Director, Information Security Governance, Risk & Compliance (GRC)

2 days ago
Seniority
Director
Posted
4 May 2026 (2 days ago)

Director, Information Security Governance, Risk & Compliance (GRC)

Life Unlimited. At Smith+Nephew, we design and manufacture technology that takes the limits off living.

Smith+Nephew is seeking an experiencedDirector of Information Security Governance, Risk & Compliance (GRC) to lead and evolve our global GRC function. Reporting to the Chief Information Security Officer, this role will have full accountability for defining, implementing, and continuously improving the Information Security and IT GRC strategy across the enterprise.

This leader will strengthen compliance, reduce information and technology risk, and enable business success—supporting Smith+Nephew’s ambition to be a leader in the medical technology industry. The role requires a strategic mindset, strong execution capability, and the ability to balance assertive leadership with empathy and collaboration.

The Director of Information Security Governance, Risk & Compliance will define, own, and execute the global Information Security and IT GRC strategy, ensuring alignment with Smith+Nephew’s business objectives and risk appetite. This role will lead, build, and develop a high-performing global GRC organization, including teams in low-cost regions, and translate complex regulatory and risk requirements into scalable, measurable programs.

The Director will oversee the governance and compliance landscape by monitoring evolving cyber security laws, regulations, and industry standards, defining and maintaining global information security policies, and deploying appropriate audits and controls to ensure sustained compliance. This includes providing clear, concise reporting, metrics, and insights to executive leadership and key stakeholders.

The role is accountable for designing and operating enterprise-wide IT and Information Security risk management programs. This includes identifying, assessing, documenting, and managing technology, security, and third-party risks, maintaining a comprehensive enterprise risk register, and ensuring risks are effectively communicated and managed.

The Director will lead the global IT SOX compliance program, ensuring strong IT General Controls and successful delivery against leadership-defined KPIs, while partnering closely with internal and external audit teams. In addition, the role will define and maintain IT computer system validation and IT quality assurance programs to meet global regulatory and compliance expectations.

Working in close partnership with Product Security, Commercial, and R&D teams, the Director will ensure compliance programs support customer assurance and commercial growth, including cyber and privacy certifications, audits, and customer tender responses. The role will also lead regulatory intelligence efforts to identify, monitor, and comply with applicable cyber security, privacy, and disclosure requirements worldwide.

This role works in close collaboration with Corporate Finance and Business Teams to align GRC strategy with business objectives and risk tolerance. The Director partners extensively with Internal Audit, Compliance, and Legal teams to ensure regulatory alignment, audit readiness, and effective governance. Strong relationships are also maintained with Corporate IT, Commercial, R&D, and Product Security teams to embed security and compliance into technology operations, product development, and customer-facing activities.

What will you need to be successful?

  • Bachelor’s degree in Information Systems, Computer Science, IT Audit, or a related field, or equivalent professional experience.
  • 10+ years of experience in GRC, IT Information Security, Information Risk Management, and/or IT Audit.
  • Proven experience building, managing, and leading global teams.
  • Extensive experience managing Sarbanes-Oxley (SOX) compliance and IT controls.
  • Strong knowledge of IT General Controls and audit practices.
  • Hands-on experience with GRC platforms and metric-driven continuous improvement.
  • Security and risk frameworks (e.g., NIST CSF, ISO 27002, CSA).
  • Privacy and regulatory requirements (e.g., GDPR, HIPAA, PCI, and other global privacy regulations).
  • Third-party risk management (internal and outsourced models).
  • Policy development, governance, and lifecycle management.
  • Data security, disaster recovery, and information governance.
  • Security and privacy contract review processes.
  • Management of GRC KPIs and executive-level reporting.

Certifications (Preferred)

  • CISA, CISM, CRISC
  • ISO 27001 Lead Auditor

Core Competencies

  • Excellent written and verbal communication skills.
  • Strong stakeholder management skills, with the ability to influence senior leaders.
  • Ability to balance assertiveness with empathy and collaboration.
  • Highly organized with strong attention to detail and problem-solving skills.
  • Ability to operate independently in a complex, global matrix environment.
  • Strong understanding of information security, GRC, and medical device industry trends.
  • Business-oriented mindset with a focus on enabling growth and innovation.

You. Unlimited.

We believe in creating the greatest good for society. Our Strongest investments are in our people and patients we serve.

Inclusion and Belonging: Committed to Welcoming, Celebrating and Thriving on Inclusion and Belonging, Learn more about our Employee Inclusion Groups on our website (www.smith-nephew.com)

Your Future: Generous annual bonus and pension Schemes, Save As You Earn share options, and a car allowance.

Work/Life Balance: Flexible Vacation and Time Off, Paid Holidays and Paid Volunteering Hours, so we can give back to our communities!

