Talent.com
AVEVA
Director, Information Security GRCAVEVA • Cambridge, England, UK
Director, Information Security GRC

Director, Information Security GRC

AVEVA • Cambridge, England, UK
27 days ago
Job type
  • Full-time
Job description

AVEVA is creating software trusted by over 90% of leading industrial companies.

Job Title: Director Information Security GRC

Location: Cambridge UK

Employment type: Full-time regular

Benefits: Competitive package with an attractive bonus incentive plan regionally specific benefits ranging from above the norm paid vacation contributions to retirement investment plans or pensions insurances and a many other memberships and perks designed to enhance the workplace experience your health and wellbeing.

Previous Experience: 10 years in information security with at least 5 years in a senior role biased towards building capability not just running it. Proven track record of building and leading teams in complex international and multi-stakeholder environments with experience reporting security risk to executive leadership and parent company governance structures. Demonstrated ability to drive automation and tooling improvements in GRC workflows to improve program scalability.

The job

The Director Information Security GRC leads AVEVAs Governance Risk and Compliance function within the central Digital Security organization a key second-line leadership role in AVEVAs federated security model. This position is accountable for the policies standards and governance frameworks that protect AVEVAs digital estate and products and for the risk assurances that AVEVA leadership and Schneider Electric require to make informed business decisions.

AVEVA is a fast-growing software company operating in highly regulated markets and is an independent subsidiary of Schneider Electric. The GRC function must be a genuine enabler of business agility continuously modernizing through automation and innovation.

We are building a highly integrated security practice where all security disciplines share and act in coordination on risk signal. The successful candidate must combine broad security experience with GRC expertise and deeply understand how they interact to deliver the trust promise of AVEVA. They will possess a collaborative mindset with a passion for data-driven scalable approaches to security and risk management.

Operating at a senior level within this specialised field and as a member of the functional Senior Leadership team the Director of Security GRC will often be called on to provide consultation to leaders and counsel to the CISO. They are responsible for generating new theories concepts principles and methodologies and will contribute significantly to the development of policy for the Digital Security function.

As a leader of leaders and with a global team this individual must establish a culture of performance excellence ensuring the team deliver on the demands and expectations of the Security practice in accordance with our values.

Key Responsibilities

Operating as the central second-line function the Director sets the standards all federated teams execute against retains independent oversight and audit rights and provides joined-up risk governance reporting to the CISO AVEVA ELT and Schneider Electric.

Security Policy & Standards

  • Define and maintain AVEVAs security policy framework aligned to ISO 27001 NIS2 IEC 62443 and contractual obligations.
  • Set centralised standards for control design and assurance testing across all federated teams; manage the full policy lifecycle in response to evolving threats regulation and business context.

Risk Assessment & Governance

  • Own the enterprise security risk register and operate governance processes including regular reporting to the AVEVA Executive Team and Schneider Electric Group Security.
  • Engage business owners in risk treatment decisions and deliver transparent defensible risk reporting that enables leadership to make informed decisions.

Third Party Risk Management

  • Lead the TPRM programme assessing the security posture of suppliers SaaS platforms and technology partners.
  • Integrate risk gates into procurement decisions and drive automation to scale the programme efficiently.

Programme Management & Maturity

  • Lead the Security PMO coordinating investment and improvement initiatives to advance programme maturity.
  • Maintain a transparent security roadmap and actively identify opportunities to automate GRC workflows to increase team capacity and strategic value.

Compliance & Certification

  • Own AVEVAs compliance posture across applicable regulatory frameworks.
  • Manage external audits and certifications (ISO 27001 SOC 2).
  • Monitor and anticipate regulatory change including NIS2 CRA and IEC 62443.

People and Functional Leadership

  • Build and develop a high-performing GRC team with a culture of intellectual curiosity and continuous improvement.
  • Set clear objectives invest in professional development and act as a visible advocate for the GRC function across AVEVA and Schneider Electric.
  • An assured leader of both direct reports and in-directs to drive strategic alignment and output setting and maintaining high standards as a member of the Digital Security Senior Leadership Team.
  • Possesses a demonstrated ability to navigate ambiguity and make tough decisionsranging from structural re-organizations and budgetary choices to talent optimizationwhile maintaining team morale transparency and a people-first culture in accordance with AVEVAs values.

Skills and Experience

  • 10 years in information security with at least 5 years in a senior role biased towards building capability not just running it.
  • Deep expertise in GRC frameworks: ISO 27001 NIST CSF NIS2 IEC 62443 SOC 2.
  • Strong understanding of security policy lifecycle management control framework design and risk register governance.
  • Experience in operating in regulated markets (ISO 27001 SOC 2 NIS2 IEC 62443).
  • Proven track record of building and leading teams in complex international and multi-stakeholder environments. Experience of leading leaders is advantageous.
  • Reporting security risk to executive leadership and parent company governance structures.
  • Driving automation and tooling improvements in GRC workflows to improve program scalability.
  • Execution bias; demonstrated ability to act tactically while innovating next generation solutions.
  • Rational empathy; demonstrated experience in aligning security imperatives with the goals and values of the organization.
  • Natural collaborator; demonstrated experience delivering joined up solutions.
  • Data literate automation biased operationally fluent.
  • Excellent risk communication skills.
  • Commercial acumen and working knowledge of cloud security DevSecOps and Agile delivery practices.

