Rodeo
Get started

DS Smith

Information and Technology Governance & Risk Lead

London
Posted about 16 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

I&T Governance and Risk Lead

About the Role

Reporting to Head of I&T GRC, Governance and Risk Lead will be responsible for driving information and cyber security awareness, delivering security awareness training including phishing and facilitation of cyber scenario desktop simulations across central and manufacturing site teams.

You will review, manage and where required prepare responses to internal and external customer enquiries in relation to information and cyber security arrangements. You will support IT, procurement, legal, data protection and digital security and business stakeholder in relation to supplier information and cyber security due diligence and requirements.

As the successful candidate you will also lead risk-based party security assurance, management, and continuous improvement activities. In addition, facilitate and coordinate IT risk management risk register, tools, process, reporting and review. You will take responsibility for managing a subset of aspects of ISO 27001 related documentation and control activities.

As the I&T Governance and Risk Lead you will have the responsibility of aspects of the I&T GRC scope, delegated and assigned by the Head of I&T GRC.

Key Accountabilities

  • Engage with key IT and business stakeholders in relation to:
    • Risk management.
    • Security awareness training.
    • Facilitation of cyber scenario desktop simulations across central and manufacturing site teams.
    • Customer security questionnaires.
    • Supplier security reviews, risk management and requirements.
  • Manage and continuously improve I&T and Security risks processes in accordance with company risk appetite and tolerance, validating that risk is clearly articulated and management response is well defined.
  • Engage risk review and assurance activities across existing suppliers.
  • Provide IT and business advice on aspects of security standards and regulations such as ISO27001, NIST CSF, PCI DSS, NISD and NIS2.
  • Engage with I&T system owners to provide training in relation to information security, cyber resilience, phishing, and facilitation of cyber scenario desktop simulations across central and manufacturing site teams.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

About You

  • Working knowledge of technology and security standards, controls and consequences across both IT and manufacturing environments in manufacturing or similar industries.
  • Experience working with information security standards and frameworks such as regulations such as ISO27001, NIST CSF, PCI DSS, NISD and NIS2.
  • Proven analytical, problem-solving, planning, project delivery and supplier work packages management skills.
  • Demonstrable experience of engaging across all levels of a company in relation to information and cyber security risks.
  • Working towards or achieved professional certifications (ISO27001 lead, ISC2, CISM or CRISC) advantageous.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

About Us

We are DS Smith, together with International Paper, a global leader in sustainable packaging solutions and other fibre-based products. We believe a better, more sustainable tomorrow is possible with the right people who challenge and support one another to create positive change. Our colleagues across Europe, the Middle East, Africa and North America bring expertise across innovation, manufacturing, design, sales, sustainability, supply chain and technology. Together, we help our customers make the world safer, more productive and more sustainable.

"To fulfil our purpose of redefining packaging for a changing world, we aim to build a diverse, motivated and engaged workforce. Our goal is to create a culture of inclusion where everyone is treated fairly, differences are valued and everyone has an equal opportunity to succeed.

Our people come from diverse backgrounds, bringing different perspectives, ideas and experiences to generate unique solutions focused on present and future sustainability challenges. We welcome all candidates to apply, even those not meeting all criteria."

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

London, England, United Kingdom

Sign up to applySee more jobs like this