The role is responsible for supporting the governance of information security, ensuring identification, management, and mitigation of information and cyber security risks across VA’s operations, with emphasis on risk assessment, third-party supply chain security, control and compliance effectiveness, and operationalising the GRC strategy by embedding security and compliance considerations into business change initiatives, digital programmes, and transformation projects. The role supports regulatory compliance and operational resilience, aligned with frameworks such as ISO/IEC 27001:2022, NIST CSF, PCI-DSS, and relevant airline information security regulatory requirements.
The role is also responsible for supporting the communication of governance matters with internal and external groups, for example Internal Audit, Technology Governance forums, Safety & Security, Virgin Group or key suppliers.
This makes it a great role for those looking to step into senior GRC or advisory roles.