This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Barclays is seeking a Data Security Governance & Compliance Lead to provide leadership across the bank’s enterprise data security governance. This role acts as the single point of accountability for defining, maintaining, and enforcing the organisation’s data security strategy, policies, and regulatory alignment. You will lead a centralised governance function that ensures data protection controls are consistent, effective, and regulator‑defensible across all business units and geographies. Sitting at the intersection of cyber security, data ownership, and regulatory oversight, the role works closely with the CISO, CDO, Privacy, Cryptography, and Data Protection Operations teams to ensure data risks are managed in a coordinated and scalable manner. This is a highly influential role for an experienced leader who can balance regulatory rigour, business enablement, and executive engagement in a complex global environment.
Job Responsibility:
Collaboration with stakeholders to understand their security requirements in business processes and IT projects, to enhance overall risk management.
Execution of risk assessments to identify and prioritise potential cybersecurity threats that could impact the banks operations and data and guide the implementation of mitigation strategies and communicate findings to relevant findings to relevant senior stakeholders.
Collaboration with business units to develop and implement security policies and procedures for the banks operations aligned to the risk management framework.
Management of the implementation, testing and monitoring of security controls across the banks IT systems to ensure the effectiveness of controls and mitigation of risk.
Execution of training content and sessions to educate employees, enhance cybersecurity awareness and provide guidance on safe online practices.
Management of complex cybersecurity incidents by collaborating with IT teams and response experts to effectively resolve cases through analysis, expertise support and project supervision.
Identification of emerging cybersecurity trends, threats, and new technologies to address potential risks by advocating the adoption of new security solutions.
Requirements:
Data Security Governance & Policy Leadership -Proven ability to define, own, and enforce enterprise‑wide data security policies, standards, and governance frameworks in a regulated environment, covering areas such as data classification, DLP, encryption, and access controls.
Regulatory & Risk Management Expertise- Deep understanding of data protection and security regulations (e.g. GDPR, banking regulatory standards) and the ability to demonstrate compliance through robust governance, metrics, and audit or regulator engagement.
Senior Stakeholder Influence & Leadership - Strong capability to influence senior executives and cross‑functional leaders (CISO, CDO, CTO, Privacy, Operations) and lead teams within a global, matrixed organisation, without relying solely on direct authority.
Nice to have:
Senior Leadership Experience within Global Financial Services - Experience leading enterprise‑wide governance activities in a senior role within a global financial institution, navigating complex regulatory and compliance environments.
Professional Security or Privacy Certifications- Relevant certifications such as CISSP, CISM, CRISC, CIPM/CIPT, or ISO 27001 Lead Implementer/Auditor, demonstrating depth in security governance and data protection.
Awareness of Emerging Data & AI Security Topics - Knowledge of emerging data security technologies and AI‑related security considerations, supporting effective horizon scanning and future‑proofing of the data security governance strategy.