
Policy Support Lead
- United Kingdom
- £60,000 per year
- Permanent
- Full-time
- Develop and maintain comprehensive security policies, standards and procedures across the organisation.
- Align all standards with applicable regulatory requirements and frameworks (e.g., ISO 27001, GDPR, NIS-R).
- Review and update standards regularly in response to emerging threats and regulatory changes.
- Oversee the exception management framework, including reporting, approvals and reviews prior to expiry.
- Monitor compliance with security policies and standards across digital and business teams.
- Act as the primary point of contact for internal and external audits related to security standards.
- Coordinate the annual standards review cycle, ensuring timely updates and stakeholder engagement.
- Support the publication and socialisation of new or revised standards to ensure organisation wide awareness.
- Collaborate with cross functional teams to embed security best practices into digital processes.
- Build and maintain relationships with key stakeholders including the CISO, CIO, architecture teams, programme delivery and business owners.
- Provide clear, engaging, and relevant communication and training around security standards.
- Deliver security messaging both in person and virtually, ensuring consistency and clarity.
- Track policy effectiveness and recommend enhancements to improve standard adoption and compliance.
- Stay informed of the latest security regulations, technologies and industry best practices to ensure standards remain current and effective.
Working pattern – 36 hours Monday to Friday.What you should bring to the role:The must-haves (essential criteria) for this opportunity include:Essential Experience:
- Experience in information security or a related governance role.
- Experience applying security frameworks and regulatory requirements (CIS, GDPR, NIS-R).
- Experience collaborating across multiple business areas and functional teams.
- Proven ability to work independently, with strong stakeholder management capabilities.
- Strong written and verbal communication skills with the ability to deliver complex messages clearly.
- Skilled in exception management, reporting and compliance monitoring.
- Experience maintaining security standards and exception frameworks.
- Exposure to information risk management processes and controls.
- Relevant certifications such as CISSP, CISM or CISA.
- Strong relationship building and collaboration skills.
- Excellent organisational and time management skills.
- Ability to influence stakeholders and drive compliance in a matrixed environment.
- Competitive salary up to £60,000 per annum depending on experience
- Annual Leave - 26 days holiday per year increasing to 30 with the length of service (plus bank holidays)
- Performance-related pay plan directly linked to both company and individual performance measures and targets
- Generous Pension Scheme through AON
- Access to lots of benefits to help you take care of you and your family’s health and wellbeing, and your finances – from annual health MOTs and access to physiotherapy and counselling, to Cycle to Work schemes, shopping vouchers and life assurance.