ICA Compliance Jobs
Search

Governance, Risk and Compliance Manager

companyThe University of Manchester
locationManchester, UK
PublishedPublished: Published 1 week ago
Enterprise Risk
About IT Services

IT Services at the University of Manchester is a vibrant and fast-moving department, we focus on delivering excellent customer service and quality services for our staff, students and researchers.

The Team

The Governance, Risk & Compliance (GRC) team sits within the Directorate Services division within the IT Services Directorate. Directorate Services consists of: Operational Support; IT Supplier Management; IT Governance, Risk and Compliance; and IT Health and Safety. These critical functions control and/or govern all aspects of the running of the IT Directorate and have large budgets, long-term strategic planning requirements and complex risk portfolios associated.

The Role

The GRC Manager will play a crucial role in the delivery of the GRC governance structure and risk framework. This position involves managing a team of GRC analysts and overseeing critical areas such as financial management, budgeting, and risk management. The GRC Manager will support the Head of GRC in:
  • Developing a robust risk framework for ITS, integrating it with data governance and security, and aligning with the broader stakeholder groups of the University.
  • Managing financial oversight of ITS assurance obligations, including but not limited to: Finances, Budgets, PCI, IG Toolkit, GDPR, Health and Safety, EDI, and ISO27001.
  • Leading process improvement initiatives, fostering a culture of agility and innovation within the team. This includes streamlining operations, enhancing workflows, and implementing best practices to achieve measured outcomes that align with the strategic goals of IT Services.
  • Leading supplier assurance and due diligence activities, managing relationships with Security, supplier management, data governance, and wider ITS partners to assess and manage suppliers effectively.
The Person

The successful candidate should be able to demonstrate:
  • Experience of working with management frameworks, e.g. ISO/IEC 27001, ITIL, COBIT and NIST SP800.
  • Strong financial acumen, with experience overseeing budgets, planning, and forecasting.
  • A solid understanding of compliance requirements for areas such as PCI, GDPR, and other national bodies.
  • Proven ability to drive continual improvement, with a focus on financial efficiency and risk management.
  • Extensive experience in developing and maturing IT risk capabilities & processes, leading risk awareness initiatives, and contributing to the prioritisation and implementation of operational risk requirements.
  • Experience of managing the interface between the organisation, audit, second line and other functions.
  • Strong knowledge of supplier assurance and due diligence activities, ensuring a risk-based view of third parties and services.
Desirable qualifications: COBIT, ITIL (Intermediate or higher), ISO27001 Lead Auditor, Information Systems, Risk Management or other related qualification.

What can you expect in return
Our diverse job opportunities all include a top benefits package that includes many features that are hard to find in the private sector:
  • Generous annual leave allowance, including Christmas/New Year closure;
  • Pension scheme membership to provide benefits for you and your family;
  • Well-being programme with counselling, fitness and leading sports facilities;
  • Learning and development opportunities;
  • Season ticket loans for public transport;
  • Cycle to Work Scheme;
  • Workplace nursery scheme;
  • Staff recognition schemes;
  • Staff discounts on a range of products and services including travel and high street savings.
In fact, there are so many benefits available you can see more of them by clicking HERE

Find out more about our organisation and values:
  • IT Services: About us and ITS Practice Charter
When completing the additional information section of your application, please ensure you make reference to the job description and person specification above, as this will form an integral part of the shortlisting process.

As an equal-opportunity employer, we welcome applicants from all sections of the community regardless of age, sex, gender (or gender identity), ethnicity, disability, sexual orientation and transgender status. All appointments are made on merit.

Our University is positive about flexible working - you can find out more here

Blended working arrangements may be considered.

Please note that we are unable to respond to enquiries, accept CVs or applications from Recruitment Agencies.

Enquiries about the vacancy, shortlisting and interviews:

Name: IT Resource Management Team

Email: it.resource@manchester.ac.uk

General enquiries:

Email: People.Recruitment@manchester.ac.uk

Technical support:

Jobtrain: 0161 850 2004 https://jobseekersupport.jobtrain.co.uk/support/home

This vacancy will close for applications at midnight on the closing date.

Please see the link below for the Further Particulars document which contains the person specification criteria.