Your Wellbeing: Private Health and Dental plans, Healthcare Cash Plans, Income Protection, Life Assurance and much more.

Flexibility: Hybrid Working Model (For most professional roles).

Training: Hands-On, Team-Customised, Mentorship.

Extra Perks: Discounts on Gyms and fitness clubs, Salary Sacrifice Bicycle and Car Schemes and many other Employee discounts.

The anticipated base compensation range for this position is 115,000-125,000 GBP annually and the compensation offered will depend on the candidate’s qualifications. You may also be entitled to receive bonus and benefits, which may include medical, dental, and vision coverage, 401k, tuition reimbursement, medical leave programs, and a variety of wellness offerings.

Stay connected by joining our Talent Community.

We're more than just a company - we're a community! Follow us on LinkedIn to see how we support and empower our employees and patients every day.


Check us out on Glassdoor for a glimpse behind the scenes and a sneak peek intoYou. Unlimited., life, culture, and benefits at S+N.

Explore our website and learn more about our mission, our team, and the opportunities we offer.

Related Jobs

View all jobs

Director, Information Security Governance, Risk & Compliance (GRC)

Smith & Nephew Watford, United Kingdom

Director, Information Security Governance, Risk & Compliance (GRC)

Electronics Engineer Consultant - Security Clearance

Newton Colmore Cambridge, United Kingdom

Director, Procurement Technology & Enablement

Smith & Nephew Cannock Chase, United Kingdom
£100,000 – £150,000 pa On-site

Director, Procurement Technology & Enablement

Smith & Nephew United States
£100,000 – £150,000 pa On-site

Director, Procurement Technology & Enablement

£100,000 – £150,000 pa On-site

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Medical Technology Jobs in the UK (2026 Guide)

Advertising medical technology jobs in the UK requires a different approach to most technical hiring. The medtech candidate pool spans biomedical engineers, regulatory affairs specialists, clinical scientists, software engineers working within IEC 62304 and MDR frameworks, imaging scientists and commercial professionals with deep healthcare sector knowledge. General job boards consistently conflate medical technology with broader healthcare, pharmaceutical and IT roles — producing high application volumes but low candidate quality for specialist medtech positions. This guide, published by MedicalTechnologyJobs.co.uk, covers where to advertise medical technology roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Medical Technology Jobs UK 2026: What to Expect Over the Next 3 Years

Medical technology is one of those rare sectors where commercial ambition and genuine human impact point in exactly the same direction. The devices, diagnostics, digital health platforms, and AI-powered clinical tools that medical technology companies develop do not just generate revenue — they extend lives, reduce suffering, and change what is possible inside the clinical encounter. That combination of purpose and commercial scale makes the medical technology jobs market one of the most compelling in the entire UK life sciences and technology landscape. And that market is changing faster than at any previous point in the sector's history. The integration of artificial intelligence into diagnostic imaging, pathology, and clinical decision support has moved from research demonstration to regulatory approval and NHS deployment. Wearable and implantable devices are generating continuous patient data at a scale that is transforming how chronic conditions are monitored and managed. Digital therapeutics — software that delivers clinically validated therapeutic interventions — have emerged as a recognised product category with its own regulatory pathway. Surgical robotics has moved from a premium offering at a handful of specialist centres to a mainstream surgical platform whose capabilities are expanding with each generation. For job seekers, the medical technology jobs market of 2026 represents an opportunity that is both broader and more technically demanding than it was three years ago. The roles being created now span a wider range of disciplines, require a more sophisticated understanding of the intersection between technology and clinical practice, and carry higher regulatory expectations than the medtech jobs of even a short time ago. This article breaks down what the UK medical technology jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the curve in one of the most consequential sectors in the UK economy.

How Many Medical Technology Tools Do You Need to Know to Get a Medical Technology Job?

If you’re pursuing a career in medical technology, it can feel like the toolkit is endlessly long: imaging systems, data analysis software, regulatory platforms, testing frameworks, prototyping tools, CAD, quality management systems, signal processing libraries and more. Scroll job boards or LinkedIn, and it’s easy to think you need to know every tool under the sun just to secure an interview. Here’s the honest truth most hiring managers won’t explicitly tell you: 👉 They don’t hire you because you know every tool — they hire you because you understand the underlying principles and can apply the right tool in the right context to solve real problems. Tools matter — absolutely — but they are secondary to problem-solving ability, clinical awareness, engineering rigour and the ability to deliver safe, reliable solutions. So how many medical technology tools do you actually need to know to get a job? For most job seekers, the answer is far fewer than you think. This article explains what employers really want, which tools are core, which are role-specific, and how to focus your learning so you look confident, competent and end-game ready.