Desired/Preferred

  • Industrial software OT/ICS security or technology companies serving critical infrastructure or highly regulated industries.
  • Working within a large enterprise group security governance structure as a subsidiary security leader.
  • Working with AI and machine learning applications in security.
  • Professional certifications: CISSP CISM CRISC or ISO 27001 Lead Implementer / Lead Auditor.
  • Experience in a federated matrixed or multi-subsidiary structure driving standards across organizational boundaries.

Competencies

  • Adaptable and resilient: Thrives in dynamic environments; maintains strategic focus through regulatory change and organisational evolution.
  • Practical and logical: Structured thinking with a bias toward pragmatic implementable solutions.
  • Self-motivated and decisive: Comfortable making and owning decisions in ambiguous situations.
  • Collaborative and influential: Earns influence through credibility and expertise; builds trusted relationships across federated teams and leadership.
  • Transparent and courageous: Surfaces difficult risk findings and brings problems to leadership.
  • Curious and growth-oriented: Continuously learning about emerging threats regulatory change and improvements in automation and tooling.

#LI-DY1


UK Benefits include:

Flexible benefits fund emergency leave days adoption leave 28 days annual leave (plus bank holidays) pension life cover private medical insurance parental leave education assistance program.


Its possible were hiring for this position in multiple countries in which case the above benefits apply to the primary location. Specific benefits vary by country but our packages are similarly comprehensive.


Find out more: working

We work in a hybrid way at AVEVA. Most roles are based at a local AVEVA office with an expectation of being on-site 50% of your working hours to support collaboration and connection. Some positions are fully office-based depending on the nature of the work and certain roles that support specific customers or markets may be remote. The working arrangement for this position will be confirmed during the hiring process.


Hiring process

Interested Great! Get started by submitting your cover letter and CV through our application portal. AVEVA is committed to recruiting and retaining people with disabilities. Please let us know in advance if you need reasonable support during your application process.


Find out more: AVEVA

AVEVA is a global leader in industrial software with more than 6500 employees in over 40 countries. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life such as energy infrastructure chemicals and minerals safely efficiently and more sustainably.


We are committed to embedding sustainability and inclusion into our operations our culture and our core business strategy. Learn more about how we are progressing against our ambitious 2030 targets: out more: requires all successful applicants to undergo and pass a drug screening and comprehensive background check before they start employment. Background checks will be conducted in accordance with local laws and may subject to those laws include proof of educational attainment employment history verification proof of work authorization criminal records identity verification credit check. Certain positions dealing with sensitive and/or third-party personal data may involve additional background check criteria.


AVEVA is an Equal Opportunity Employer. We are committed to being an exemplary employer with an inclusive culture developing a workplace environment where all our employees are treated with dignity and respect. We value diversity and the expertise that people from different backgrounds bring to our business. AVEVA provides reasonable accommodation to applicants with disabilities where appropriate. If you need reasonable accommodation for any part of the application and hiring process please notify your recruiter. Determinations on requests for reasonable accommodation will be made on a case-by-case basis.


Required Experience:

Director


Employment Type : Full-Time
Experience: years
Vacancy: 1
Create a job alert for this search

Director, Information Security GRC • Cambridge, England, UK

Similar jobs

Technology Lead, Electronics and Software – Defence and Security

Cambridge ConsultantsCambridge, England, GB
Full-time

We are on the lookout for a talented and ambitious Technical Specialist/Lead to join our Security and Defence, Systems and Technology team here in Cambridge, UK.The role is within the Defence & Sec... Show more

 • Promoted

Security Engineering Consultant, Hardware

ECM Selection Ltd.Royston, ENG, GB
Full-time

Tackling challenges of hardware and cyber threats for UK defenceNorth Hertfordshire; to c£75,000 DoE + Benefits + Bonus This dedicated defence consultancy provides expertise in defence and cy... Show more

 • Promoted

Applications Security Engineer — Hybrid, SDLC Security

RealVNCCambridge, England, GB
Full-time

RealVNC is seeking an Applications Security Engineer to embed security into the SDLC.You will perform manual and automated testing across web, API, desktop and mobile apps, triage findings, and gui... Show more

 • Promoted

Chief Arm ISA Architect & dpISA Lead

Huawei Technologies Research & Development (UK) LtdCambridge, England, GB
Full-time

