Governance, Risk & Regulatory Compliance Director
other jobs Deloitte
Added before 3 Days
  • Scotland,Glasgow City
  • Full Time, Permanent
  • Salary not specified
Job Description:
Full job descriptionGovernance, Risk & Regulatory Compliance Director, Quality Risk & Security, Enabling FunctionsBasic informationLocation

Aberdeen, Belfast, Birmingham, Bristol, Cambridge, Cardiff, Edinburgh, Gatwick, Glasgow, Guernsey, Ipswich, Isle of Man, Jersey, Leeds, Liverpool, London, Manchester, Milton Keynes, Newcastle, Nottingham, Port Talbot, Reading, Southampton, St Albans

Business Line

Enabling Functions

Job Type

Permanent / FTC

Date published

10-Sep-2026

Req #

25068
Job descriptionConnect to your Industry
Deloitte’s Quality, Risk and Security (QRS) community is the overarching identity for all the professionals who manage quality and risk for Deloitte. It comprises: Deloitte Business Security (DBS), National Quality and Risk Management (NQRM), Quality & Risk Operations (QR Ops), and Business Line Quality and Risk Management teams (including Switzerland) and is led by a dedicated partner who sits on the firm’s Executive.
Within QRS, we use our skills and experience across a variety of disciplines to support a risk intelligent culture at Deloitte, acting as custodians of firm risk, security, ethics, and reputation, enabling our partners and practitioners to deliver high-quality services to their clients.
Deloitte Business Security (DBS) is the firm’s internal corporate security organisation, providing support to Deloitte and its clients to enable secure business and manage data risk. We are looking for a Governance Risk & Regulatory Compliance (GRRC) Director to join the DBS leadership team and lead our independent second line of defence GRRC function, a key area for Deloitte UK and our clients. This is a new and exciting role, created to provide additional senior leadership and bring vital focus and energy to effectively manage governance, risk and regulatory compliance across our 3 central pillars of Confidentiality, Privacy & Security.
With technologies and data becoming ever more central to our business, the regulatory landscape around both ever evolving, ensuring risks within Confidentiality, Privacy and Security (CPS) are being effectively managed end to end is a vital foundation of our brand.
Connect to your career at Deloitte
Deloitte drives progress. Using our vast range of expertise, we help our clients become leaders wherever they choose to compete. To do this, we invest in outstanding people. We build teams of future thinkers, with diverse talents and backgrounds, and empower them all to reach for and achieve more.
What brings us all together at Deloitte? It’s how we approach thousands of decisions we make every day. How we behave, our beliefs, and our attitudes. In other words: our values. Whatever we do, wherever we are in the world, we lead the way , serve with integrity , take care of each other , foster inclusion , and collaborate for measurable impact . These five shared values lead every decision we make and action we take, guiding us to deliver impact how and where it matters most.
Connect to your opportunity
The Governance, Risk & Regulatory Compliance Director role within DBS is to lead the firm’s second-line Governance, Risk and Regulatory Compliance function for our 3 pillars of Confidentiality, Privacy and Security. You’ll own the integrated framework, produce the aggregate risk views for leadership, relevant risk committees, firm Executive and Board, and lead a multi-disciplinary team that embeds and most importantly drives GRC and effective risk management across our function. The outputs of which will also feed directly into our wider Enterprise Risk Management framework. Vital to this will also be a forward looking regulatory view, ensuring that the wider CPS function is sighted on upcoming relevant regulations and preparing for compliance with them as required.
The role reports to the Security Partner and is part of the Deloitte Business Security leadership team where you’ll also be expected to play an active role in collaborating with the team and steering the strategic direction of the function. The GRRC Director will work collaboratively with colleagues across CPS, QRS, Enabling Functions, Enterprise and global risk management teams. You will lead a diverse team of skilled SMEs to help horizon scan, report and ensure management and movement of some of the firm’s most important risks.
This role requires strong leadership and stakeholder management skills, risk management expertise, and good people skills. You will be supported by and working closely with SMEs from across Deloitte Business Security.
Specific responsibilities:
· Develop and own the integrated governance risk and compliance framework for confidentiality, privacy, and security, covering taxonomy, risk appetite, KRIs, and reporting. Deliver clear, executive-level risk insights to leadership, forums, and the Board, ensuring alignment with the Enterprise Risk Management framework.
· Translate CPS risk into clear, accessible insights for non-technical executives, and independently assess residual risk based on threat exposure and control effectiveness. Provide robust second-line GRC challenge to first-line information security, as well as second-line cyber risk, privacy and confidentiality functions and relevant business teams.
· Oversee the ISMS, ISO certifications, and CPS-related ISQM1/QC1000 components, maintaining strong governance over regulatory and internal/firm audit requirements.
· Lead a forward-looking regulatory radar, monitoring UK and EU developments, assessing impact, and where relevant, leading workstreams to ensure the function/firm are compliant and embedding any required changes into business-as-usual operations.
· Foster strong collaboration across all three lines of defence, enabling effective information sharing and evidence management.
· Lead emerging risk across the three pillars translated into actionable changes to the risk register and control framework. Lead CPS scenario analysis and stress testing, plugged into ERM scenarios.
· Oversee the central operations of the CPS function, ensuring alignment and effective delivery of strategic priorities.
· Lead, develop and inspire a high-performing GRRC team, promoting an inclusive team culture based on mutual respect and trust, building and developing talent.
Connect to your skills and professional experience
· Track record of executive and board-level risk reporting; able to translate technical risk into commercial and strategic terms. Strong leadership and people management skills, with a track record of running and working across multi-functional teams.
· Working knowledge and operational experience of: UK GDPR, NIS2, ISO 27001, ISO42001, ISQM1, QC1000 and FCA rules relevant to in-scope entities.
· In-depth knowledge of risk assessment and risk management...
Job number 4126022

Increase your exposure to recruiters with ProJobs

Thousands of recruiters are looking for you in the Job Master profile database, increase your exposure 4 times with a ProJob subscription

You can cancel your subscription at any time.
metapel
Company Details:
Deloitte
Company size:
Industry:
The jobs on site are for both men and women