Vista previa de la oferta
Governance, Risk & Regulatory Compliance Director, Quality Risk & Security, Enabling Functions
senior · Risk & Compliance
Basic information
Location Aberdeen, Belfast, Birmingham, Bristol, Cambridge, Cardiff, Edinburgh, Gatwick, Glasgow, Guernsey, Ipswich, Isle of Man, Jersey, Leeds, Liverpool, London, Manchester, Milton Keynes, Newcastle, Nottingham, Port Talbot, Reading, Southampton, St Albans Business Line Enabling Functions Job Type Permanent / FTC Date published 10-Sep-2026 Req # 25068Job description
Connect to your Industry
Deloitte’s Quality, Risk and Security (QRS) community is the overarching identity for all the professionals who manage quality and risk for Deloitte. It comprises: Deloitte Business Security (DBS), National Quality and Risk Management (NQRM), Quality & Risk Operations (QR Ops), and Business Line Quality and Risk Management teams (including Switzerland) and is led by a dedicated partner who sits on the firm’s Executive.
Within QRS, we use our skills and experience across a variety of disciplines to support a risk intelligent culture at Deloitte, acting as custodians of firm risk, security, ethics, and reputation, enabling our partners and practitioners to deliver high-quality services to their clients.
Deloitte Business Security (DBS) is the firm’s internal corporate security organisation, providing support to Deloitte and its clients to enable secure business and manage data risk. We are looking for a Governance Risk & Regulatory Compliance (GRRC) Director to join the DBS leadership team and lead our independent second line of defence GRRC function, a key area for Deloitte UK and our clients. This is a new and exciting role, created to provide additional senior leadership and bring vital focus and energy to effectively manage governance, risk and regulatory compliance across our 3 central pillars of Confidentiality, Privacy & Security.
With technologies and data becoming ever more central to our business, the regulatory landscape around both ever evolving, ensuring risks within Confidentiality, Privacy and Security (CPS) are being effectively managed end to end is a vital foundation of our brand.
Connect to your career at Deloitte
Deloitte drives progress. Using our vast range of expertise, we help our clients become leaders wherever they choose to compete. To do this, we invest in outstanding people. We build teams of future thinkers, with diverse talents and backgrounds, and empower them all to reach for and achieve more.
What brings us all together at Deloitte? It’s how we approach thousands of decisions we make every day. How we behave, our beliefs, and our attitudes. In other words: our values. Whatever we do, wherever we are in the world, we lead the way, serve with integrity, take care of each other, foster inclusion, and collaborate for measurable impact. These five shared values lead every decision we make and action we take, guiding us to deliver impact how and where it matters most.
Connect to your opportunity
The Governance, Risk & Regulatory Compliance Director role within DBS is to lead the firm's second-line Governance, Risk and Regulatory Compliance function for our 3 pillars of Confidentiality, Privacy and Security. You'll own the integrated framework, produce the aggregate risk views for leadership, relevant risk committees, firm Executive and Board, and lead a multi-disciplinary team that embeds and most importantly drives GRC and effective risk management across our function. The outputs of which will also feed directly into our wider Enterprise Risk Management framework. Vital to this will also be a forward looking regulatory view, ensuring that the wider CPS function is sighted on upcoming relevant regulations and preparing for compliance with them as required.
The role reports to the Security Partner and is part of the Deloitte Business Security leadership team where you’ll also be expected to play an active role in collaborating with the team and steering the strategic direction of the function. The GRRC Director will work collaboratively with colleagues across CPS, QRS, Enabling Functions, Enterprise and global risk management teams. You will lead a diverse team of skilled SMEs to help horizon scan, report and ensure management and movement of some of the firm’s most important risks.
This role requires strong leadership and stakeholder management skills, risk management expertise, and good people skills. You will be supported by and working closely with SMEs from across Deloitte Business Security.
Specific responsibilities:
· Develop and own the integrated governance risk and compliance framework for confidentiality, privacy, and security, covering taxonomy, risk appetite, KRIs, and reporting. Deliver clear, executive-level risk insights to leadership, forums, and the Board, ensuring alignment with the Enterprise Risk Management framework.
· Translate CPS risk into clear, accessible insights for non-technical executives, and independently assess residual risk based on threat exposure and control effectiveness. Provide robust second-line GRC challenge to first-line information security, as well as second-line cyber risk, privacy and confidentiality functions and relevant business teams.
· Oversee the ISMS, ISO certifications, and CPS-related ISQM1/QC1000 components, maintaining strong governance over regulatory and internal/firm audit requirements.
· Lead a forward-looking regulatory radar, monitoring UK and EU developments, assessing impact, and where relevant, leading workstreams to ensure the function/firm are compliant and embedding any required changes into business-as-usual operations.
· Foster strong collaboration across all three lines of defence, enabling effective information sharing and evidence management.
· Lead emerging risk across the three pillars translated into actionable changes to the risk register and control framework. Lead CPS scenario analysis and stress testing, plugged into ERM scenarios.
