Information Security and Compliance Risk Manager

Reference: yg32h4k17kyunkyutyiq

We are seeking an Information Security and Compliance Risk Manager to lead the development, implementation and continual improvement of information security, compliance and enterprise risk management practices. This role will provide trusted advice to senior stakeholders, helping to identify, assess and manage technology, information and operational risks across the organisation. You will support a strong culture of security and accountability while ensuring that policies, controls and processes remain aligned with relevant legislation, regulatory expectations, industry standards and business objectives.

Key responsibilities will include maintaining the information security and compliance risk framework; managing risk assessments, control reviews, assurance activities and remediation plans; and monitoring the effectiveness of security and compliance controls. You will coordinate internal and external audits, prepare clear reports for governance forums, track actions through to completion and provide constructive challenge where risks or control weaknesses are identified. The role will also contribute to incident response, business continuity, third-party risk management, privacy and data protection activities, policy development, security awareness and ongoing regulatory change. You will work collaboratively with technology, legal, procurement, internal audit and operational teams to embed practical, proportionate and sustainable risk management practices.

The successful candidate will have substantial experience in information security, technology risk, compliance, governance or a related discipline, with a strong understanding of recognised frameworks such as ISO 27001, NIST, COBIT or equivalent. Experience of conducting risk assessments, managing audit programmes, interpreting regulatory requirements and presenting complex issues to senior audiences is essential. Relevant professional qualifications, such as CISA, CISM, CISSP, CRISC, ISO 27001 Lead Implementer or Auditor, are desirable. You will be analytical, organised and confident in influencing stakeholders at all levels, with excellent written and verbal communication skills. A pragmatic approach, sound judgement, strong attention to detail and the ability to manage competing priorities are key to success in this role.

COMPETITIVE SALARY
Added 26/08/2026
Reference: yg32h4k17kyunkyutyiq

Information Security and Compliance Risk Manager

London, England, United Kingdom Permanent Compliance

Other similar jobs

Business Information Security Officer, Dental & Care Services

Added 09/09/2026

We are seeking a Business Information Security Officer to support the secure delivery of dental and care services across a complex, people-focused environment. This role will provide practical information security guidance to business leaders, operational teams and technology colleagues, helping to protect sensitive patient, client, employee and business information while enabling effective service delivery. You will act as a trusted adviser, translating security requirements into clear, proportionate and achievable actions. Your responsibilities will include maintaining and improving information security policies, standards, procedures and controls; supporting risk assessments, business impact assessments and security reviews; and advising on the secure design and...

Learn more

Security Engineer

Added 08/09/2026

We are seeking a skilled Security Engineer to help protect critical systems, applications, networks, and data against evolving cyber threats. In this role, you will design, implement, and maintain effective security controls across cloud and on-premises environments. You will work closely with infrastructure, software development, operations, and compliance teams to identify risks, strengthen security practices, and support the delivery of resilient technology services. Your responsibilities will include monitoring security events, investigating alerts, and coordinating the response to incidents from initial detection through remediation and lessons learned. You will conduct vulnerability assessments, support penetration testing activities, manage security tools, and recommend...

Learn more

Group Head of AI Security Architecture

Added 01/09/2026

We are seeking an experienced Group Head of AI Security Architecture to define and lead the security architecture strategy for artificial intelligence, machine learning and generative AI capabilities across a complex, highly regulated environment. This senior role will establish secure-by-design principles for AI products, platforms and services, ensuring that innovation is supported by robust risk management, privacy safeguards, resilience and regulatory compliance. You will act as a trusted adviser to technology, data, engineering, product and executive stakeholders, translating emerging AI threats into practical architectural standards and investment priorities. Key responsibilities will include developing and maintaining the enterprise AI security architecture...

Learn more

Information Security Governance, Risk, and Compliance (GRC) Specialist

Added 09/09/2026

An opportunity is available for an Information Security Governance, Risk, and Compliance (GRC) Specialist to support the development, implementation, and continuous improvement of information security governance and risk management practices. The successful candidate will help ensure that security policies, controls, and processes align with business objectives, regulatory obligations, and recognised industry frameworks. This role will work closely with technology, operational, legal, privacy, and business stakeholders to promote a consistent and effective approach to managing information security risk. Key responsibilities will include maintaining information security policies, standards, procedures, and control documentation; coordinating risk assessments and tracking remediation activities; supporting internal and...

Learn more

Information Security Governance, Risk, and Compliance (GRC) Specialist

Added 18/08/2026

We are seeking a dedicated Information Security Governance, Risk, and Compliance (GRC) Specialist to join our team. In this role, you will be responsible for developing and maintaining the organization's information security policies and procedures, ensuring compliance with applicable regulations and standards. You will conduct risk assessments, identify vulnerabilities, and implement effective mitigation strategies to protect sensitive data. Collaborating with cross-functional teams, you will lead initiatives to enhance the organization’s overall security posture and ensure that all security measures align with business objectives. Your expertise will be crucial in conducting regular audits and assessments to evaluate the effectiveness of current...

Learn more

Head of Governance, Risk and Compliance (Information Security)

Added 10/08/2026

We are seeking a dynamic and experienced professional to take on the role of Head of Governance, Risk and Compliance (Information Security). In this leadership position, you will be responsible for developing and implementing a robust governance framework that ensures compliance with relevant laws, regulations, and industry standards. You will lead the organization’s risk management strategy, identifying potential risks and developing mitigation plans to protect sensitive information and maintain operational integrity. Your expertise will guide the creation and enforcement of policies and procedures to enhance the organization’s information security posture. The ideal candidate will possess strong analytical skills and a...

