Information Security Governance, Risk, and Compliance (GRC) Specialist
An opportunity is available for an Information Security Governance, Risk, and Compliance (GRC) Specialist to support the development, implementation, and continuous improvement of information security governance and risk management practices. The successful candidate will help ensure that security policies, controls, and processes align with business objectives, regulatory obligations, and recognised industry frameworks. This role will work closely with technology, operational, legal, privacy, and business stakeholders to promote a consistent and effective approach to managing information security risk.
Key responsibilities will include maintaining information security policies, standards, procedures, and control documentation; coordinating risk assessments and tracking remediation activities; supporting internal and external audits; and preparing clear reports, dashboards, and management information on compliance and risk matters. The role will also contribute to third-party and supplier security assessments, control testing, exception management, and the monitoring of compliance with applicable laws, regulations, contractual requirements, and security frameworks such as ISO 27001, NIST, or equivalent standards. You will help identify opportunities to strengthen governance processes and improve security awareness across the organisation.
Applicants should have experience in information security governance, risk, compliance, audit, or a related discipline, together with a sound understanding of security controls, risk assessment methodologies, and regulatory requirements. Strong analytical, documentation, communication, and stakeholder management skills are essential, as is the ability to manage competing priorities and explain technical or compliance matters to non-technical audiences. Experience with GRC platforms, control frameworks, third-party risk, business continuity, data protection, or audit preparation would be advantageous. Relevant qualifications or certifications, such as CISA, CISM, CRISC, ISO 27001, or equivalent experience, are desirable. The role suits a proactive, detail-focused professional who can work collaboratively while maintaining sound judgement, confidentiality, and a strong commitment to continuous improvement.
Information Security Governance, Risk, and Compliance (GRC) Specialist
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- Security Engineer
- Security Analyst
- Security Architect
- IT Security Manager
- Security Consultant
- SOC Analyst
- Identity Access Management IAM
- Cyber Security Consultant
- Cloud Security
- Application Security
- Incident Response
- Penetration Tester
LATEST JOBS
- Security Engineer (Contractor)
- Vice President, Field CISO Com...
- Microsoft 365 & Security Infra...
- Senior ICT Security Designer
- Data Protection Expert
- Data Protection Officer: Schoo...
- Data Protection Officer
- IT CONSULTANT (IT Management,...
- Technology and Cyber Employee...
- Cyber Security Consultant
- Cyber Security Consultant (Pen...
- Platform and Services Engineer...