Information,Security and Technology Risk,Regulation Lead
INFORMATION SECURITY AND TECHNOLOGY RISK, REGULATION (GRC) AND AWARENESS LEAD
Our Client, a Major Oil and Gas Operator is seeking an Information Security Governance, Risk, Policy, Framework & Awareness Lead. This is a 12 month PAYE contract role based in Aberdeen with a hybrid working model in place.
Role overview
The Information Security Governance, Risk, Policy, Framework & Awareness Lead is accountable for designing and maintaining the enterprise's security governance structures, risk management frameworks, policy ecosystem, and security awareness strategy. This role ensures cybersecurity is effectively governed, risk-managed, and communicated across all levels of the organisation through structured frameworks, stakeholder engagement, and compliance oversight.
Key Responsibilities:
Security governance and frameworks
Design and maintain the organisation's overarching information security governance model.
Define roles, responsibilities, forums, and escalation paths for cyber governance across business units and functions.
Align frameworks with industry standards (e.g. ISO/IEC 27001, NIST CSF, CAF) and integrate with enterprise governance structures.
Information Security Risk Management
Lead the design and operation of the security risk management framework, including risk identification, assessment, treatment, and reporting.
Ensure risk registers are maintained and embedded into governance reviews and decision-making forums.
Coordinate with Enterprise Risk Management (ERM) to integrate cyber risk into the broader risk posture.
Policy, standards and compliance
Own the lifecycle of information security policies, standards, procedures, and guidelines.
Ensure alignment with legal, regulatory, and industry requirements (e.g., NIS2, GDPR).
Establish governance routines to review, approve, and communicate policy updates organisation-wide.
Awareness, culture and training
Develop and lead a comprehensive cybersecurity awareness and training strategy for all staff.
Drive behavioural change through targeted campaigns, phishing simulations, and executive-level engagement.
Measure awareness effectiveness through KPIs, surveys, and cultural assessments.
Executive reporting and assurance
Deliver regular reporting to senior leadership and boards on governance effectiveness, risk posture, and policy compliance.
Support internal and external audit activity and ensure timely remediation of control deficiencies.
Lead maturity assessments (e.g. ISO 27001 audits, CAF assessments) and track progress against strategic goals.
Stakeholder Engagement & Integration
Collaborate with Legal, Compliance, HR, and IT to embed governance, risk, and policy practices into business-as-usual activities.
Act as a subject matter expert to guide the development of secure business processes and projects.
Ensure governance and awareness initiatives are adapted to regional, cultural, and operational contexts.
Skills, experience & attributes of candidate:
Experience with setting Information Security Policy and Frameworks
Experience with Technology Risk Reporting and engagement with Enterprise Risk and Audit Committees
Excellent understanding of regulatory frameworks e.g. UK CAF, Cyber Security and Resilience Bill, NIS2
Confident engaging senior leadership and explaining the current risk position and option for risk reduction
Familiar with IT security frameworks such as the NIST CSF
Bachelor's in CS, InfoSec, or equivalent experience
Certifications: GICSP, CISSP, or equivalent qualification
- ...An organisation is seeking an Information Security GRC & Awareness Lead to own and evolve its security governance, risk management, policy framework, and awareness strategy. This role ensures cyber security is effectively governed, risk-managed, and embedded across the organisation...RiskTemporary
- £58k - £75k per annumEstimated...Partner with the best As a Lead Engineer, Mechanical, Customer... ...with commercial awareness to secure projects and build long-term customer... ...discussions. Monitoring risks and proactively suggest... ...quality standards, and industry regulations (e.g., API 6A, 17D, 5CT, 5L, NACE...RiskLong-term contractFlexible hours
- ...Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving real transformational... ...an opportunity to design and maintain our clients security governance structures, risk management frameworks, policy ecosystem, and security...RiskFlexible hours
- £50k - £67k per annumEstimated...Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving... ...engagements to ensure high-quality, secure, and scalable automation solutions and... ...code components Identify delivery risks (security, data exposure, change...RiskFlexible hours
- £62k - £82k per annumEstimated...Lead Product Planner Do you enjoy being part of team that provides high-quality project... ...to be completed in the future ii) Risks in schedules and mitigation actions iii)... ...Project Planning About Us: We are an energy technology company that provides solutions to energy...RiskFlexible hours
- £59k - £75k per annumEstimated...to develop your career in a Global Energy Technology company Join our team! We devise... ...surface pressure capabilities are industry leading. The Services Team specializes in aftermarket... ...all customer requirements, technical risks and past lessons learned are properly captured...RiskPermanentOn-siteFlexible hours
- ...IT Risk Advisor specialising in secure-by-design architecture to provide technical security oversight across... ...BAU operations. This role sits within technology governance, ensuring robust,... ...to delivery teams. Conduct threat-informed design reviews and support appropriate...RiskTemporary
- £40k - £53k per annumEstimated...Land Manager and Origination Lead - Onshore Energy Location:... ...expertise in cutting-edge energy technologies and strategic investment *... ...agents, and statutory bodies * Secure land rights through voluntary... ...* Manage land-related risks, constraints, and dependencies...RiskPermanentFull-timeFlexible hours
- £54k - £71k per annumEstimated...Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving... ...documentation to track actions, risks and issues. Track project progress... ...within oil & gas, energy, or highly regulated industries Ability to engage stakeholders...RiskHybrid workingFlexible hours
- £45k - £59k per annumEstimated...the world with unrivalled expertise, equipment, and technology that supports the entire asset life-cycle - offshore... ...customized integrated solutions. This approach reduces risk and enhances efficiencies making us a leading and trusted partner every step of the way. The Role...RiskPermanentFull-time