Huawei Technologies Research & Development (UK) Ltd is looking for a Chief Architect (dpISA) to lead the architecture R&D initiatives.This senior-level position requires extensive expertise in Arm ... Show more

 • Promoted

Global IT & Digital Transformation Director

Fauna & FloraCambridge, England, GB
Full-time

A leading environmental conservation organization based in Cambridge is seeking a Head of IT to lead its technology strategy and ensure compliance with regulations like GDPR.The role combines strat... Show more

 • Promoted

Cybersecurity Lead: Strategy, Risk, & Incident Response

Hlx Life SciencesCambridge, England, GB
Full-time

HLX Life Sciences in Cambridge is seeking an experienced Cybersecurity Leader to define and evolve our cybersecurity function across cloud and on-premises environments.You will own strategy, risk m... Show more

 • Promoted

Security Architect

Consultancy.ukMelbourn, England, GB
Full-time

We believe in the power of ingenuity to build a positive human future.As strategies, technologies, and innovation collide, we create opportunity from complexity.Our teams of interdisciplinary exper... Show more

 • Promoted

ELIXIR Director

European Bioinformatics Institute | EMBL-EBICambridge, England, GB
Full-time

ELIXIR is a pan-European distributed research infrastructure for life science data.We seek an exceptional leader to guide ELIXIR through its next phase of development, bringing together diverse sta... Show more

 • Promoted

Director of Electronics and FPGA Innovation

Adder TechnologyCambridge, England, GB
Full-time

A leading technology firm in Cambridge is seeking a Head of Electronics to lead the hardware and FPGA engineering team.This role requires a proven leader with deep technical expertise and the abili... Show more

 • Promoted

Global Data Excellence Director

MundipharmaCambridgeshire and Peterborough, England, GB
Full-time

A healthcare company in the United Kingdom is seeking a Data Excellence Director to lead the Data Excellence Centre.The role requires expertise in data analytics, particularly in the pharmaceutical... Show more

 • Promoted

Director

CURRIE & BROWN UK LIMITEDCB23 7NX, ENG, GB
Full-time

The Cambridge office Director will be a visionary leader, both internally and externally, for our offering across the Cambridge and wider East Anglia region, responsible for the profile, promotion ... Show more

 • Promoted

Security Engineer

Darktrace Ltd.Cambridge, England, GB
Full-time

Security EngineerApplylocations: Cambridge Office, United Kingdomtime type: Full timeposted on: Posted 6 Days Agojob requisition id: JR101984Darktrace is a global leader in AI for cybersecu... Show more

 • Promoted

Senior Information Technology Project Manager

La FosseCambridgeshire and Peterborough, England, GB
Full-time

We’re hiring on behalf of a global technology client for a Senior IT Project Manager to lead the end‑to‑end delivery of GenAI and AI initiatives, including Copilot‑style assistants, automation and ... Show more

 • Promoted

Security Engineer

DarktraceCambridge, England, GB
Full-time

Successful candidates will complete a 12-week structured training programme to develop expertise in threat detection and investigation, working alongside security analysts reviewing real incidents,... Show more

 • Promoted

Strategic SoC SDL Architect | Security Lifecycle Leader

ArmCambridge, England, GB
Full-time

A leading technology firm is seeking an SDL Architect to manage the Security Development Lifecycle for Arm-based SoCs.The role involves defining security processes, overseeing adherence to industry... Show more

 • Promoted

Senior Risk Leader - Infrastructure Programs

Turner & TownsendCambridge, England, GB
Full-time

Turner & Townsend is looking for a Senior Risk Manager in Cambridge to lead their Infrastructure team's risk management for high-profile projects.The ideal candidate will have strong experience in ... Show more

 • Promoted

Hybrid Enterprise Solutions Architect: Cloud, Security

Solus Accident Repair CentresBishop's Stortford, England, GB
Full-time

Solus Accident Repair Centres is seeking a Solutions Architect to define and guide our enterprise architecture.This role involves collaborating across various domains to ensure that our solutions a... Show more

 • Promoted

Strategic Technical Director, Civil Infrastructure

Strata ConsultingCambridge, England, GB
Full-time

Strata Consulting's Cambridge office is seeking a highly skilled Technical Director to provide strategic leadership and drive business growth.The role emphasizes client-facing activities and techni... Show more

 • Promoted

Cyber Systems Engineer — IT Infrastructure & Security

CyberDefenceSouth Cambridgeshire, England, GB
Full-time

A leading cybersecurity company in the UK is seeking a Systems Engineer to provide IT support and manage essential systems.The role includes maintaining servers (Windows & Ubuntu), supporting clien... Show more

 • Promoted

Associate Director: System Architect & Engineering Lead

Planet PharmaCambourne, England, GB
Full-time

Planet Pharma is seeking an Associate Director to lead system engineering and architecture initiatives in Cambourne, United Kingdom.You will shape technology strategies, drive scalable architecture... Show more