> Markdown version of [/jobs/ext/82928-information-security-governance-and-risk-manager](https://www.wearedevelopers.com/jobs/ext/82928-information-security-governance-and-risk-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Governance and Risk Manager - **Company:** UK Research and Innovation - **Location:** Nottingham, UK - **Salary:** £58,589.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Data Logging, Information Security Management System - **Published:** May 24, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=a7e07b127290208c ## About the Role Do you have experience in Presentation skills?, As a minimum, due to the nature of this role, candidates must be eligible for clearance in line with UK National vetting guidelines and willing to undertake the process. Please indicate eligibility in the written submission. Candidates not meeting this level of clearance will not be considered., Applicants will be able to demonstrate skills in line with the cyber security risk manager roles using the Government Security Profession career framework. Essential * Degree in a related subject or relevant comparable education. (S) * A professional qualification (e.g., CISM, CISSP, CCSP, ISO 27001 Lead Implementer/Lead Auditor). (S) * Effective decision-making, communication and interpersonal skills, with the ability to adapt communication style and approach to different environments and audiences. (I) * Self-motivated, shows initiative and works with minimal direction, demonstrating strong customer focus. (S&I) * Changing and improving processes, systems, and people to achieve positive outcomes. (S&I) * Strong knowledge of information security governance, risk management and compliance, including operating within an ISO/IEC 27001 management system. (S&I) * In-depth understanding of cloud security principles and practices for AWS and Azure, including secure configuration, identity, logging, network controls and data protection. (S&I) * Ability to coordinate and communicate security risk issues at a senior level and propose solutions that are appropriate, proportionate and effective. (S&I) * Strong problem-solving and analytical skills, including interpreting technical evidence and translating it into business risk. (S&I), Successful candidates must undergo a criminal record check. Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check . ## Description The UKRI CIO Group plays a pivotal role in managing and optimising the organisations critical enterprise technical services that underpin and enable UKRI’s business capabilities. Within the group a team of Information Security Professionals support the delivery of modern, secure, resilient and scalable services across a larger federated team of Digital, Data and Technology professionals to deliver impact across the organisation and the wider UK research and innovation system. Join us for this rare opportunity to apply your experience in information security governance, risk and assurance in a dynamic, fast-paced strategic role in an organisation at the heart of research and innovation in the UK. Managing the Information Security Governance, Risk and Assurance function your broad remit is to drive the implementation of our ambitious information security roadmap and support the UKRI Head of Information Security to mature our information security function. You will lead UKRI’s cyber security risk, compliance and assurance activity for cloud and enterprise services (AWS and Azure). You will own the information security management system (ISMS) and accreditations (ISO 27001 and Cyber Essentials Plus), run the information security risk framework, and drive secure-by-design assurance for new and existing services. You will work across UKRI’s federated technology estate to set proportionate controls, monitor compliance, and provide clear, actionable risk reporting to senior stakeholders. Your responsibilities: * Own and lead UKRI’s Information Security Governance, Risk and Assurance framework. * Own, operate and continuously improve the Information Security Management System (ISMS). * Provide end-to-end security assurance for cloud and enterprise services (AWS and Azure). * Define and maintain UKRI’s security policy and control framework. * Enable and support risk ownership across UKRI’s federated technology and business teams. * Develop and maintain meaningful security metrics, dashboards and management information. * Define, deliver and track a multi-year security governance, risk and assurance roadmap. * Lead security assessment, testing and remediation activity. * Provide ongoing oversight of supplier and third-party security risk. * Establish and maintain enterprise visibility of assets, services and data risk context. * Provide governance leadership across incident management, people, suppliers and assurance partnerships. * Ensure governance-level oversight of significant security incidents., * UK nationals * nationals of the Republic of Ireland * nationals of Commonwealth countries who have the right to work in the UK * nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) * nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS) * individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020 * Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Software Engineer Salary in The UK](https://www.wearedevelopers.com/magazine/231-software-engineer-salary-in-the-uk)