- £58k - £74k per annumEstimated...Investment Lead Onshore/Offshore Aberdeen/Edinburgh/London... ...expertise in cutting-edge energy technologies and strategic investment.... ...external advisors, identifying key risks and mitigation strategies for... ...technical and financial information quickly and distil it into actionable...RiskPermanentFull-timeFlexible hours
- £49k - £63k per annumEstimated...Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving... ...ensuring data is onboarded quickly, securely, and consistently. A senior... ...platform experience. • Experience in regulated sectors with understanding of data governance...RiskOngoing contractPermanentHybrid workingFlexible hours
- £37k - £48k per annumEstimated...Team Leader , you will be responsible for leading a team of nurses and healthcare... ..., governance protocols, and safeguarding regulations. Supervise and support junior staff through... ...compassionate care. Monitor patient care plans, risk assessments, and outcomes to maintain...RiskPermanentFull-timeFlexible hoursShift workRotating shiftsAfternoon shift
£58.1k - £87.1k per annum
...exciting opportunity for a Senior Lead Project Engineer to join our... ...that engineering design risks are identified and mitigated to... ...to present complex technical information clearly and support informed decision... ...for net zero to create secure power for generations to come....RiskPermanentOn-siteFlexible hours- ...the review of customer feedback comments, complaints, incidents and risks. Oversee the provision of health assessments and private GP... ...liaison with the Clinical Health Assessment Leadership Team (CHALT). Lead on the implementation of clinical policies and procedures with...RiskPermanentPart-timeRemoteFlexible hours
- £54k - £69k per annumEstimated...Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving transformational change within our clients... ...point for complex delivery, organisational, and risk challenges. 2. Senior Client Advisory & Strategy Consulting...RiskFull-timeFlexible hours
£76.89k - £82.25k per annum
...applications from all sections of society. Lead the Digital Transformation of Health and... ...to drive the safe adoption of digital technology across Nursing, Midwifery, and Allied... ...future of healthcare in Grampian. For informal enquiries, contact ****@*****.***...Fixed-term contractNight shift- ...Support the training pathways to ensure training happens on time Lead by example and be hands-on when required Assign duties amongst... ...ensure Pret’s Financial Standards are always followed to minimise risks and ensure team safety To always follow merchandising...RiskImmediate startRotating shifts
- £45k - £58k per annumEstimated...• Partner with the best Baker Hughes is a global energy technology company delivering innovative solutions across the full energy and... ...safer, cleaner, and more efficient. Fuel your passion As a Lead Sales Specialist, you will play a key role in driving commercial...Long-term contractOn-siteFlexible hours
- £43k - £57k per annumEstimated...Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, dedicated... ...and is comfortable delivering in regulated and safety critical contexts.... ...delivery, ensuring scope, requirements, risks and dependencies are clearly defined...RiskFull-timeFlexible hours
- £31k - £41k per annumEstimated...Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving... ...testing progress, dependencies, risks, and defects, communicating updates... ...working within energy, utilities, or regulated industries. Exposure to Azure, AWS...RiskHybrid workingFlexible hours
£15.77 per hour
...environment by complying with health, safety and security procedures, including medication... ...possible, if applicable, with reference to the risk assessment process. Supporting service... ...matters if appropriate. Taking the lead in planning, monitoring and reviewing service...RiskHourly payPermanentFull-timeShift workNight shiftRotating shiftsAfternoon shiftEarly shift- £67k - £89k per annumEstimated...Equipment : Use state-of-the-art technology to collect, analyse, and... ...everything is accurate and up to regulations. Prepare, use, and maintain... ...guidance Plan and perform Risk assessments and toll box... ...Who we are DOF is a leading provider of integrated marine...RiskPermanentFlexible hoursShift work
- £47k - £63k per annumEstimated.../ identity, record, track and inform the Quality Engineers, Managers... ...a proper use of adequate risk assessment, root cause analysis... ...Sampling inspection Experience leading a team and delegating tasks... ...technical procedures, or governmental regulations Shares information, advice,...RiskPermanentFull-timeShift work
- £30k - £39k per annumEstimated...Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving... ..., the role ensures leaders can make informed, data-driven decisions on the timing... ...people impacts, dependencies, and risks. Support planning activities to...RiskFlexible hours
- £50k - £65k per annumEstimated...Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving real transformation... ...g. ERP, CRM, HR systems). · Experience in regulated sectors with understanding of compliance, risk, and security considerations. · Experience...RiskOngoing contractPermanentFlexible hours
- ...enduring value for clients in Strategy, Risk & Transactions (SR&T) and Technology & Transformation (T&T). We deliver... ..., wherever we are in the world, we lead the way , serve with integrity ,... ...us. Personal independence Regulation and controls are standard practice in...RiskFixed-term contractSelf-employedFreelanceHybrid workingOn-siteImmediate startRemote
- ...Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving... ...) environments, aiming to establish secure, autonomous platforms while maintaining... ...Plan that supports traceability, risk mitigation, and readiness for system...RiskFlexible hours
- £37k - £48k per annumEstimated...Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving... ...and meetings to gather key information for report submissions Identify patterns... ..., gaps, or potential compliance risks through data insights. Ensure documentation...RiskFull-timeFlexible hours
- ...Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving... ...businesses. • Define guardrails covering security, compliance, cost management, and operational resilience within regulated environments. • Act as the technical...RiskOngoing contractPermanentHybrid workingFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information,Security and Technology Risk,Regulation Lead. Be the first to apply!
- risk & business continuity manager Aberdeen
- risk control Aberdeen
- political risk Aberdeen
- credit risk contract Aberdeen
- business analyst wholesale credit risk banking contract Aberdeen
- information security Aberdeen
- IT teacher Aberdeen
- information technology Aberdeen
- information technology instructor Aberdeen
- information technology field engineer Aberdeen