Learn more

Technical Specialist (cyber related), Operational Risk and Resilience, R&CGI Operational Risk and Resilience Team - Insurance Directorate

Added 24/07/2026

We are seeking a highly skilled Technical Specialist with a strong focus on cyber-related issues to join our Operational Risk and Resilience Team within the Insurance Directorate. In this role, you will be responsible for identifying, assessing, and mitigating cyber risks that could impact the organization's operational resilience. You will work closely with cross-functional teams to develop and implement strategies aimed at enhancing the cybersecurity posture and ensuring compliance with relevant regulations and industry standards. Your expertise will be critical in conducting risk assessments, analyzing potential threats, and recommending appropriate risk management solutions. The ideal candidate will have a solid...

Learn more

Delivery Consultant - Security, Risk, and Compliance, Professional Services

Added 18/08/2026

We are seeking a dedicated Delivery Consultant with expertise in Security, Risk, and Compliance within the realm of Professional Services. In this role, you will be responsible for leading client engagements, delivering tailored solutions, and ensuring that all security and compliance requirements are met. You will collaborate closely with clients to assess their current security posture, identify potential risks, and develop comprehensive strategies that align with regulatory standards and best practices. Your analytical skills will be vital in conducting detailed risk assessments, vulnerability analyses, and compliance audits. The ideal candidate will possess strong communication skills, allowing you to effectively present...

Learn more

InfoSec Governance, Risk and Compliance Analyst

Added 10/08/2026

We are seeking a qualified InfoSec Governance, Risk and Compliance Analyst to join our dynamic team. In this role, you will be responsible for developing, implementing, and maintaining the organization's information security governance framework. You will work closely with various departments to ensure compliance with relevant regulations and standards, while promoting a culture of security awareness throughout the organization. Your expertise will be crucial in identifying and assessing risks, as well as implementing effective strategies to mitigate them. Key responsibilities include conducting regular audits and assessments of information security policies and procedures, ensuring adherence to industry standards such as ISO...

Learn more

Cyber Risk and Compliance Lead (GRC) - Up to £80k

Added 29/07/2026

Are you passionate about cyber risk management and governance? An exciting opportunity has arisen for an experienced Cyber Risk and Compliance Lead (GRC) to join a dynamic team, offering up to £80k for the right candidate. In this pivotal role, you will be responsible for overseeing the development and implementation of the organisation's governance, risk, and compliance framework. You will lead efforts to identify, assess, and mitigate cyber risks, ensuring alignment with regulatory requirements and industry best practices. Your expertise will be crucial in conducting risk assessments, managing compliance audits, and supporting the implementation of security controls across the business....

Learn more

Information Systems and Security Compliance Manager

Added 05/08/2026

An exciting opportunity has arisen for a talented Information Systems and Security Compliance Manager to join a dynamic team focused on maintaining robust security and compliance practices. The successful candidate will be responsible for overseeing the development, implementation, and management of information security policies, standards, and procedures, ensuring strict adherence to relevant regulatory and industry requirements. This role requires close collaboration with IT, legal, and business units to identify compliance gaps, assess risks, and implement effective controls to protect sensitive data and critical systems. Key duties include conducting regular security assessments and audits, managing risk management frameworks, and coordinating responses...

Learn more

Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC)

Added 18/09/2026

We are seeking a Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) to lead the development and continuous improvement of a mature cybersecurity governance and risk management framework. This role will provide strategic direction, independent challenge and practical guidance to ensure security controls, policies and processes align with business objectives, regulatory obligations and recognised industry standards. The successful candidate will work closely with technology, risk, legal, audit and operational teams to strengthen cyber resilience across the organisation. Key responsibilities include owning and maintaining cybersecurity policies, standards, procedures and control frameworks; overseeing enterprise cyber risk assessments, risk registers, remediation plans and...

Learn more

Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC)

Added 04/08/2026

We are seeking a seasoned professional to join our team as a Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC). In this role, you will be responsible for developing, implementing, and maintaining an effective cybersecurity governance framework. Your primary duties will include overseeing risk assessments, compliance audits, and policy development to ensure alignment with industry standards and regulations. You will collaborate with various departments to identify and mitigate potential risks, ensuring that the organization remains compliant with all relevant laws and best practices. Additionally, you will lead a team of cybersecurity professionals, providing guidance and support in the execution of...

Learn more

Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC)

Added 03/08/2026

We are seeking a highly skilled Senior Manager of Cybersecurity Governance, Risk & Compliance (GRC) to join our team. In this pivotal role, you will lead efforts to establish, implement, and manage our cybersecurity governance framework. You will be responsible for developing and maintaining policies, procedures, and standards to ensure compliance with applicable regulations and frameworks. Collaborating with cross-functional teams, you will assess risks, recommend mitigation strategies, and ensure that all cybersecurity initiatives align with business objectives. Your duties will include conducting regular risk assessments, audits, and compliance reviews to identify vulnerabilities and recommend necessary improvements. You will also oversee...

Learn more

Risk Manager - Tech & Cyber Risk

Added 22/07/2026

We are seeking a skilled Risk Manager specializing in Tech & Cyber Risk to join our dynamic team. In this role, you will be responsible for identifying, assessing, and mitigating risks associated with technology and cybersecurity within the organization. You will develop and implement risk management strategies to safeguard sensitive data and maintain compliance with industry regulations. Collaborating closely with IT, legal, and operational teams, you will conduct thorough risk assessments, create risk reports, and present findings to senior management while ensuring that risk policies are upheld and communicated effectively across the organization. To excel in this role, you will...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.