×
Register Here to Apply for Jobs or Post Jobs. X

Head of Cyber Security Risk

Job in Birmingham, West Midlands, B1, England, UK
Listing for: CRH
Full Time position
Listed on 2026-01-15
Job specializations:
  • IT/Tech
    Cybersecurity, IT Project Manager, Information Security, Data Security
Job Description & How to Apply Below

Join to apply for the Head of Cyber Security Risk role at CRH

Position Overview

The Head of Cyber Security Risk will lead the strategic direction and operational execution of cyber risk management across CRH International. This role is critical to ensuring the protection of digital assets, operational resilience, and regulatory compliance across diverse global operations.

As a key member of the CRH International Technology Leadership Team, reporting directly to the International CIO, the role will influence enterprise‑wide decisions on cyber risk, resilience, and cyber transformation, while working closely with CRH Group functions.

The successful candidate will bring a proven track record of applying real‑world, pragmatic approaches to cyber risk, striking a balance between strategic oversight and hands‑on delivery. They will drive technical enhancements and measurable risk reduction across CRH’s international operating companies, while working seamlessly across both technical and business teams.

This role requires a leader who can balance diverse stakeholder expectations, navigate ambiguity, simplify and clarify direction, and drive continuous improvement across CRH International’s cyber posture.

Key Tasks and Responsibilities
  • Define and lead a collaborative cyber risk strategy aligned with CRH International’s business and digital transformation goals.
  • Establish governance and processes to manage cyber risk across CRH International business units, operating companies and central teams and functions.
  • Integrate cyber risk thinking and outcomes into CRH International’s risk management and strategic planning processes.
  • Drive continued improvement in all areas of cyber risk across the division, leading the existing team, and collaborating with Operating Companies.
  • Apply practical, business‑aligned approaches to identifying, assessing, and prioritising cyber risks.
  • Prioritise and implement risk‑based controls and mitigation strategies that reflect operational realities and business constraints.
  • Balance competing demands and priorities, while ensuring overall enhancements and progress aligned to the Divisional strategic objectives and roadmaps.
Transformation & Technical Enhancement
  • Drive the transformation of cyber risk capabilities across CRH’s international operating companies, moving from theory to transformative impact and outcomes.
  • Lead the deployment of security roadmaps, technologies and automation to enhance detection, response, and resilience services in place today.
  • Define central priorities, outcomes, roadmap and operational security metrics, capabilities and services.
  • Oversee the evolution of GRC platforms, threat intelligence, and incident response capabilities to support improved reporting across CRH International.
Cross‑Functional Collaboration
  • Work to ensure alignment and co‑development of Group cyber security requirements (e.g. Policies, Standards, and Strategic Direction), while ensuring divisional balance.
  • Work collaboratively with members of the existing Risk & Internal Control, Technology Operations, Technology Driven Transformation, Internal Audit and central Cyber team to achieve joint wins and outcomes.
  • Work closely with IT, OT, product, and commercial teams to embed cyber risk management into business processes and technology platforms.
  • Foster a culture of shared accountability for cyber risk across technical and non‑technical stakeholders.
  • Ensure cyber risk initiatives support CRH’s customer‑centric approach and operational excellence.
Stakeholder Engagement & Influence
  • Serve as the key owner and be accountable for cyber security risk for CRH International, working closely with the CRH International CIO, senior leadership, and relevant stakeholder committees on cyber risk matters.
  • Balance competing stakeholder expectations while maintaining focus on long‑term risk reduction and resilience.
  • Communicate effectively across all levels of the organisation, translating technical risk into business language, with simple common‑sense action plans and implementation approaches.
Navigating Ambiguity & Driving Posture Improvement
  • Operate effectively in complex, ambiguous environments where risk is evolving…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary