Group Director – Regulatory Assurance and Cyber at Information Commissioner’s Office (ICO) | Cardiff, Wales | Rezi

Group Director – Regulatory Assurance and Cyber at Information Commissioner’s Office (ICO)

Group Director – Regulatory Assurance and Cyber

Information Commissioner’s Office (ICO) · Cardiff, Wales

6 days ago

Group Director – Regulatory Assurance and Cyber

Information Commissioner’s Office (ICO) · Cardiff, Wales

7 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Join the Information Commissioner’s Office (ICO) at a pivotal moment to lead assurance and cyber regulation. You will drive a risk-led, outcome-focused supervisory model, ensuring strong data protection frameworks that support innovation and public confidence. This role involves delivering major regulatory programmes, shaping the ICO’s response to new cyber legislation, and leading expert teams to provide proactive assurance, targeted interventions, and strategic oversight.

Responsibilities

  • Work collaboratively with senior leader colleagues to develop and deliver the ICO’s purpose and vision, role modelling our values.
  • Provide direct leadership and line management for the Director of Regulatory Assurance, Director of Cyber, and two PACE product roles, integrating assurance, cyber, and product capabilities.
  • Ensure all staff within the directorates understand expected standards and are empowered to achieve them.
  • Provide senior oversight of PACE product activity, ensuring product delivery supports regulatory assurance and cyber priorities and aligns with the ICO’s strategy.
  • Lead the delivery of the ICO’s regulatory responsibilities arising from the Cyber Security and Resilience Bill, ensuring readiness, capability, and effective supervisory approaches.
  • Manage strategic risks and opportunities in all areas of responsibility, agreeing clear risk appetites and ensuring controls are effective and proportionate.
  • Oversee budgetary and fiscal responsibility for Regulatory Assurance and Cyber functions, including operational spend and business case development.
  • Embed a supervisory approach to regulation focused on earlier engagement, prevention of harm, and delivery of clear, measurable regulatory outcomes.
  • Ensure assurance and cyber interventions are proportionate, evidence-based, and consistent with the ICO’s Better Regulatory Interventions approach.
  • Collaborate with Legal, Investigations, and other regulatory functions to support effective escalation, enforcement decision-making, and end-to-end regulatory coherence.
  • Contribute to organisational horizon-scanning and risk assessment, identifying emerging threats, opportunities, and trends relevant to cyber resilience and assurance.
  • Establish and maintain effective internal and external relationships with government, public bodies, regulators, industry, and other stakeholders.
  • Support the Executive Director for Regulatory Risk and Innovation in business planning, performance management, and reporting on assurance and cyber activity.
  • Engage across the ICO, establishing close working relationships and taking responsibility for matrix management to ensure cohesive strategy implementation.
  • Ensure the ICO values diversity and demonstrates equality of opportunity in its treatment of staff, customers, and all business aspects.
  • Seek continuous improvement in all areas of responsibility, acting as a catalyst for efficiency, high performance, and innovation.
  • Play a significant role in the leadership of the ICO and all relevant initiatives, taking personal responsibility for ad hoc projects or tasks.
  • Represent the ICO and advise the Executive Team as required.
  • Ensure that the ICO values diversity in its workforce and demonstrates equality of opportunity in its treatment of staff, customers and in all aspects of its business.

Requirements

  • Senior-level experience demonstrating widely recognised expertise in cyber, regulatory assurance, or closely related risk-focused disciplines.
  • Strong track record of leading complex cyber-related, regulatory, or assurance activity and delivering high-quality outcomes in high-risk or fast-moving contexts.
  • Extensive experience of senior leadership and people management, including setting clear direction, motivating teams, and sustaining delivery through change.
  • Experience operating effectively in high-profile, high-risk environments with significant reputational, public trust, or wider system implications.
  • Substantial experience in senior representational and negotiating roles, building effective relationships with government, regulators, industry, and other stakeholders.
  • Strong understanding of the principles of good regulation and their practical application within assurance and supervisory contexts.
  • Knowledge of cyber risk, resilience, assurance, or related regulatory domains with the credibility to operate authoritatively at senior levels, or the demonstrable ability to develop and apply such expertise quickly.
  • Ability to champion and role model equality, diversity, and inclusion, demonstrating strong personal integrity and a commitment to the ICO’s values.
  • The ability to exercise sound judgement in ambiguous or controversial circumstances.
  • Ability to lead cross-functional and matrix working, influencing without line authority where required.
  • Experience of embedding outcome-focused, proportionate regulatory interventions and measuring their effectiveness.
  • Good understanding of public sector governance, accountability, and performance management.
  • Commercially and politically aware, with an understanding of how cyber risk, technological change, and system resilience impact regulatory decision-making and public trust.
  • Collaborative leadership style, with a commitment to empowering others and building high-performing teams.
  • Strong written, verbal, and communications skills, directed at negotiating with and influencing a wide range of stakeholders, including public speaking and media.
  • Resilient, adaptable, and able to operate effectively under pressure.
  • Candidates with a disability who meet the minimum criteria will be invited to interview.
  • Candidates who declare they identify as belonging from an ethnic minority background and who meet the minimum criteria are guaranteed an interview.
  • Post holders will be required to receive security clearance to DV level.
  • Requires the disclosure of spent and unspent convictions for security clearance.

Skills

  • Cyber security
  • Regulatory assurance
  • Risk management
  • Leadership
  • People management
  • Stakeholder management
  • Negotiation
  • Public speaking
  • Media communication
  • Strategic planning
  • Business case development
  • Performance management
  • Equality, diversity, and inclusion
  • Cyber risk
  • Cyber resilience
  • Regulatory interventions

Location

  • Manchester
  • London
  • Edinburgh
  • Cardiff
  • Belfast

Work Type

  • Hybrid
  • Full-time
  • Part-time

Experience Level

  • Senior-level experience in cyber, regulatory assurance or closely related risk-focused disciplines
  • Strong track record of leading complex cyber-related, regulatory or assurance activity
  • Extensive experience of senior leadership and people management
  • Experience operating effectively in high-profile, high-risk environments
  • Substantial experience in senior representational and negotiating roles

Salary/Compensations

  • £119,930 - £145,590
  • Potential for further progression to £171,248 with pay progression scheme

Benefits

  • Pay progression scheme
  • Hybrid and flexible working options
  • 25 days paid holiday per year, plus privilege and public holidays
  • Flexi leave (up to 26 additional days leave per year)
  • Pension (employer contribution around 28.9%)
  • Online discount scheme
  • Health Cash Plan
  • Fantastic development opportunities

About the Company

  • The Information Commissioner’s Office (ICO) is the independent regulator of information rights.
  • In a data-driven world, we provide advice, guidance, and support to organisations enabling compliance with their obligations, as well as protecting individuals and their personal data.
  • As an employer, we are passionate about making a positive difference to the lives and careers of our people, and we empower you to be curious, impactful, collaborative and respectful.

Equal Opportunity

  • The ICO is committed to promoting and enhancing equality, diversity, and inclusion.
  • We are focused on developing a workforce that is representative of the communities we serve and together we are building an inclusive workplace where all of our colleagues have the opportunity to make a real difference.
  • We are championing this through our Equality Diversity and Inclusion Board together with a number of staff networks.
  • Candidates with a disability who meet the minimum criteria for this vacancy will be invited to interview as part of the ICO’s commitment to the Disability Confident Scheme.
  • We guarantee an interview to candidates who declare they identify as belonging from an ethnic minority background and who meet the minimum criteria for this vacancy.
  • If you are disabled or have an impairment and require an alternative application method, please email the HR team at recruitment@ico.org.uk.