Rodeo
Get started

Rowden

Security Governance Risk & Compliance Officer

Filton
£50k – £60k/yr
Posted about 2 months ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Security Governance, Risk & Compliance Officer

Department: Engineering

Employment Type: Permanent - Full Time

Location: Bristol, UK

Reporting To: Nikki Mason

Compensation: £50,000 - £60,000 / year

We’re building the UK's next generation engineering powerhouse, providing critical technology that strengthens national security and resilience.

We specialise in turning advances in sensing, AI, and communications into operational capability for the edge, where connectivity may be degraded or denied. Our work focuses on accelerating the deployment of technology, improving decision-making for frontline teams, and protecting people and critical assets in demanding environments.

Headquartered in Bristol, Rowden employs around 160 people and operates over 20,000 sq ft of engineering and manufacturing facilities. We have a growing international footprint and are one of Europe’s fastest-growing engineering businesses.


About the Role

We are looking for a Security Governance, Risk and Compliance (GRC) Officer to join our expanding security team. In this role, you will work alongside our security architects and engineers, providing governance, risk, and compliance support across the organisation, helping to ensure security is joined up, proportionate, and embedded in how we deliver work.

We are open to candidates from a range of backgrounds; you don’t need deep prior knowledge of every defence-specific framework. If you’ve built skills in risk, audit, compliance or governance, those are highly transferable here, and we’ll support you to acquire specialist knowledge through structured on-the-job training.

This is a role with clear room to grow into broader security assurance and governance responsibility as our security function scales alongside the business.

Key requirement: A minimum of 3 days per week on-site at Rowden’s Bristol HQ.

Eligibility: Candidates must be eligible for SC Security Clearance and be UK nationals.

Learn more about security clearance here.


Key Areas of Responsibility

As Rowden’s Security Governance, Risk and Compliance Officer, you will:

  • Advise programme and engineering teams on governance, risk, and compliance, helping them identify security requirements.
  • Collaborate closely with customer stakeholders to drive security solutions that are both effective and realistic.
  • Own and develop risk management and assurance documentation as well as Secure by Design artefacts for new projects.
  • Support the security aspects of bids and contracts, liaising with contracting authorities and accrediting bodies.
  • Ensure compliance with UK defence and government requirements, including:
    • MOD Cyber Security Model
    • Def Stan 05-138
    • NCSC Cyber Assessment Framework
    • Secure by Design
    • JSP 440/Defence Security Policy Framework expectations.
  • Track changes to relevant legislation, industry standards, and guidance, including:
    • NCSC guidance
    • MOD requirements
    • ISO 27001
    • UK GDPR/Data Protection Act 2018
  • Help deliver security awareness and training, fostering a strong security culture across the business.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.


Key Skills, Experience & Behaviours

Essential

  • Experience in security governance, risk, compliance, information security, audit, or assurance roles.
  • A sound understanding of security governance and compliance principles.
  • A working knowledge of:
    • ISO 27001
    • Information security risk management (including assessment and treatment).
  • Experience maintaining policies, controls, and evidence, supporting internal or external audits.
  • Strong written communication skills, with the ability to produce clear policies, reports, and risk documentation.
  • Sound risk judgement, making proportionate, well-reasoned decisions.
  • A methodical, detail-oriented approach, ensuring accurate record-keeping and evidence tracking.
  • Ability to convert technical standards and guidance into clear actionable insights.
  • Confidence to challenge at all levels while providing constructive advice.
  • The ability to work at pace, manage competing priorities while maintaining quality and control.

Desirable (Not Essential)

  • A degree or equivalent experience in cyber security, information assurance, risk management, or a related field.
  • One or more recognised certifications, such as:
    • CISMP
    • ISO 27001 Lead Auditor/Lead Implementer
    • CISSP
    • CISM
    • CISA
    • CRISC (currently studied or held).
  • Familiarity with:
    • UK defence and government security frameworks (e.g., JSP 440, Secure by Design).
    • NIST CSF/NIST 800-53.
    • UK GDPR/Data Protection Act 2018.
  • Experience working in defence, government, or regulated/secure environments.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

About You

Core BehaviourDescription
PragmaticImplements controls proportionately and avoids excessive "tick-box" compliance.
CollaborativeBuilds strong working relationships with internal teams and external partners.
Proactive ThinkerAnticipates challenges and actively shapes risk management rather than merely reacting to issues.
ResilientOperates comfortably in fast-paced, evolving environments where requirements adapt as problems are solved.
Continuous LearnerActively seeks to expand specialist knowledge, staying up-to-date with changing standards and threats.

Working at Rowden

We are committed to creating a flexible, inclusive, and enabling workplace filled with talent from diverse backgrounds. We encourage you to apply as you are.

Flexible Working

We support hybrid-working with an average of 3 days in the office per week, based on role requirements. Discussions on:

  • Flexible hours
  • Part-time arrangements
  • Workplace adjustments are welcome for all applicants.

Disability Confident Committed

Rowden is a Disability Confident Committed company. If you have a disability or health condition, please disclose early so we can accommodate your needs during recruitment to ensure a smooth and inclusive process.

Diverse & Inclusive

If you feel your experience doesn’t precisely match the criteria but hold transferable skills and related experience, we’d love for you to apply anyway!

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Security Governance
Risk Management
Compliance
Information Security Audit
ISO 27001
Risk Assessment
Policy Maintenance
Technical Writing
Stakeholder Management
Security Assurance
Regulatory Compliance
Communication Skills

Location

Filton, England, United Kingdom

Sign up to applySee more jobs like this