Information Security GRC Lead

Reference: blndbwf7mpl7hu9w3pkh

We are seeking an experienced Information Security GRC Lead to strengthen and mature governance, risk and compliance activities across the organisation. In this role, you will lead the development, implementation and continuous improvement of information security policies, standards, procedures and control frameworks. You will work closely with technology, legal, privacy, risk, audit and business stakeholders to ensure that security requirements are clearly defined, consistently applied and aligned with business objectives and regulatory obligations.

Your responsibilities will include maintaining the information security risk management programme, coordinating risk assessments, documenting remediation plans and monitoring progress against agreed actions. You will lead internal and external audit activities, support regulatory and customer assurance requests, and oversee the preparation of evidence for certifications and compliance assessments. You will also manage security control testing, track key risk and compliance metrics, prepare clear reports for senior leadership, and provide practical guidance on emerging regulatory, contractual and information security requirements. Where gaps are identified, you will help teams define proportionate and sustainable corrective actions.

The successful candidate will have substantial experience in information security governance, risk and compliance, ideally within a complex or regulated environment. Strong knowledge of recognised frameworks and standards such as ISO 27001, NIST, COBIT, SOC 2 or PCI DSS is expected, together with experience in audit management, risk assessment and control design. Relevant professional qualifications, such as CISA, CISM, CRISC, CISSP or ISO 27001 Lead Implementer/Auditor, are desirable. You will be a confident communicator who can engage effectively with both technical and non-technical audiences, influence stakeholders at all levels and translate complex requirements into clear, actionable outcomes. A structured, analytical and collaborative approach, combined with sound judgement and a commitment to continuous improvement, is essential.

COMPETITIVE SALARY
Added 08/09/2026
Reference: blndbwf7mpl7hu9w3pkh

Other similar jobs

Information Security GRC Lead

Added 04/08/2026

We are seeking an experienced Information Security GRC Lead to join our dynamic team. In this role, you will be responsible for developing, implementing, and managing the Governance, Risk, and Compliance (GRC) framework to ensure the organization meets its security and regulatory requirements. You will work closely with various departments to identify risks, establish security policies, and ensure compliance with industry standards and regulations. Your expertise will be critical in conducting risk assessments, audits, and continuous monitoring of the organization's security posture. The ideal candidate will possess a deep understanding of information security principles, risk management, and compliance mandates. You...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking a Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance initiatives. This role will lead the development, implementation and continuous improvement of cybersecurity frameworks, policies, standards and controls aligned with recognised industry practices and applicable regulatory requirements. You will work closely with technology, privacy, legal, risk and business stakeholders to strengthen security governance and support informed risk-based decision-making. Key responsibilities include managing enterprise security risk assessments, maintaining risk registers and treatment plans, coordinating internal and external audits, and overseeing compliance activities against frameworks such as ISO 27001, NIST, SOC 2 or equivalent standards....

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking a Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance activities. In this role, you will lead the development, implementation and continuous improvement of cybersecurity frameworks, policies, standards and control environments. You will work with technology, privacy, legal, internal audit and business stakeholders to identify information security risks, assess their potential impact and ensure that appropriate mitigation plans are defined, owned and tracked. Your responsibilities will include leading risk assessments, control reviews, compliance readiness activities and third-party security assessments. You will map regulatory and industry requirements to internal controls, support audit preparation and...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking a Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance initiatives. In this role, you will lead the development, implementation and continuous improvement of cybersecurity frameworks, policies, standards and procedures aligned with recognised industry practices and regulatory requirements. You will work closely with technology, risk, legal, compliance, audit and business stakeholders to strengthen security governance and embed effective risk management across the organisation. Key responsibilities include leading cybersecurity risk assessments, control reviews, compliance gap analyses and remediation programmes. You will advise on regulatory obligations, customer and third-party assurance requirements, and the design and...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance activities. In this role, you will lead the development, implementation and continuous improvement of cybersecurity policies, standards, procedures and control frameworks. You will work closely with technology, security, legal, privacy, audit and business stakeholders to ensure that security risks are identified, assessed and managed in line with organisational objectives and regulatory expectations. Key responsibilities include leading enterprise security risk assessments, maintaining risk registers and treatment plans, and advising on appropriate mitigation strategies. You will coordinate internal and external audits, support regulatory and...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking a Lead Cybersecurity GRC Consultant to provide strategic leadership across governance, risk, and compliance initiatives. This role will help strengthen the organisation’s cybersecurity posture by translating business objectives, regulatory obligations, and industry standards into practical security policies, controls, and improvement programmes. You will work closely with technology, risk, legal, audit, privacy, and business stakeholders to promote a consistent, risk-based approach to information security. Key responsibilities include leading cybersecurity risk assessments, control reviews, maturity assessments, and remediation planning; maintaining and improving security governance frameworks; and supporting compliance with applicable regulations, contractual requirements, and recognised standards such as ISO...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance initiatives. In this role, you will help strengthen the organisation’s security posture by developing and maintaining cybersecurity policies, standards, procedures and control frameworks aligned with recognised industry practices and regulatory requirements. You will work closely with technology, risk, legal, audit and business stakeholders to translate security objectives into practical, measurable and sustainable outcomes. Your responsibilities will include leading cybersecurity risk assessments, control evaluations, compliance reviews and third-party risk assessments; identifying gaps; and recommending prioritised remediation plans. You will coordinate evidence collection and...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic direction and hands-on leadership across governance, risk and compliance activities. In this role, you will advise senior stakeholders on cybersecurity risk, regulatory obligations and control effectiveness, while helping to strengthen security governance and embed sustainable risk management practices across the organisation. You will lead complex engagements from assessment through to remediation, ensuring that security objectives are aligned with business priorities. Key responsibilities will include developing and maintaining cybersecurity policies, standards, frameworks and control libraries; conducting risk assessments, control reviews, maturity assessments and compliance gap analyses; and preparing clear...

