Principal IT Security Manager (GRC)

Reference: 2qonn24f0q0ug1wcnyux

We are seeking a Principal IT Security Manager (GRC) to lead the development, implementation and continuous improvement of an enterprise-wide governance, risk and compliance framework. This senior role will provide strategic direction on information security risk management, regulatory compliance, policies, standards and control effectiveness across technology and business environments. You will act as a trusted adviser to senior stakeholders, translating complex security and regulatory requirements into practical, risk-based solutions that support business objectives.

Key responsibilities include owning the information security risk management lifecycle, including risk identification, assessment, treatment, acceptance and reporting. You will oversee the design, review and maintenance of security policies, procedures and control frameworks, and coordinate internal and external audits, regulatory reviews and assurance activities. The role will also involve managing security exceptions, tracking remediation plans, preparing executive-level risk reporting and advising on security requirements for projects, suppliers, cloud services and technology changes. You will help strengthen governance through metrics, maturity assessments, continuous control monitoring and security awareness initiatives, while supporting the development of a high-performing GRC capability.

The successful candidate will bring significant experience in information security governance, risk and compliance, ideally within a complex, regulated or multinational environment. You will have strong knowledge of recognised frameworks and standards such as ISO 27001, NIST, COBIT, SOC 2 and applicable data protection or industry regulations. Professional certifications such as CISSP, CISM, CRISC, CISA or ISO 27001 Lead Implementer/Auditor are desirable. Excellent stakeholder management, communication and influencing skills are essential, together with the ability to engage confidently with technical teams, auditors, risk functions and executive leadership. A pragmatic, analytical and collaborative approach, combined with strong judgement and the ability to manage competing priorities, will be key to success.

£65,474.00
Per annum
Added 15/09/2026
Reference: 2qonn24f0q0ug1wcnyux

Other similar jobs

Security Operations & GRC Manager

Added 18/08/2026

We are seeking a skilled and motivated Security Operations & GRC Manager to oversee and enhance our organization’s security posture and governance, risk management, and compliance (GRC) framework. In this pivotal role, you will be responsible for developing, implementing, and maintaining security operations processes while ensuring adherence to industry standards and regulatory requirements. You will lead a team of security professionals, collaborating with cross-functional departments to identify vulnerabilities, assess risks, and establish robust security measures that protect our assets and data. Your primary responsibilities will include conducting security assessments, managing incident response activities, and developing comprehensive security policies and procedures....

Learn more

Information Security Manager/GRC Consultant - Telecoms

Added 05/08/2026

We are seeking an experienced Information Security Manager/GRC Consultant with a focus on the telecoms sector to oversee and enhance our information security framework. In this role, you will be responsible for developing, implementing, and maintaining a comprehensive Governance, Risk management, and Compliance (GRC) strategy that aligns with industry best practices and regulatory requirements. You will lead risk assessments, manage security audits, and ensure adherence to applicable laws and standards while also providing guidance on security policies and procedures to safeguard sensitive information. The ideal candidate will have a strong background in information security management, with expertise in telecoms-specific challenges...

Learn more

Security Operations & GRC Manager

Added 05/08/2026

We are seeking a highly skilled and motivated Security Operations & GRC Manager to oversee our security operations and governance, risk, and compliance (GRC) initiatives. The ideal candidate will be responsible for developing, implementing, and maintaining security policies, procedures, and controls to protect sensitive information and ensure compliance with industry regulations. You will lead a team of security professionals, coordinate incident response efforts, and manage all aspects of security operations to mitigate risks effectively. Additionally, you will conduct regular audits and assessments to evaluate the effectiveness of existing security measures, providing recommendations for continuous improvement. In this role, you will...

Learn more

Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC)

Added 18/09/2026

We are seeking a Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) to lead the development and continuous improvement of a mature cybersecurity governance and risk management framework. This role will provide strategic direction, independent challenge and practical guidance to ensure security controls, policies and processes align with business objectives, regulatory obligations and recognised industry standards. The successful candidate will work closely with technology, risk, legal, audit and operational teams to strengthen cyber resilience across the organisation. Key responsibilities include owning and maintaining cybersecurity policies, standards, procedures and control frameworks; overseeing enterprise cyber risk assessments, risk registers, remediation plans and...

Learn more

Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC)

Added 04/08/2026

We are seeking a seasoned professional to join our team as a Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC). In this role, you will be responsible for developing, implementing, and maintaining an effective cybersecurity governance framework. Your primary duties will include overseeing risk assessments, compliance audits, and policy development to ensure alignment with industry standards and regulations. You will collaborate with various departments to identify and mitigate potential risks, ensuring that the organization remains compliant with all relevant laws and best practices. Additionally, you will lead a team of cybersecurity professionals, providing guidance and support in the execution of...

Learn more

Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC)

Added 03/08/2026

We are seeking a highly skilled Senior Manager of Cybersecurity Governance, Risk & Compliance (GRC) to join our team. In this pivotal role, you will lead efforts to establish, implement, and manage our cybersecurity governance framework. You will be responsible for developing and maintaining policies, procedures, and standards to ensure compliance with applicable regulations and frameworks. Collaborating with cross-functional teams, you will assess risks, recommend mitigation strategies, and ensure that all cybersecurity initiatives align with business objectives. Your duties will include conducting regular risk assessments, audits, and compliance reviews to identify vulnerabilities and recommend necessary improvements. You will also oversee...

