are effectively identified, assessed, communicated, and managed in accordance with business objectives and risk appetite. Responsibilities Governance & Security Program Management * Lead the development, implementation, and maintenance of cybersecurity governance programs, policies, standards, procedures, and guidelines. * Align governance activities with business objectives, cybersecurity strategy, and enterprise risk appetite. * Develop and maintain KPIs, KRIs, program metrics, and executive reporting. * Drive cybersecurity program maturity and continuous improvement initiatives. Cybersecurity Risk Management * Lead enterprise cybersecurity risk assessments and maintain the cybersecurity risk register. * Facilitate risk reviews, mitigation planning, risk acceptance, and remediation efforts. * Evaluate cybersecurity risks associated with new technologies, cloud services, vendors, and business initiatives. * Ensure risk decisions are documented, approved, and periodically reviewed. * Communicate key risks, trends, and mitigation activities to leadership. Compliance & Regulatory Oversight * Manage compliance programs related to ISO 27001, SOC 2, HIPAA, GDPR, UK Cyber Essentials, NIST Cybersecurity Framework, and other applicable regulations. * Coordinate control assessments, evidence collection, gap analyses, corrective actions, and compliance reporting. * Monitor regulatory and industry changes and assess organizational impacts. * Maintain an audit-ready cybersecurity compliance posture. Audit & Assurance Management * Serve as the primary cybersecurity coordinator for internal and external audits, certifications, and regulatory assessments. * Lead audit preparation, evidence validation, stakeholder engagement, and responses. * Track audit findings, corrective actions, and remediation progress. * Provide status reporting and updates to leadership. Third-Party Risk Management * Oversee cybersecurity due diligence and risk assessments for vendors, suppliers, and service providers. * Review security controls, certifications, contracts, and assessment responses for critical vendors. * Coordinate remediation activities with vendors, procurement, legal, and business stakeholders. * Establish ongoing monitoring and reporting practices for third-party security risks. Security Awareness, Policy & Culture * Lead enterprise security awareness and compliance training initiatives. * Measure program effectiveness through participation and behavior-based metrics. * Partner with HR and business leaders to strengthen security culture and accountability. * Maintain cybersecurity policies through review, approval, communication, and lifecycle management processes. People Leadership * Supervise, coach, mentor, and develop GRC and data protection team members. * Establish performance expectations, development plans, and accountability measures. * Manage workload prioritization, resource allocation, and operational coverage. * Promote collaboration, knowledge sharing, and continuous learning. Stakeholder Engagement * Collaborate with Cybersecurity, IT, Legal, Privacy, Internal Audit, Quality, Regulatory Affairs, Data & AI, and business leaders. * Translate cybersecurity and compliance requirements into actionable business processes. * Present program updates, compliance status, risks, and recommendations to leadership. Essential Functions of the Role * Communicate effectively via email, phone, and virtual platforms. * Collaborate across departments to support organizational goals. * Participate in cross-functional meetings and initiatives. * Prepare reports and dashboards for internal stakeholders. * Ensure data accuracy and confidentiality in compliance with company and legal standards. * Demonstrate initiative in identifying process improvements or automation opportunities. * Maintain secure handling of sensitive information. * Support audits and regulatory reporting as needed. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [ZEISS & Microsoft - Building the Next Generation Medical Ecosystem in the Cloud](https://www.wearedevelopers.com/videos/424-zeiss-microsoft-building-the-next-generation-medical-ecosystem-in-the-cloud) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Best Companies to Work For in Germany: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/33-best-companies-to-work-for-in-germany-top-25-companies-in-2023)