About the Role
This is a builder role where you will shape how Governance, Risk and Compliance (GRC) works from the ground up, creating a modern, engineering-led function that fits a fast-moving, creative business. You will lead the strategy, operating model, and future team for GRC, working directly with the Director of Cyber Security and senior leaders across the business. You will be curious and inventive about how AI and automation can be used to solve GRC problems and remove friction.
Responsibilities
- Define and own the cyber GRC vision, principles, and multi-year roadmap.
- Design practical governance forums and decision pathways.
- Establish a clear security policy framework and lifecycle.
- Agree the future team structure, capabilities, and hiring plan.
- Create and embed simple, outcome-focused frameworks for security and enterprise risk management, control design and assurance, and compliance coordination.
- Ensure risks have clear owners and treatment plans.
- Ensure controls are measurable and effective.
- Ensure evidence management is scalable and reusable.
- Lead the move towards policy as code, automated control testing, workflow-driven assurance, and integration of GRC into engineering and business processes.
- Use data, tooling, and automation to reduce manual, document-heavy tasks and improve visibility of risk and compliance posture.
- Partner with Technology, Product, Legal, Procurement, Privacy, Audit, and business teams to embed GRC into day-to-day work.
- Own security culture, awareness, and behavior-change activities.
- Provide clear, concise risk and compliance reporting and insights for senior leaders and boards.
Requirements
- Experience setting GRC strategy and operating models.
- Willingness to build frameworks, content, and processes.
- Strong background in security governance, risk, and compliance in technology-led organizations.
- Interest in GRC engineering, automation, and policy-as-code approaches.
- Ability to keep things proportionate and outcomes-focused rather than checkbox-driven.
- Excellent stakeholder skills, able to build credibility with engineers, product teams, legal, procurement, audit, and senior executives.
- Genuine curiosity about how AI and related technologies can safely augment GRC processes.
- Ability to spot practical use cases that reduce friction and improve outcomes.
- Comfortable in fast-paced, changing environments.
- Track record of turning ideas into working practices, tooling, and measurable improvements.
Skills
- GRC strategy
- Operating models
- Security governance
- Risk management
- Compliance
- GRC engineering
- Automation
- Policy as code
- Stakeholder management
- AI and automation in GRC
- Risk reporting
Experience Level
- Head of Governance, Risk and Compliance
Benefits
- Shape what 'great' GRC looks like for a leading media and entertainment company.
- Create a function that is modern, data-driven, and fit for a digital world.
- Mandate to design and implement the strategy, operating model, processes, and shape the tooling.
- Focus on practical, lightweight frameworks that help people make good decisions.
- Strip out red tape and build approaches that teams genuinely want to use.
- Work closely with engineers, product teams, commercial leaders, and support functions.
- Embed GRC into everyday workflows.
- Build a strong, collaborative security culture.
About the Company
- Global is a leading media and entertainment company.
