Full-Time

Head of Governance

Risk and Compliance

Posted on 6/20/2026

Deadline 6/26/26
Barclays

Barclays

10,001+ employees

Wealth management services for UK clients

No salary listed

London, UK

In Person

On-site in London (Canary Wharf), UK. No remote option stated.

Category
Legal & Compliance (1)
Requirements
  • CISM, CRISC, or CISSP certification
  • Experience with DORA (Digital Operational Resilience Act) compliance requirements and implementation
  • ISO 27001 Lead Auditor or Lead Implementer certification
  • PCI QSA or Internal Security Assessor (ISA) qualification
  • Previous experience in FinTech, Digital Banking, Payment Acquiring organisation
  • Experience with Visa GACS and Mastercard SDP acquirer compliance programmes
  • Significant experience of progressive experience in information security governance, risk, and compliance, with at least 5 years leading a GRC team in a regulated environment
  • Strong understanding of UK GDPR and the role of security controls in meeting data protection obligations, including breach notification requirements and data protection impact assessments
  • Experience designing and operating security control frameworks mapped to multiple regulatory requirements simultaneously (e.g., a single framework serving PCI DSS, FCA, and GDPR)
  • Understanding of cloud-native architectures and their implications for compliance and risk management
  • Proven ability to translate technical security risks into business language for executive audiences
  • Experience managing internal and external audit relationships, regulatory examinations, and QSA assessments
  • Understanding of risk quantification methodologies and experience producing risk reporting that supports investment decisions
  • Proven people management experience, developing analysts and building team capability in a growing organisation
  • Experience with GRC tooling and platforms (e.g., Drata, Vanta, ServiceNow GRC, OneTrust, or equivalent)
Responsibilities
  • Own the security policy framework, ensuring policies are current, proportionate, and aligned to PCI DSS, FCA expectations, UK GDPR, and DORA requirements
  • Maintain and operate the security risk register, ensuring risks are assessed consistently using a defined methodology, owned explicitly, and reported accurately to the CISO and Executive Leadership Team (ETL)
  • Manage the relationship with external auditors, the Qualified Security Assessor (QSA), and 2nd/3rd Line of Defence (LoD) on all security and technology risk matters
  • Own the third-party security assurance process, ensuring all vendors, partners, and card scheme integrations are risk-assessed with a tiered approach proportionate to data access and criticality
  • Chair the monthly Cyber and Tech Risk and Controls Forum, presenting risk posture, compliance status, and material findings to the CISO, CIO and ELT
  • Design and maintain the control framework, mapping controls to PCI DSS, FCA, UK GDPR, and DORA requirements, and ensuring control effectiveness is tested on a continuous cycle
  • Produce KRI dashboards and risk reporting for CISO, CIO, and ELT consumption, ensuring risk is communicated in business terms
  • Lead regulatory and audit engagement on security matters, coordinating regulatory review and audit interactions and proactively managing stakeholder relationships
  • Own the risk assessment calendar, ensuring both cyclical and event-driven assessments are executed on schedule with appropriate rigour
  • Manage the risk acceptance process, ensuring risk acceptance decisions are documented, time-bound, approved at the appropriate authority level, and reviewed before expiry
  • Manage and develop the GRC team, building capability across risk assessment, compliance, and third-party assurance disciplines

Barclays Wealth Management provides personalized wealth management services to clients across the UK through a regional network of financial experts. It delivers tailored investment management, financial planning, and estate and trust services, based on each client’s goals, risk tolerance, and time horizon, with support from Barclays’ broader banking resources. The company differentiates itself through its scale and integration, combining local, face-to-face guidance with the back‑end support and product access of a large UK bank. Its goal is to help clients preserve and grow their wealth over the long term while managing risk through a comprehensive, advisor-led service.

Company Size

10,001+

Company Stage

IPO

Headquarters

London, United Kingdom

Founded

1690

Your Connections

People at Barclays who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Large UK wealth market growth supports scalable service expansion.
  • Barclays' broad platform improves cross-sell from banking into wealth services.
  • Sustainability and private-credit themes attract affluent clients seeking tailored advice.

What critics are saying

  • Rising competition from digital challengers compresses fees and client acquisition.
  • Heavy technology spending delays margin gains if productivity improvements lag.
  • Capital requirements reduce balance-sheet capacity and constrain lending returns.

What makes Barclays unique

  • Barclays combines UK wealth management, mortgages, and private banking in one platform.
  • It offers broad service coverage across financial planning, brokerage, and investment management.
  • Recent leadership hires aim to deliver differentiated client experiences in wealth management.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
Zenobē
Jun 19th, 2026
Zenobē secures c.£980m financing to accelerate roll-out of electric buses across the UK and Ireland - Zenobē

Zenobē secures c.£980m to accelerate electric bus deployment and charging infrastructure across the UK and Ireland.

Business Examiner
Jun 1st, 2026
Social Housing REIT secures £30m loan from Barclays | BE News

Social Housing REIT has secured a new £30m floating rate debt facility with Barclays Bank.

Real Estate Capital Europe
May 22nd, 2026
Loans in focus: Patron kicks off lending strategy with two UK loans, pbb and Helaba provide €185m for Prague office park, Barclays issues £180m to Edmond de Rothschild

Patron Capital Partners kicks off its lending strategy with the provision of £107 million (€124 million) of loans in the UK; pbb Deutsche Pfandbriefbank and Helaba provide a €185 million refinancing facility to Crestyl Group for its Prague office park; Barclays issues a £180 million green refinancing facility to Edmond de Rothschild REIM backed by five build-to-rent assets; the latest additions to the Real Estate Capital Europe lending database; and more in our round-up of European loan deals from the past week.

Senseonics Holdings, Inc.
May 6th, 2026
Senseonics Announces Closing of $92 Million Public Offering and Full Exercise of Underwriters’ Option to Purchase Additional Shares

GERMANTOWN, Md., May 04, 2026 (GLOBE NEWSWIRE) -- Senseonics Holdings, Inc. (NASDAQ: SENS), a medical technology company focused on the design, development and commercialization of long-term, implantable continuous glucose monitoring (CGM) systems for people with diabetes, today announced the closing of its previously

StreetInsider
Apr 14th, 2026
Marathon Petroleum enters $5 billion credit agreement

Marathon Petroleum Corporation (NYSE: MPC) entered into a $5 billion, five-year revolving credit agreement on April 7, 2026, according to a company statement.The agreement involves JPMorgan Chase Bank as administrative...