Learn more

Information Security & GRC Specialist

Added 17/09/2026

We are seeking an Information Security & GRC Specialist to support the development, implementation and continuous improvement of information security governance, risk and compliance activities. The role will help protect business information and technology assets by translating security requirements into practical policies, processes and controls. You will work with stakeholders across technology, operations, legal, privacy and business functions to promote a strong security culture and ensure that risks are identified, assessed and managed effectively. Key responsibilities include maintaining information security policies, standards and procedures; coordinating risk assessments, control reviews and remediation plans; supporting internal and external audits; and monitoring compliance...

Learn more

Senior Cyber Security Governance, Risk & Compliance (GRC) Engineer

Added 17/09/2026

We are seeking a Senior Cyber Security Governance, Risk & Compliance (GRC) Engineer to strengthen enterprise-wide security governance and support the continuous improvement of cyber risk management practices. This role will provide expert guidance across security frameworks, policies, controls and assurance activities, helping to ensure that technology, business processes and third-party services meet regulatory, contractual and organisational requirements. Key responsibilities include developing, maintaining and reviewing information security policies, standards and procedures; conducting risk assessments and control reviews; supporting audit and compliance programmes; and tracking remediation activities through to completion. You will coordinate evidence gathering, prepare clear reports for senior stakeholders,...

Learn more

Security GRC Analyst

Added 14/09/2026

We are seeking a Security GRC Analyst to support the development, implementation and continuous improvement of governance, risk and compliance practices across the organisation. In this role, you will help ensure that information security policies, processes and controls align with business objectives, regulatory requirements and recognised industry standards. You will work closely with security, technology, legal, privacy, audit and operational teams to promote effective risk management and a strong culture of security awareness. Your responsibilities will include maintaining security policies, standards, procedures and control frameworks; coordinating risk assessments and documenting findings, treatment plans and remediation activities; supporting internal and external...

Learn more

Sr. Security Engineer - GRC Fintech & Financial Services EU/UK

Added 11/09/2026

We are seeking a Senior Security Engineer specialising in Governance, Risk and Compliance (GRC) to support security and resilience across fintech and financial services environments in the UK and EU. This role will help strengthen risk management practices, maintain regulatory readiness and translate security requirements into practical, measurable controls. You will work closely with engineering, technology, legal, privacy, compliance and business teams to promote secure, compliant and resilient operations. Your responsibilities will include leading security and technology risk assessments, identifying control gaps and coordinating remediation plans through to completion. You will develop, review and maintain security policies, standards, procedures and...

Learn more

Information Security Governance, Risk, and Compliance (GRC) Specialist

Added 09/09/2026

An opportunity is available for an Information Security Governance, Risk, and Compliance (GRC) Specialist to support the development, implementation, and continuous improvement of information security governance and risk management practices. The successful candidate will help ensure that security policies, controls, and processes align with business objectives, regulatory obligations, and recognised industry frameworks. This role will work closely with technology, operational, legal, privacy, and business stakeholders to promote a consistent and effective approach to managing information security risk. Key responsibilities will include maintaining information security policies, standards, procedures, and control documentation; coordinating risk assessments and tracking remediation activities; supporting internal and...

Learn more

Information Security GRC Lead

Added 08/09/2026

We are seeking an experienced Information Security GRC Lead to strengthen and mature governance, risk and compliance activities across the organisation. In this role, you will lead the development, implementation and continuous improvement of information security policies, standards, procedures and control frameworks. You will work closely with technology, legal, privacy, risk, audit and business stakeholders to ensure that security requirements are clearly defined, consistently applied and aligned with business objectives and regulatory obligations. Your responsibilities will include maintaining the information security risk management programme, coordinating risk assessments, documenting remediation plans and monitoring progress against agreed actions. You will lead internal...

Learn more

Information Security GRC Analyst

Added 03/09/2026

We are seeking an Information Security GRC Analyst to support the development, maintenance, and continuous improvement of information security governance, risk, and compliance activities. This role will help ensure that security policies, processes, and controls remain aligned with business objectives, regulatory obligations, and recognised industry standards. The successful candidate will work closely with technology, risk, legal, privacy, and operational teams to promote a consistent and effective approach to managing information security risk. Key responsibilities include maintaining security policies, standards, procedures, and control frameworks; coordinating risk assessments, control reviews, and remediation activities; and supporting internal and external audits. You will collect...

Learn more

Information Security GRC Analyst

Added 03/09/2026

We are seeking an Information Security GRC Analyst to support the development, implementation and continuous improvement of governance, risk and compliance activities. This role will help ensure that information security policies, standards and controls are aligned with business objectives, regulatory obligations and recognised industry frameworks. You will work closely with technology, privacy, legal, procurement and operational teams to promote a consistent and effective approach to managing information security risk. Key responsibilities include maintaining information security policies, procedures, standards and control documentation; supporting risk assessments, control testing and remediation tracking; coordinating internal and external audit activities; and preparing clear reports for...

Learn more

Junior Information Security Analyst (GRC) - Engine by Starling

Added 02/09/2026

We are seeking a Junior Information Security Analyst to support governance, risk and compliance activities within a growing technology environment. This is an excellent opportunity for someone early in their information security career who is keen to develop practical experience across security controls, risk management, regulatory requirements and assurance. You will work closely with colleagues across technology, operations and the wider business to help maintain a strong security posture and promote effective risk management. Your responsibilities will include supporting the maintenance of information security policies, standards and procedures; assisting with risk assessments, control reviews and evidence collection; and helping to...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.