Supervisor, IT Security, Governance, Risk & Compliance

Date:  Aug 27, 2026
Location(s): 

Winnersh, GB, RG41 5TS

Location(s): 

Winnersh, GB, RG41 5TS

Company:  Hollister Europe Limited

We Make Life More Rewarding and Dignified 

Location: ​Winnersh​
Department: ​IT

 

Summary

The Supervisor, Governance, Risk & Compliance (GRC) leads and enhances the organization's cybersecurity governance, risk management, regulatory compliance, audit readiness, third-party risk, security awareness, privacy coordination, and policy management programs. The role provides both strategic direction and operational oversight while leading a team responsible for ensuring alignment with regulatory requirements, industry frameworks, contractual obligations, and internal security standards. The position serves as a key liaison across Cybersecurity, IT, Legal, Privacy, Compliance, Internal Audit, Quality, and business functions to ensure cybersecurity risks are effectively identified, assessed, communicated, and managed in accordance with business objectives and risk appetite.

Responsibilities

Team Leadership & Management: 
•    Lead, develop, and support a high-performing team of Cybersecurity Analysts. 
•    Set goals, monitor performance, provide feedback, and support professional development. 
•    Recruit, interview, onboard, and coach team members. 
•    Foster a collaborative team environment and work effectively with internal teams, business partners, and external vendors. 

 

Security GRC Oversight: 
•    Oversee day-to-day Cybersecurity GRC activities, including risk assessments, compliance activities, audits, and security assessment coordination. 
•    Develop and maintain SOPs, playbooks, and runbooks for GRC processes with a focus on repeatability and automation. 
•    Evaluate and coordinate security GRC vendors, tools, and services. 

 

Data Protection, DLP & Insider Risk: 
•    Oversee data protection governance, including data classification, sensitivity labeling, data handling standards, and protection of regulated, confidential, proprietary, and sensitive information. 
•    Partner with Privacy, Legal, Compliance, Infrastructure, Enterprise Architecture, and business teams to maintain data protection requirements across cloud, SaaS, endpoint, collaboration, and on-premises environments. 
•    Guide Data Loss Prevention control design, implementation, monitoring, tuning, exception handling, alert review, and risk-based escalation. 
•    Support insider risk management by reviewing sensitive data movement, coordinating investigations, recommending corrective actions, and reporting DLP and data protection trends to leadership. 

 

AI Security Governance: 
•    Support AI security governance policies, standards, control requirements, and review processes. 
•    Assess risks from Generative AI, AI agents, machine learning platforms, third-party AI tools, prompt-based attacks, data leakage, shadow AI, and insecure AI integrations. 
•    Partner with AI governance, Privacy, Legal, Enterprise Architecture, application, and business teams to enable secure and responsible AI adoption. 
•    Define expectations for AI access, data inputs and outputs, logging, auditability, human oversight, and protection of intellectual property and sensitive data. 

 

Governance: 
•    Develop and maintain cybersecurity policies, standards, and procedures, including requirements for data protection, DLP, insider risk, and AI security governance. 
•    Align cybersecurity governance activities with business objectives, regulatory requirements, and applicable security frameworks. 
•    Conduct regular reviews and updates of governance frameworks, controls, and reporting processes. 

 

Risk Management: 
•    Identify, assess, prioritize, and report cybersecurity risks, including data protection, third-party, cloud, vulnerability, and AI-related risks. 
•    Develop and track risk mitigation plans and monitor remediation effectiveness. 
•    Perform risk assessments, vendor and software reviews, and vulnerability analyses. 

 

Compliance & Reporting:  
•    Support compliance with relevant security, privacy, data protection, and AI governance regulations and standards, including PCI-DSS, ISO 27001, SOC, NIST Cybersecurity Framework, HIPAA, GDPR, and emerging AI regulatory expectations. 
•    Produce reports covering risk assessments, compliance posture, DLP trends, insider risk activity, AI governance status, incidents, vulnerabilities, and security awareness metrics. 
•    Participate in internal and external audits, prepare compliance materials, and perform other duties as assigned.

