Rodeo
Get started

Hollister Incorporated

Supervisor, IT Security, Governance, Risk & Compliance

Winnersh
Posted about 22 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

We Make Life More Rewarding and Dignified

Location: Winnersh

Department: IT

Summary

The Supervisor, Governance, Risk & Compliance (GRC) leads and enhances the organization's cybersecurity governance, risk management, regulatory compliance, audit readiness, third-party risk, security awareness, privacy coordination, and policy management programs. The role provides both strategic direction and operational oversight while leading a team responsible for ensuring alignment with regulatory requirements, industry frameworks, contractual obligations, and internal security standards. The position serves as a key liaison across Cybersecurity, IT, Legal, Privacy, Compliance, Internal Audit, Quality, and business functions to ensure cybersecurity risks are effectively identified, assessed, communicated, and managed in accordance with business objectives and risk appetite.

Responsibilities

Team Leadership & Management:

  • Lead, develop, and support a high-performing team of Cybersecurity Analysts.
  • Set goals, monitor performance, provide feedback, and support professional development.
  • Recruit, interview, onboard, and coach team members.
  • Foster a collaborative team environment and work effectively with internal teams, business partners, and external vendors.

Security GRC Oversight

  • Oversee day-to-day Cybersecurity GRC activities, including risk assessments, compliance activities, audits, and security assessment coordination.
  • Develop and maintain SOPs, playbooks, and runbooks for GRC processes with a focus on repeatability and automation.
  • Evaluate and coordinate security GRC vendors, tools, and services.

Data Protection, DLP & Insider Risk

  • Oversee data protection governance, including data classification, sensitivity labeling, data handling standards, and protection of regulated, confidential, proprietary, and sensitive information.
  • Partner with Privacy, Legal, Compliance, Infrastructure, Enterprise Architecture, and business teams to maintain data protection requirements across cloud, SaaS, endpoint, collaboration, and on-premises environments.
  • Guide Data Loss Prevention control design, implementation, monitoring, tuning, exception handling, alert review, and risk-based escalation.
  • Support insider risk management by reviewing sensitive data movement, coordinating investigations, recommending corrective actions, and reporting DLP and data protection trends to leadership.

AI Security Governance

  • Support AI security governance policies, standards, control requirements, and review processes.
  • Assess risks from Generative AI, AI agents, machine learning platforms, third-party AI tools, prompt-based attacks, data leakage, shadow AI, and insecure AI integrations.
  • Partner with AI governance, Privacy, Legal, Enterprise Architecture, application, and business teams to enable secure and responsible AI adoption.
  • Define expectations for AI access, data inputs and outputs, logging, auditability, human oversight, and protection of intellectual property and sensitive data.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Governance

  • Develop and maintain cybersecurity policies, standards, and procedures, including requirements for data protection, DLP, insider risk, and AI security governance.
  • Align cybersecurity governance activities with business objectives, regulatory requirements, and applicable security frameworks.
  • Conduct regular reviews and updates of governance frameworks, controls, and reporting processes.

Risk Management

  • Identify, assess, prioritize, and report cybersecurity risks, including data protection, third-party, cloud, vulnerability, and AI-related risks.
  • Develop and track risk mitigation plans and monitor remediation effectiveness.
  • Perform risk assessments, vendor and software reviews, and vulnerability analyses.

Compliance & Reporting

  • Support compliance with relevant security, privacy, data protection, and AI governance regulations and standards, including PCI-DSS, ISO 27001, SOC, NIST Cybersecurity Framework, HIPAA, GDPR, and emerging AI regulatory expectations.
  • Produce reports covering risk assessments, compliance posture, DLP trends, insider risk activity, AI governance status, incidents, vulnerabilities, and security awareness metrics.
  • Participate in internal and external audits, prepare compliance materials, and perform other duties as assigned.

Perform Other Duties As Required And Assigned

May be required to work outside of normal business hours to respond to urgent cybersecurity matters.

Essential Functions Of The Role

  • Communicate effectively via email, phone, and virtual platforms.
  • Collaborate across departments to support organizational goals.
  • Participate in cross-functional meetings and initiatives.
  • Prepare reports and dashboards for internal stakeholders.
  • Ensure data accuracy and confidentiality in compliance with company and legal standards.
  • Demonstrate initiative in identifying process improvements or automation opportunities.
  • Maintain secure handling of sensitive information.
  • Support audits and regulatory reporting as needed.

Education & Work Requirements

Bachelor’s Degree with 8-12 years of related experience

Education & Work Preferences

  • Progressive experience in cybersecurity, governance, risk management, compliance, audit, or information security.
  • 3+ years of people leadership, supervisory, or demonstrated workstream leadership experience.
  • Experience supporting or leading ISO 27001, SOC 2, HIPAA, privacy, or similar compliance programs.
  • Experience with Microsoft Purview or similar data protection platforms, including sensitivity labeling, DLP, information protection, classification, insider risk, or compliance management.
  • Strong understanding of network security, incident response, threat hunting, vulnerability management, cloud security, and security reporting.
  • Excellent communication, analytical, problem-solving, decision-making, interpersonal, and presentation skills with the ability to work independently and collaboratively.
  • Experience conducting risk assessments, managing audits, tracking remediation activities, and performing third-party security risk assessments.
  • Experience within healthcare, medical device, manufacturing, life sciences, or other regulated industries.
  • Experience working within a global cybersecurity governance environment.
  • Experience building, implementing, or maturing enterprise GRC programs and reporting outcomes to leadership.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Preferred Certifications

  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Internal Auditor (CIA)
  • ISO 27001 Lead Implementer or Lead Auditor
  • Certified Data Privacy Solutions Engineer (CDPSE)

Preferred Knowledge & Competencies

  • Cybersecurity governance frameworks (ISO 27001, SOC 2, NIST CSF)
  • Risk assessment and audit management methodologies
  • HIPAA, GDPR, privacy, and regulatory compliance requirements
  • Vendor risk management and continuous monitoring
  • Microsoft Purview, Azure security and compliance concepts, identity and access management, and data loss prevention
  • Strategic thinking, business acumen, executive communication, people development, cross-functional collaboration, and risk-based decision making.

Competencies

  • Be Agile - Innovates and adapts quickly, approaching change with curiosity while persisting through obstacles.
  • Be Customer Centric - Considers the needs, experiences and feedback of customers in all we do.
  • Be People-Focused - Builds trust and collaborates with an inclusive and empathetic approach.
  • Be Performance Driven - Operates with an ownership mindset, driving meaningful outcomes.
  • Live The Schneiders’ Legacy, Our Noble Purpose - Passionately serves Our Mission and Vision, while demonstrating the Immutable Principles.

About Hollister Incorporated

Hollister Incorporated is an independent, employee-owned company that develops, manufactures and markets healthcare products worldwide. The company spearheads the advancement of innovative products for ostomy care, continence care and critical care, and also creates educational support materials for patients and healthcare professionals. Headquartered in Libertyville, Illinois, Hollister has manufacturing and distribution centers on three continents and sells in nearly 80 countries. Hollister is a wholly owned subsidiary of The Firm of John Dickinson Schneider, Inc., and is guided both by its Mission to make life more rewarding and dignified for people who use our products and services, as well as its Vision to grow and prosper as an independent, employee-owned company, and in the process, to become better human beings.

EOE Statement

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.

Job Req ID: 36464

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

Winnersh, England, United Kingdom

Sign up to applySee more jobs like this