Information Security GRC Lead
We are seeking an experienced Information Security GRC Lead to strengthen and mature governance, risk and compliance activities across the organisation. In this role, you will lead the development, implementation and continuous improvement of information security policies, standards, procedures and control frameworks. You will work closely with technology, legal, privacy, risk, audit and business stakeholders to ensure that security requirements are clearly defined, consistently applied and aligned with business objectives and regulatory obligations.
Your responsibilities will include maintaining the information security risk management programme, coordinating risk assessments, documenting remediation plans and monitoring progress against agreed actions. You will lead internal and external audit activities, support regulatory and customer assurance requests, and oversee the preparation of evidence for certifications and compliance assessments. You will also manage security control testing, track key risk and compliance metrics, prepare clear reports for senior leadership, and provide practical guidance on emerging regulatory, contractual and information security requirements. Where gaps are identified, you will help teams define proportionate and sustainable corrective actions.
The successful candidate will have substantial experience in information security governance, risk and compliance, ideally within a complex or regulated environment. Strong knowledge of recognised frameworks and standards such as ISO 27001, NIST, COBIT, SOC 2 or PCI DSS is expected, together with experience in audit management, risk assessment and control design. Relevant professional qualifications, such as CISA, CISM, CRISC, CISSP or ISO 27001 Lead Implementer/Auditor, are desirable. You will be a confident communicator who can engage effectively with both technical and non-technical audiences, influence stakeholders at all levels and translate complex requirements into clear, actionable outcomes. A structured, analytical and collaborative approach, combined with sound judgement and a commitment to continuous improvement, is essential.
Information Security GRC Lead
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- Security Engineer
- Security Analyst
- Security Architect
- IT Security Manager
- Security Consultant
- SOC Analyst
- Identity Access Management IAM
- Cyber Security Consultant
- Cloud Security
- Application Security
- Incident Response
- Penetration Tester
LATEST JOBS
- Security Engineer (Contractor)
- Vice President, Field CISO Com...
- Microsoft 365 & Security Infra...
- Senior ICT Security Designer
- Data Protection Expert
- Data Protection Officer: Schoo...
- Data Protection Officer
- IT CONSULTANT (IT Management,...
- Technology and Cyber Employee...
- Cyber Security Consultant
- Cyber Security Consultant (Pen...
- Platform and Services Engineer...