Group Head of IT & Information Security Risk and Governance

Group Head of IT & Information Security Risk and Governance

Location
Angel Court, London
Location
Full Time
Apply

Job Description:

Group Head of IT & Information Security Risk and Governance

Flexible on location - attending meetings in London a couple of times a month

Hybrid & flexible working options

Permanent

Salary - £95,000 - £110,000 per annum + benefits package

Full Time - 35 hours

Closing date for applications - Monday 8th December 2025

We make health happen!

At Bupa, our purpose is simple: helping people live longer, healthier, happier lives and making a better world. With no shareholders, our customers are at the heart of everything we do.

The Group Head of IT & Information Security Risk and Governance will be responsible for developing, leading, and maintaining a comprehensive IT and information security risk management program. This role ensures that the organisation effectively identifies, assesses, manages, and mitigates IT and security risks across all information assets and systems. This role is key to ensuring the organisation remains resilient against evolving information security threats while maintaining compliance with industry standards. The Group Head of IT & Information Security Risk and Governance will lead efforts to create a robust security environment and minimise risks to critical business operations.

Key Responsibilities:

  • Maintain and oversee the global IT & information security risk management strategy that aligns with the organisation's overall business objectives and risk appetite underpinning the Enterprise Risk Management Framework.
  • Define and oversee risk assessment methodologies, controls, and reporting structures.
  • Active involvement in the use of security tools and technologies that support risk identification, monitoring, and mitigation to strengthen the organisation's security posture and reduce risk.
  • Conduct thematic risk assessments and evaluations to identify potential threats and vulnerabilities in the organisation's IT infrastructure and applications.
  • Collaborate with cross-functional teams to assess the impact of new technologies, regulations, and security standards on the organisation's risk landscape.
  • Develop processes for continuous monitoring of IT and security risks and the effectiveness of implemented controls.
  • Lead governance frameworks, policies, and procedures across Bupa market units.
  • Deliver accurate, timely reports for regulatory, board, and operational purposes.
  • Champion risk awareness and training across the organisation.
  • Collaborate with internal teams to enhance the understanding of IT and information security risks and promote risk-based decision-making.
  • Manage and develop the IT & Information Security Risk and Governance team, fostering collaboration and innovation.
  • Act as the primary point of contact for IT and security risk queries, engaging with internal and external stakeholders within Group Information Security and the Market Units.

What We're Looking For:

  • Proven track record of building teams and leading risk management in a complex, global organisation.
  • Extensive experience in IT and information security risk management, cybersecurity, or a related field with demonstrated success in leadership roles.
  • Deep understanding of IT and security frameworks, risk assessment methodologies, and industry regulations.
  • Excellent leadership, communication, and stakeholder management skills.
  • Ability to translate complex technical risks into actionable recommendations.
  • Proficiency in using risk management tools, platforms and security technologies.
  • Strategic thinker with a proactive approach to problem-solving.
  • A master's degree or professional certifications such as CISSP, CISM, or CRISC are highly desirable.
  • Bachelor's degree in IT, information security, Cybersecurity, computer science, risk management, or a related field.

Benefits

Our benefits are designed to make health happen for our people. Viva is our global wellbeing programme and includes all aspects of our health - from mental and physical, to financial, social and environmental wellbeing. We support flexible working and have a range of family-friendly benefits.

Joining Bupa in this role you will receive the following benefits and more:

  • 25 days holiday, increasing through length of service, with the option to buy or sell
  • Enhanced pension and life insurance
  • Annual Bonus
  • Car Allowance
  • Private medical insurance
  • Global wellbeing days
  • Opportunities for career development and internal mobility

Why Bupa?

We're a health insurer and provider. With no shareholders, our customers are our focus. Our people are all driven by the same purpose - helping people live longer, healthier, happier lives and making a better world. We make health happen by being brave, caring and responsible in everything we do.

We encourage all of our people to "Be you at Bupa", we champion diversity, and we understand the importance of our people representing the communities and customers we serve. That's why we especially encourage applications from people with diverse backgrounds and experiences.

Bupa is a Level 2 Disability Confident Employer. This means we aim to offer an interview/assessment to every disabled applicant who meets the minimum criteria for the role. We'll make sure you are treated fairly and offer reasonable adjustments as part of our recruitment process to anyone that needs them.

Time Type:

Full time

Job Area:

Locations:

Angel Court, London

Group Head of IT & Information Security Risk and Governance

Location
Angel Court, London
Location
Full Time
Apply
DJD Purpose.jpg

Our
purpose

Bupa’s purpose is helping people live longer, healthier, happier lives and making a better world. We do this by providing a broad range of healthcare services, support and advice to people throughout their lives. People are at the heart of everything we do. Together, we make health happen.

Our
values

Every company needs an ethos, and we're no different. Through good days and challeging times, we always work with our values in mind. These are: Brave - Make new possibilities happen. Caring - Act with empathy and respect. Responsible - Own your decisions and actions.

We don't have shareholders at Bupa, which means we're free to invest our profits where they matter: our patients, our facilities, our research, and you. 

As a healthcare provider, we have a duty to do the right thing. By our customers, our people and our partners. The Bupa Code holds us to this duty. It's our promise to protect, care for, and build trust with everyone who relies on us.

DJD Values.jpg
DJD Inclusion.jpg

Free to be
you

Here you’ll be welcomed. We champion diversity and we understand the importance of our people representing the communities and customers we serve. 

You’ll find an inclusive environment where you can be yourself and where everyone is driven by the same purpose – helping people live longer, healthier, happier lives and making a better world.Free
to be you.

Back in September 2018, we made a pledge. That we'd do whatever we could to make Bupa a diverse, kind and inclusive place to work.

Everyone deserves a positive working environment. Everyone deserves to have their voice heard. Everyone deserves freedom from bullying, harassment and discrimination.

Group Head of IT & Information Security Risk and Governance

Location
Angel Court, London
Location
Full Time
Apply