• Conduct information security and compliance risk assessments, maintaining and updating our risk register.
• Manage third-party risk — from due diligence and onboarding to ongoing oversight — ensuring suppliers meet our high standards.
• Partner with project teams to embed security, legal, and regulatory requirements into every stage of delivery.
• Develop and enhance security policies and standards, making them clear, relevant, and actionable.
• Support awareness and education programmes that bring our security principles to life.
• Prepare and organise evidence for audits and compliance assessments.
• Participate in governance and risk forums, sharing insights and ideas that help shape our security strategy.