Head of Security Governance - Director
Date: 28 Sept 2026
Location: London (Lon), GB
Company: Mizuho
Profile Summary
As Head of Security Governance, the role has overall senior responsibility for defining, directing and overseeing the Security Governance function across EMEA, operating as a senior business-facing security leader within the EMEA CISO Office. The role provides strategic and operational leadership across policy oversight and communications and awareness. It is accountable for ensuring that security policy, risk oversight, regulatory assessment activity, user behaviour, data protection controls and training and awareness processes operate effectively, demonstrably and in alignment with Head Office, Group, regulatory, audit and business requirements.
The role is expected to work collaboratively with business management, technology teams, control functions, Head Office, local office stakeholders and the EMEA ISO organisation to uplift cyber governance, staff security behaviours, control maturity and demonstrable compliance across the entities served in the region.
- Provide senior leadership for business-related security interaction across EMEA, ensuring security requirements are translated into pragmatic business controls, operating practices and measurable outcomes.
- Own and continuously mature the control operating model across policy, regulatory/security risk assessments, security communications, training and awareness and related controls.
- Act as a senior interface between the EMEA CISO Office, Head Office, business stakeholders, technology teams, audit, compliance, risk management and local office security stakeholders.
- Drive consistent standards, evidence quality, governance cadence and management information across security activities, including issue escalation, remediation tracking and senior reporting.
Duties and Responsibilities
- Maintain, review and enhance information security policies, standards, procedures and supporting guidance, ensuring alignment with Group requirements, Head Office direction, regulatory expectations and relevant industry practice.
- Lead the security risk and maturity assessment cycle, including assessment methodology, evidence standards, thematic analysis, maturity scoring, action tracking and senior management reporting.
- Coordinate and oversee regulatory and industry-aligned security assessments, including SWIFT, ISO/IEC 27001 and other applicable cyber, operational resilience, data protection or regulatory reviews.
- Act as a principal contact for Head Office interaction, ensuring timely responses to Head Office requests, effective translation of Group requirements into EMEA obligations and clear escalation of local constraints or risk acceptances.
- Coordinate audit activity relating to control oversight, cyber policy, user controls, and related process domains, including audit planning support, evidence production, management action tracking and closure validation.
- Establish oversight of user behaviour and acceptable use policy monitoring, ensuring findings are reviewed, escalated and remediated proportionately, with due consideration of HR, Legal, Compliance and privacy requirements.
- Provide senior oversight of data loss prevention, data handling, information classification and related user control activity, ensuring control gaps, process weaknesses and behavioural themes are identified and addressed.
- Develop high-quality governance reporting, risk insights and management information to support the EMEA CISO, business leadership, committees and relevant control functions.
Communications and Awareness:
- Set the direction for the EMEA cyber awareness and security communications strategy, ensuring it is risk-based, business-relevant, measurable and aligned to Mizuho’s threat and control priorities.
- Oversee general business cyber awareness training, ensuring that training content is maintained, completion is monitored and outcomes are reported through appropriate governance routes.
- Develop and direct role-based training for higher-risk or specialist populations, including privileged users, application owners, control owners, senior managers, approvers and staff handling sensitive or classified information.
- Take ownership of phishing simulation and awareness processes, including campaign objectives, business engagement, communication strategy, results analysis, targeted remediation and continuous improvement of staff resilience to social engineering threats.
- Lead staff communication on cyber security themes, emerging risks, control expectations, incidents, lessons learned and policy changes, ensuring messaging is timely, concise and appropriate for the target business audience.
- Use training outcomes, phishing simulation results, DLP/classification themes and user behaviour monitoring to identify targeted interventions and evidence cultural uplift over time.
Security Service Management:
- Define, maintain and report security service KPI and KRI metrics, ensuring measures are meaningful, risk-based, consistently evidenced and suitable for senior management, committee and Head Office oversight.
- Oversee third-party security posture monitoring, including review of supplier control performance, cyber risk indicators, assurance outputs, remediation progress and material changes in service or threat exposure.
- Produce regular control and performance status reporting across managed security services, highlighting control effectiveness, operational issues, SLA performance, emerging risks, dependencies and required management actions.
- Manage outsourcing relationship governance for relevant security services, supporting service reviews, issue escalation, risk acceptance, contractual control obligations, exit considerations and alignment with internal outsourcing and third-party risk management requirements.
Leadership, Governance and Stakeholder Management:
- Lead, develop and manage the security governance team, setting clear priorities, performance expectations, development plans and standards for quality, timeliness and professional judgement.
- Provide senior-level challenge and advice to business stakeholders on security policy compliance, access control, user behaviour, data handling and cyber awareness obligations.
