Cyber Governance Specialist - Ref 2863
- Reference:
- 2863
- Posted on
Join a people-centred technology team that thrives on innovation, collaboration, and delivering meaningful outcomes. We are seeking a talented and motivated Cyber Governance Specialist to join a growing Cyber Security team. In this role, you will play a key part in supporting the effective operation of a cyber governance programme, helping to translate cyber security strategy, policies, and standards into structured, repeatable governance processes across the organisation. Working closely with stakeholders across enterprise IT, operational technology, and supply chain environments, you will support security reviews, track remediation activities, monitor performance metrics, and deliver insightful reporting to senior leadership and governance forums. If you enjoy bringing structure to complex environments, influencing positive security outcomes, and contributing to a strong culture of governance and continuous improvement, we'd love to hear from you.
📍 Location: Aberdeen (Hybrid working)
🔁Contract Type: Permanent preferred (contract considered)
What you’ll do
- Operate the governance processes and calendar — review gates, reporting cycles, forum cadences, and evidence deadlines — that give effect to the Cyber Security Standard and its supporting policy suite
- Conduct cyber security reviews of IT and business projects at defined lifecycle gates in line with agreed process and approach, agreeing proportionate remediation actions with project owners and tracking them to closure
- Maintain the central registers of security actions and policy exceptions, validating evidence of completion to a standard suitable for internal audit and regulatory inspection
- Support cyber security risk management processes, including risk register administration and associated reporting
- Collect, validate, and trend cyber security KPIs and KRIs, and produce recurring report packs for the security steering group, executive risk committee, and project and portfolio boards
- Support the Assurance function in collating evidence for CAF self-assessment and regulatory inspection preparation; ownership of regulatory evidence and regulator engagement remains with Assurance
- Operate the supplier cyber assessment procedure and maintain the supplier assurance record.
- Contribute to the selection and administration of GRC tooling, and refine governance processes and templates as the programme matures
Accountabilities
The role holder is accountable for:
- Governance forums receive accurate, complete report packs on time, every cycle
- Cyber reviews of projects are completed within agreed service levels and recorded consistently
- The action and evidence registers are current, complete, and audit-ready at all times
- KPI and KRI data presented to governance forums is accurate and traceable to source
- The exception register is current, with expiring exceptions escalated before lapse
- Governance processes are documented such that they can be operated by others, with no key-person dependency
- Risks, blockers, and material non-compliance identified through governance activity are escalated promptly
What to bring
Essential
- Demonstrable experience operating cyber or information security governance processes
- Experience conducting security reviews or assessments of projects and change against defined policies and standards
- Working knowledge of at least one recognised security framework: NCSC Cyber Assessment Framework, ISO/IEC 27001, or NIST CSF
- Experience producing governance reporting
- Strong communication and stakeholder management skills
- Ability to work collaboratively across teams
- Strong analytical and problem-solving skills
- Ability to manage competing priorities effectively
- Commitment to continuous improvement and organisational values
Desirable
- Experience within an Operator of Essential Services or organisation subject to the NIS Regulations
- Experience of supplier or third-party cyber risk assessment
- Experience administering GRC tooling
Why prosource.it?
Technology is constantly evolving, and so are we.
Since our beginnings as a managed IT services provider, prosource.it has grown alongside the organisations we support, adapting to changing technologies and business needs. Today, we deliver a broad range of technology and business services that help clients plan, implement and embrace change successfully.
While technology is at the heart of what we do, we know that delivering lasting value takes more than technical expertise alone. By combining innovative thinking with practical experience and strong client partnerships, we help organisations realise the full potential of their technology investments. From adopting emerging technologies and delivering complex transformation programmes to improving day-to-day operations, we focus on achieving outcomes that make a measurable difference. As technology continues to evolve, we're committed to staying at the forefront of change, helping our clients embrace new opportunities and shape what's next.
We've built our reputation on being knowledgeable, approachable and easy to work with. Our people bring a wealth of skills and experience, united by a shared commitment to doing the right thing for our customers. With a culture built on teamwork, accountability and trust, our people are empowered to work in a way that makes a meaningful impact.
If you're looking for a role where you can make a difference, develop professionally and be part of a team that's helping organisations navigate an ever-changing technology landscape, we'd love to hear from you.
What You’ll Get in Return
Our people are central to our success, and we're committed to creating an environment where they can thrive. As a business with a broad and varied client base, we can offer opportunities to gain experience across multiple industries, take on new challenges and continue developing your skills. Whether you're looking to deepen your expertise or broaden your experience, we'll support you in building a rewarding career.
We're also committed to helping our people continue to learn and progress. For those pursuing professional qualifications, we'll fund approved self-study materials and exam fees, and reward successful exam passes with an incentive bonus.
Alongside a competitive salary, we offer a comprehensive benefits package including a Company Pension Scheme, Private Medical and Dental Insurance, Group Income Protection, Group Life Assurance, and salary sacrifice schemes for both Cycle to Work and Electric Vehicles.
prosource.it. Building careers, not just jobs.
How to Apply
We’re committed to creating an inclusive and accessible recruitment process. If you have any access needs or require adjustments at any stage of the application or assessment process, please let us know — we’re happy to support you.
Please note: All offers of employment will be subject to background checks and confirmation of the right to work in the UK.
📅 Apply now to be part of a team that values initiative, collaboration and continuous improvement. Send your CV to talent@prosource.it
Live.it Work.it
Latest Opportunities
All OpportunitiesGet in Touch
Talk to us today to explore how we can support your organisation's technology needs.