• Proven leadership experience in Information Security GRC, security governance or cyber risk within a complex, regulated environment
• Strong understanding of frameworks and regulations such as ISO 27001, NIST CSF, PCI-DSS, UK GDPR, NIS/NIS2 and aviation or resilience requirements
• Experience leading multi-disciplinary teams, including managers, and driving performance and capability development
• Deep knowledge of risk management, control assurance, compliance and governance frameworks
• Strong understanding of identity and access governance, including privileged access, segregation of duties and lifecycle controls
• Experience supporting audit and regulatory engagements, including remediation and assurance
• Ability to influence and challenge senior stakeholders across business and technology in a complex, matrixed environment
• Professional certifications such as CISSP, CISM, CRISC or CISA (or equivalent)