- Ensure security risks, issues, control gaps, audit findings and maturity observations are captured, owned, tracked and escalated through appropriate governance forums.
- Promote consistent, transparent and evidence-based decision-making across security processes, with particular focus on balancing business enablement, regulatory compliance and cyber risk reduction.
Qualifications, Skills and Experience
Essential:
- Degree-level education or equivalent senior professional experience in information security, cyber risk, technology risk, control governance, audit, operational resilience, compliance or a related discipline.
- Recognised professional information security, risk, audit or governance qualification, or demonstrable equivalent experience, such as CISM, CISSP, CRISC, CISA, ISO/IEC 27001 Lead Implementer/Lead Auditor, or equivalent.
- Strong understanding of financial services regulatory expectations relating to cyber security, operational resilience, technology risk, data protection and access governance.
- Extensive senior experience in information security, technology risk, cyber governance or a related control function within banking, investment banking, financial services or another highly regulated environment.
- Demonstrable experience of leading policy governance, control oversight, maturity assessment, risk assessment, regulatory assessment or audit coordination activity across multiple stakeholders and entities.
- Experience operating with Head Office, Group or regional governance requirements, including translating central standards into local obligations and escalating conflicts, gaps or implementation challenges.
- Practical experience of cyber control frameworks and assurance regimes, such as ISO/IEC 27001, NIST, COBIT, ISF, SWIFT CSP, SOX, Operational Resilience requirements or equivalent regulatory/audit frameworks.
- Experience developing or overseeing security awareness, phishing simulation, user communication and role-based training programmes.
- Experience producing management information, committee reporting, risk dashboards or maturity reports for senior management, audit, risk, compliance or regulatory audiences.
- Proven leadership experience, including managing priorities, developing staff, building team capability and sustaining high standards of delivery across a multi-disciplinary function.
- Broad knowledge of cyber security governance, risk and control disciplines, including policy management, security assurance, audit response, incident learning, access control, data protection and user behaviour controls.
- Ability to assess control design and operating effectiveness, identify maturity gaps, prioritise remediation and explain risk clearly to technical and non-technical stakeholders.
- Strong written communication skills, with the ability to draft policies, standards, management papers, awareness communications, audit responses and governance updates suitable for senior audiences.
- Working knowledge of security technologies and control environments across applications, infrastructure, networks, end-user computing, monitoring, vulnerability management, DLP, classification and access management.
Desirable:
- Additional qualifications or training in data protection, audit management, privacy, operational resilience, SWIFT Customer Security Programme, COBIT, ITIL or recognised cyber control frameworks.
- Management or leadership training relevant to leading multi-disciplinary teams and senior stakeholder engagement.
- Experience with data loss prevention, information classification, acceptable use monitoring, security culture measurement or behavioural risk analytics.
- Experience managing third-party or outsourced cyber security service providers, including MSSPs, SOC providers, assurance partners or specialist testing providers.
Key Behaviours/Competencies:
- Senior leadership presence, sound judgement and the ability to influence across business, technology, risk, compliance, operational resilience, audit and Head Office stakeholders.
- Strategic business management mindset, focused on improving cyber maturity, sustaining effective controls and enabling the business to operate securely.
- High standards of ethics, conduct, confidentiality and escalation discipline, particularly when handling sensitive user behaviour, access, data handling or audit matters.
- Client-centric and outcome-focused approach, balancing business enablement with proportionate security challenge and regulatory accountability.
- Ability to lead through ambiguity, prioritise competing demands, drive remediation and maintain momentum across complex stakeholder groups.
- Commitment to continuous improvement, evidence quality, operational discipline and the professional development of team members.
What Mizuho Can Offer You
Here at Mizuho, there are fantastic progression opportunities and clear paths to promotion. We will give you ample opportunity to affect change and to help grow our business.
In addition to the great opportunity outlined above we are also currently able to offer:
- Competitive starting salary, plus discretionary bonus
- Non-contributory pension
- 27 days’ annual leave
- Core working hours*
- Hybrid working - office and home based*
- Virtual GP
- Wellbeing benefits, including Mental Health Allies and First Aiders
*For applicable roles only
At Mizuho, we embrace flexible ways of working when the role permits. We offer different working arrangements like part-time, job-sharing and hybrid (office and home) working. Our purpose-led culture and global infrastructure help us connect, collaborate, and work together in agile ways to meet all our business needs.
We are committed to supporting equality and diversity, and seek to create a workplace that is fully inclusive. We welcome applications from all sections of the community that we operate in and from all ethnic backgrounds, sexual orientation, beliefs, gender identities and disabilities
If you require more information about our equal opportunities policy or wish to discuss any accessibility requirements or reasonable adjustments please contact the recruitment team – recruitment@mizuhoemea.com and we will be happy to help.