These are some of the key components to the position:
• Maintain and operationalise JET’s security governance documentation policies, standards, and control models keeping them aligned to JET’s risk appetite and frameworks including NIST CSF and ISO 27001.
• Run governance forums and working groups, ensuring decisions are documented, tracked, and communicated to engineering, risk, and compliance stakeholders in a timely way.
• Coordinate evidence gathering and control validation across L1, L2, supporting audit cycles and maintaining a clear, accountable control registry.
• Draft and refine technical security standards for cloud platforms (AWS/GCP), CI/CD pipelines, and third-party integrations, working with Engineering Leads to embed these into delivery workflows.
• Track exceptions and remediation plans with technical owners, escalating risks where needed and maintaining visibility across the Three Lines of Defence.
• Build and maintain KPI/KRI dashboards that provide stakeholders with clear, accurate visibility of control health and compliance posture.