Cybersecurity Governance, Risk and Awareness Manager

Date: 2 Oct 2026

Location: England, GB

Company: Coats

The Cybersecurity Governance, Risk and Awareness Manager will help strengthen Coats’ cyber resilience by turning cyber risk into clear business decisions, practical policies, measurable controls and consistent employee awareness. The role establishes and maintains the governance routines, policy framework, cyber risk reporting, control self-assessment approach and awareness programme needed to move Coats from activity tracking to measurable risk reduction. This is a business-facing role that sits at the intersection of Cybersecurity, Digital and Technology, Internal Audit, Risk, Legal, HR, Communications, Procurement and operational teams, working closely with the CISO and wider D&T leadership to embed cyber accountability across Coats globally.

  • Policy, standards and control framework – develop, socialise and maintain priority cybersecurity policies, standards, procedures and a practical control framework that control owners can self-assess against.
  • Cyber governance and operating model – embed a practical governance model with clear decision rights and escalation routes, shifting cyber reporting from activity status to business-readable risk and control effectiveness.
  • Cyber risk management and risk assessments – own the cyber risk register and a consistent risk assessment process for change, ensuring risks are captured, assessed, treated and reported.
  • Security awareness and culture – design and deliver a consistent global awareness programme that builds safer employee behaviours and a positive reporting culture.

 

Education, Qualification and Experience

  • Experience in cybersecurity governance, risk, compliance, information security management, technology risk, internal controls or a related discipline.
  • Hands on experience developing or maintaining policies, standards, control frameworks, risk registers, assurance trackers or governance reporting.
  • Experience working with senior stakeholders and translating cyber risk into clear business language.
  • Experience supporting security awareness, phishing simulation, training, communications or behaviour change programmes.
  • Strong written communication skills and good risk judgement, with the ability to prioritise based on business impact.
  • Degree or equivalent experience in cybersecurity, information technology, risk management, business, audit or a related field.

Even better if...

  • Experience in a complex, multinational or manufacturing environment.
  • Understanding of cyber frameworks such as NIST CSF, ISO 27001 or CIS Controls.
  • Relevant certifications such as CISM, CRISC, CISSP, ISO 27001 Lead Implementer or Lead Auditor, or equivalent experience.
  • Awareness of data protection, third-party risk, IT controls, operational resilience or business continuity.