Learn more

Cyber Risk and Compliance Lead (GRC) - Up to £80k

Added 29/07/2026

Are you passionate about cyber risk management and governance? An exciting opportunity has arisen for an experienced Cyber Risk and Compliance Lead (GRC) to join a dynamic team, offering up to £80k for the right candidate. In this pivotal role, you will be responsible for overseeing the development and implementation of the organisation's governance, risk, and compliance framework. You will lead efforts to identify, assess, and mitigate cyber risks, ensuring alignment with regulatory requirements and industry best practices. Your expertise will be crucial in conducting risk assessments, managing compliance audits, and supporting the implementation of security controls across the business....

Learn more

Information Security & GRC Specialist

Added 17/09/2026

We are seeking an Information Security & GRC Specialist to support the development, implementation and continuous improvement of information security governance, risk and compliance activities. The role will help protect business information and technology assets by translating security requirements into practical policies, processes and controls. You will work with stakeholders across technology, operations, legal, privacy and business functions to promote a strong security culture and ensure that risks are identified, assessed and managed effectively. Key responsibilities include maintaining information security policies, standards and procedures; coordinating risk assessments, control reviews and remediation plans; supporting internal and external audits; and monitoring compliance...

Learn more

Information Security Governance, Risk, and Compliance (GRC) Specialist

Added 09/09/2026

An opportunity is available for an Information Security Governance, Risk, and Compliance (GRC) Specialist to support the development, implementation, and continuous improvement of information security governance and risk management practices. The successful candidate will help ensure that security policies, controls, and processes align with business objectives, regulatory obligations, and recognised industry frameworks. This role will work closely with technology, operational, legal, privacy, and business stakeholders to promote a consistent and effective approach to managing information security risk. Key responsibilities will include maintaining information security policies, standards, procedures, and control documentation; coordinating risk assessments and tracking remediation activities; supporting internal and...

Learn more

Information Security GRC Analyst

Added 03/09/2026

We are seeking an Information Security GRC Analyst to support the development, implementation and continuous improvement of governance, risk and compliance activities. This role will help ensure that information security policies, standards and controls are aligned with business objectives, regulatory obligations and recognised industry frameworks. You will work closely with technology, privacy, legal, procurement and operational teams to promote a consistent and effective approach to managing information security risk. Key responsibilities include maintaining information security policies, procedures, standards and control documentation; supporting risk assessments, control testing and remediation tracking; coordinating internal and external audit activities; and preparing clear reports for...

Learn more

Information Security GRC Analyst

Added 03/09/2026

We are seeking an Information Security GRC Analyst to support the development, maintenance, and continuous improvement of information security governance, risk, and compliance activities. This role will help ensure that security policies, processes, and controls remain aligned with business objectives, regulatory obligations, and recognised industry standards. The successful candidate will work closely with technology, risk, legal, privacy, and operational teams to promote a consistent and effective approach to managing information security risk. Key responsibilities include maintaining security policies, standards, procedures, and control frameworks; coordinating risk assessments, control reviews, and remediation activities; and supporting internal and external audits. You will collect...

Learn more

Junior Information Security Analyst (GRC) - Engine by Starling

Added 02/09/2026

We are seeking a motivated Junior Information Security Analyst to support governance, risk and compliance activities across a fast-paced technology environment. This is an excellent opportunity for someone at the start of their information security career who is keen to develop practical experience in risk management, security controls, regulatory requirements and assurance. You will work with colleagues across technology, operations and business teams to help maintain a strong security culture and support the continuous improvement of the organisation’s information security framework. Your responsibilities will include assisting with security risk assessments, control reviews and the maintenance of risk and compliance registers....

Learn more

Junior Information Security Analyst (GRC) - Engine by Starling

Added 02/09/2026

We are seeking a Junior Information Security Analyst to support governance, risk and compliance activities within a growing technology environment. This is an excellent opportunity for someone early in their information security career who is keen to develop practical experience across security controls, risk management, regulatory requirements and assurance. You will work closely with colleagues across technology, operations and the wider business to help maintain a strong security posture and promote effective risk management. Your responsibilities will include supporting the maintenance of information security policies, standards and procedures; assisting with risk assessments, control reviews and evidence collection; and helping to...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.