· Oversee the central operations of the CPS function, ensuring alignment and effective delivery of strategic priorities.
· Lead, develop and inspire a high-performing GRRC team, promoting an inclusive team culture based on mutual respect and trust, building and developing talent.
Connect to your skills and professional experience
· Track record of executive and board-level risk reporting; able to translate technical risk into commercial and strategic terms. Strong leadership and people management skills, with a track record of running and working across multi-functional teams.
· Working knowledge and operational experience of: UK GDPR, NIS2, ISO 27001, ISO42001, ISQM1, QC1000 and FCA rules relevant to in-scope entities.
· In-depth knowledge of risk assessment and risk management methodologies, and the ability to lead and drive change to keep pace with the changing risk and business landscape.
· Strong influence without authority, the role works through partnership with colleagues across multiple teams that own and manage risk daily, not by direct control.
· Excellent communication and stakeholder management skills.
· Relevant professional certifications (e.g. ISO 27001 Lead Implementer or Lead Auditor
IRM qualifications) are highly desirable.
Connect to your business - Enabling Functions
Collaboration is central to everything we do at Deloitte. From IT to HR, marketing and more, our teams help to support the wider business in everything they do. Bringing your individual skills and specialist knowledge, you can make a far-reaching impact. Come join us.
National Quality and Risk Management
We ensure we manage our business with integrity. This includes developing and managing assurance and business risk frameworks, anti-money laundering, addressing any potential conflicts of interest amongst clients and maintaining our independence from them, ensuring we’re compliant and managing the security of our people.
Personal independence
Regulation and controls are standard practice in our industry and Deloitte is no exception. These controls provide important legal protection for both you and the firm. We are subject to a number of audit regulations, one of which requires that certain colleagues abide by specific personal independence constraints (e.g., in relation to any financial interests and employment relationships). This can mean that you and your "Immediate Family Members" are not permitted to hold certain financial interests (shares, funds, bonds etc.) with audit clients of the firm, and also prohibitions on certain employment relationships (e.g., you are not permitted to hold a secondary employment role with SEC audit clients of the firm whilst being employed by the firm). The recruitment team will provide further detail as you progress through the recruitment process or you can contact the Independence team upon request.
Connect with your colleagues
"Deloitte’s a large, complex and fast-paced organisation but it’s open to new ideas. Everyone is encouraged to show initiative and challenge the norm.” -Lisa, Enabling Functions
Our hybrid working policy
You’ll be based in one of our UK locations with hybrid working.
At Deloitte we understand the importance of balancing your career alongside your home life. That’s why we’ll support you to work flexibly through our hybrid working policy. Depending on the requirements of your role, you’ll have the opportunity to work in your local office, virtual collaboration spaces, client sites and remotely. You’ll get the chance to meet face to face when needed, while you collaborate and learn from colleagues, share your experiences, and build the relationships that will fuel your career and prioritise your wellbeing. Please check with your recruiter for the specific working requirements that may apply for your role.
Connect to your return to work opportunity
Are you looking to return to the workplace after an extended career break?
For this role we can offer coaching and support designed for returners to refresh your knowledge and skills, and help your transition back into the workplace after a career break of two years or more. If this is relevant for you, just let your recruiter know when you make your application.
Our commitment to you
Making an impact is more than just what we do: it’s why we’re here. So we work hard to create an environment where you can experience a purpose you believe in, the freedom to be you, and the capacity to go further than ever before.
We want you. The true you. Your own strengths, perspective and personality. So we’re nurturing a culture where everyone belongs, feels supported and heard, and is empowered to make a valuable, personal contribution. You can be sure we’ll take your wellbeing seriously, too. Because it’s only when you’re comfortable and at your best that you can make the kind of impact you, and we, live for.
Your expertise is our capability, so we’ll make sure it never stops growing. Whether it’s from the complex work you do, or the people you collaborate with, you’ll learn every day. Through world-class development, you’ll gain invaluable technical and personal skills. Whatever your level, you’ll learn how to lead.
Connect to your next step
A career at Deloitte is an opportunity to develop in any direction you choose. Join us and you’ll experience a purpose you can believe in and an impact you can see. You’ll be free to bring your true self to work every day. And you’ll never stop growing, whatever your level.
Discover more reasons to connect with us, our people and purpose-driven culture at deloitte.co.uk/careers
RTWPROG WPFULL SLICSS LOCOFFICE
Apply Share this job: Share
- Share Governance, Risk & Regulatory Compliance Director, Quality Risk & Security, Enabling Functions with LinkedIn
- Share Governance, Risk & Regulatory Compliance Director, Quality Risk & Security, Enabling Functions with Facebook
- Share Governance, Risk & Regulatory Compliance Director, Quality Risk & Security, Enabling Functions with Twitter
- Share Governance, Risk & Regulatory Compliance Director, Quality Risk & Security, Enabling Functions with a friend via e-mail