Department - Information and Cyber Security / Governance, Risk and Compliance
Reporting To - Governance and Compliance Manager
The Role
The Information and Cyber Security team plays a vital role safeguarding JLRs information assets on a global basis. This role is part of the Governance, Risk and Compliance function whose purpose is to manage information risk to acceptable levels, using a framework of controls and oversight across the enterprise.
The role ensures we deliver appropriate governance, risk and compliance for information security throughout JLR. The role also provides some support for other functions (SOx IT, Risk Management, Strategy, Culture, Supply Chain).
Key Performance Indicators
- The purpose of the role is to ensure compliance and deliver appropriate governance to manage information risks to within risk appetite, measured through - Compliance with enterprise standards and policies
- Effectiveness of security controls to manage risk to acceptable levels
- Measuring and performance risk through KPIs and KRIs
- Accurate and timely analysis / reporting to facilitate decision-making
- Ensuring delivery through assurance and governance
- Compliance with appropriate standards, frameworks and leading practice
- Quality of information controls
Key Accountabilities and Responsibilities
Create, maintain and improve security standards and policies, to ensure they are fit for purpose and current.Develop and maintain insight, analysis, including performance data, to enable effective decision-making on security and information risk.Manage the creation of scheduled and ad-hoc reporting (including presentations for committees, reports, updates and communication content).Manage comprehensive program of Security Assurance, including testing of controls, compliance monitoring across the enterprise, to ensure information risks are managed to acceptable levels.Ensure delivery of audit actions through governance and oversight activities.Manage continuous process improvement and optimisation to ensure quality and risk management outcomes.Support and drive key initiatives and projects to improve security capabilities and reduce risk.Skills Required
Compliance