Principal IT Security Manager (GRC)
We are seeking a Principal IT Security Manager (GRC) to lead the development, implementation and continuous improvement of an enterprise-wide governance, risk and compliance framework. This senior role will provide strategic direction on information security risk management, regulatory compliance, policies, standards and control effectiveness across technology and business environments. You will act as a trusted adviser to senior stakeholders, translating complex security and regulatory requirements into practical, risk-based solutions that support business objectives.
Key responsibilities include owning the information security risk management lifecycle, including risk identification, assessment, treatment, acceptance and reporting. You will oversee the design, review and maintenance of security policies, procedures and control frameworks, and coordinate internal and external audits, regulatory reviews and assurance activities. The role will also involve managing security exceptions, tracking remediation plans, preparing executive-level risk reporting and advising on security requirements for projects, suppliers, cloud services and technology changes. You will help strengthen governance through metrics, maturity assessments, continuous control monitoring and security awareness initiatives, while supporting the development of a high-performing GRC capability.
The successful candidate will bring significant experience in information security governance, risk and compliance, ideally within a complex, regulated or multinational environment. You will have strong knowledge of recognised frameworks and standards such as ISO 27001, NIST, COBIT, SOC 2 and applicable data protection or industry regulations. Professional certifications such as CISSP, CISM, CRISC, CISA or ISO 27001 Lead Implementer/Auditor are desirable. Excellent stakeholder management, communication and influencing skills are essential, together with the ability to engage confidently with technical teams, auditors, risk functions and executive leadership. A pragmatic, analytical and collaborative approach, combined with strong judgement and the ability to manage competing priorities, will be key to success.
Principal IT Security Manager (GRC)
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- Security Engineer
- Security Analyst
- Security Architect
- IT Security Manager
- Security Consultant
- SOC Analyst
- Identity Access Management IAM
- Cyber Security Consultant
- Cloud Security
- Application Security
- Incident Response
- Penetration Tester
LATEST JOBS
- Security Engineer (Contractor)
- Vice President, Field CISO Com...
- Microsoft 365 & Security Infra...
- Senior ICT Security Designer
- Data Protection Expert
- Data Protection Officer: Schoo...
- Data Protection Officer
- IT CONSULTANT (IT Management,...
- Technology and Cyber Employee...
- Cyber Security Consultant
- Cyber Security Consultant (Pen...
- Platform and Services Engineer...