 

Perform other duties as required and assigned

May be required to work outside of normal business hours to respond to urgent cybersecurity matters.

Essential Functions of the Role

  • Communicate effectively via email, phone, and virtual platforms.
  • Collaborate across departments to support organizational goals.
  • Participate in cross-functional meetings and initiatives.
  • Prepare reports and dashboards for internal stakeholders.
  • Ensure data accuracy and confidentiality in compliance with company and legal standards.
  • Demonstrate initiative in identifying process improvements or automation opportunities.
  • Maintain secure handling of sensitive information.
  • Support audits and regulatory reporting as needed.

Education & Work Requirements

  • Bachelor’s Degree with 8-12 years of related experience

Education & Work Preferences

  • Progressive experience in cybersecurity, governance, risk management, compliance, audit, or information security.
  • 3+ years of people leadership, supervisory, or demonstrated workstream leadership experience.
  • Experience supporting or leading ISO 27001, SOC 2, HIPAA, privacy, or similar compliance programs.
  • Experience with Microsoft Purview or similar data protection platforms, including sensitivity labeling, DLP, information protection, classification, insider risk, or compliance management.
  • Strong understanding of network security, incident response, threat hunting, vulnerability management, cloud security, and security reporting.
  • Excellent communication, analytical, problem-solving, decision-making, interpersonal, and presentation skills with the ability to work independently and collaboratively.
  • Experience conducting risk assessments, managing audits, tracking remediation activities, and performing third-party security risk assessments.
  • Experience within healthcare, medical device, manufacturing, life sciences, or other regulated industries.
  • Experience working within a global cybersecurity governance environment.
  • Experience building, implementing, or maturing enterprise GRC programs and reporting outcomes to leadership.
  • Preferred Certifications
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Internal Auditor (CIA)
  • ISO 27001 Lead Implementer or Lead Auditor
  • Certified Data Privacy Solutions Engineer (CDPSE)
  • Preferred Knowledge & Competencies
  • Cybersecurity governance frameworks (ISO 27001, SOC 2, NIST CSF)
  • Risk assessment and audit management methodologies
  • HIPAA, GDPR, privacy, and regulatory compliance requirements
  • Vendor risk management and continuous monitoring
  • Microsoft Purview, Azure security and compliance concepts, identity and access management, and data loss prevention
  • Strategic thinking, business acumen, executive communication, people development, cross-functional collaboration, and risk-based decision making.

Competencies

  • Be Agile - Innovates and adapts quickly, approaching change with curiosity while persisting through obstacles.
  • Be Customer Centric - Considers the needs, experiences and feedback of customers in all we do.
  • Be People-Focused - Builds trust and collaborates with an inclusive and empathetic approach.
  • Be Performance Driven - Operates with an ownership mindset, driving meaningful outcomes.
  • Live The Schneiders’ Legacy, Our Noble Purpose - Passionately serves Our Mission and Vision, while demonstrating the Immutable Principles.

About Hollister Incorporated
Hollister Incorporated is an independent, employee-owned company that develops, manufactures and markets healthcare products worldwide. The company spearheads the advancement of innovative products for ostomy care, continence care and critical care, and also creates educational support materials for patients and healthcare professionals. Headquartered in Libertyville, Illinois, Hollister has manufacturing and distribution centers on three continents and sells in nearly 80 countries. Hollister is a wholly owned subsidiary of The Firm of John Dickinson Schneider, Inc., and is guided both by its Mission to make life more rewarding and dignified for people who use our products and services, as well as its Vision to grow and prosper as an independent, employee-owned company, and in the process, to become better human beings.

EOE Statement
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.

Job Req ID: 36464


Job Segment: Compliance, Internal Audit, Intellectual Property, Information Technology, IT Architecture, Legal, Finance, Technology