Job Description

The Governance & Compliance Team Lead is responsible for defining, implementing, and maintaining cyber security policies, standards, and procedures that ensure Sellafield Ltd operates securely and in full alignment with regulatory and legal obligations. Operating within a complex, safety-critical, and highly regulated environment, the role leads the development and oversight of cyber compliance frameworks, ensuring alignment with applicable legislation and industry best practice. The postholder supports the Head of GRCA in maintaining regulatory confidence and embedding cyber governance across the organisation. As the owner of cyber compliance requirements, the role provides expert guidance to internal stakeholders, supports audit readiness, and drives continuous improvement in governance maturity. Through strategic leadership and effective stakeholder engagement, the Governance & Compliance Team Lead plays a key role in strengthening the organisation’s cyber posture and ensuring accountability across all levels of the business.

Principal Accountabilities

• Lead the development, maintenance, and communication of cyber security policies, standards, and procedures across the organisation.
• Ensure compliance with applicable legal and regulatory requirements, including ONR SyAPs, NISR 2003, GDPR, and the HMG Security Policy Framework.
• Own and manage the cyber compliance framework, ensuring it reflects the organisation’s risk appetite and supports strategic objectives.
• Monitor and report on compliance performance through meaningful metrics, dashboards, and governance reporting.
• Coordinate and support internal and external audits, including regulatory inspections, and manage timely responses to findings.
• Provide subject matter expertise on cyber governance and compliance to ICT, business units, and project teams.
• Collaborate with risk and assurance leads to ensure governance controls are risk-informed, effective, and proportionate.
• Promote awareness and understanding of cyber security policies and compliance obligations through training and engagement.
• Support the Head of GRCA in regulatory engagement and the development of governance forums, reporting structures, and assurance activities.
• Drive continuous improvement in governance and compliance maturity, ensuring alignment with evolving threats and business needs.

Authorities & Dimensions:
• Budget Responsibility: Contributes to the management of governance and compliance activities within the GRCA budget.
• Line Management: Direct line management of >5 resources.
• Decision-Making Authority: Authority to approve policy changes and compliance reporting outputs.

Knowledge & Experience

Job Context & Challenges

The Governance & Compliance Team Lead operates at the heart of a high stakes, safety critical environment where cyber security governance is subject to intense regulatory scrutiny and evolving legal obligations. The role demands a careful balance between enforcing strict compliance and enabling operational flexibility to support business delivery. With a constantly shifting landscape of legislation, policy frameworks, and industry expectations, the postholder must maintain a forward-looking view of compliance risks and opportunities, ensuring the organisation remains both defensible and adaptable. This requires not only technical expertise in governance and regulatory standards but also the ability to influence and embed policy across diverse business functions. The role supports the Head of GRCA in sustaining regulator confidence, driving governance maturity, and ensuring that cyber security is governed with clarity, accountability, and strategic alignment across the enterprise. Navigating complex

Essential Skills

• Strong experience in cyber security governance and compliance within a regulated environment.
• In-depth knowledge of relevant legislation and frameworks (e.g., NISR 2003, GDPR, ONR SyAPs, SPF).
• Experience developing and managing cyber security policies and compliance frameworks.
• Strong communication and stakeholder engagement skills, including experience working with regulators.
• Ability to interpret complex regulatory requirements and translate them into practical controls.
• Methodical and detail-oriented.
• Strong ethical standards and integrity.
• Collaborative and able to influence across functions.  Resilient and able to manage competing priorities.
• Degree or equivalent in cyber security, law, governance, or a related field.
• Relevant certifications (e.g., CISM, ISO 27001 Lead Implementer, CIPM).

Desirable Skills

• Experience in the nuclear or critical national infrastructure (CNI) sector.
• Familiarity with CAF implementation and maturity assessments.
• Experience with policy automation and compliance tooling.
• Knowledge of data protection and information governance frameworks.

Additional Information

• Open VN
• Number of Vacancies: 1
• Contact/s: Nicola Lyons

ASW’s may have the right to apply for internal Sellafield Ltd vacancies. Please note if you are an Agency Supplied Worker you are required to attach evidence of all qualifications obtained to support your application. We require a minimum of A*-C (9-4) GCSE in English Language, Maths & Science/IT or equivalent / higher qualification.

If you choose to apply for this role and your application is shortlisted by the hiring manager, you will be invited to a competency based interview. The competencies will be issued when invited to interview.

Please see link to the competency framework for further information:
https://slportal.ssa-intra.net/pub/SC001/00027/Competency%20Framework/Forms/AllItems.aspx

If your technical competency is not in the above framework, please refer to the profession’s share point page for further information.

Sellafield Ltd are recognised as a Disability Confident Employer (Level 3). Disability Confident employers offer an interview to disabled applicants that meet the minimum criteria for a vacancy. Sellafield Ltd define the minimum criteria as the ‘essential skills’ which are listed on the vacancy notice. Whilst completing your application form, you will be able to indicate if you wish to be considered under the disability confident scheme. If you would prefer to discuss this directly with us, please contact the GBS Recruitment team on recruitment@sellafieldcloud.co.uk

Please ensure that you save a copy of this advert for future reference if you make an application for this role.

The closing date for this vacancy is Monday 31st August 2026.

Governance & Compliance Team Lead

Job number

SP06768

Profession

IT Information Services

Location

Risley Warrington

Contract type

Internal Recruitment

Posting date

16 August 2026

Closing date

31 August 2026

Band

3B Upper

Work Schedule

Days