We are seeking a Security Program Manager, Exam and Audit to lead the planning, coordination, and continuous improvement... Read more
We are seeking a Security Program Manager, Exam and Audit to lead the planning, coordination, and continuous improvement of security assessment activities across the organisation. This role will manage examination and audit programmes, ensuring that internal controls, policies, procedures, and operational practices are prepared for review and aligned with applicable regulatory, contractual, and industry requirements. You will act as a central point of contact for auditors, examiners, control owners, and senior stakeholders, coordinating evidence collection, interview schedules, responses, and remediation tracking.
Responsibilities include maintaining the security assessment calendar; defining programme milestones, deliverables, and dependencies; assessing audit readiness; and identifying risks or gaps before formal examinations begin. You will oversee the preparation of accurate, complete, and appropriately protected evidence, monitor findings through to closure, and provide clear status reporting to leadership. The role will also involve supporting control testing, coordinating responses to requests, validating corrective action plans, and improving processes, documentation, and tooling used to manage audits and examinations. You will work closely with information security, risk, compliance, legal, privacy, technology, and business teams to promote consistent and sustainable control ownership.
The successful candidate will have experience managing security, technology, compliance, or assurance programmes, preferably in an environment subject to external audits, regulatory examinations, or customer assessments. Knowledge of recognised security and risk frameworks, audit methodologies, control design, and evidence management is required. Strong organisational and project management skills are essential, along with the ability to manage competing priorities, influence stakeholders, and communicate complex issues clearly to both technical and non-technical audiences. Experience with governance, risk, and compliance platforms, audit remediation, and metrics or reporting is desirable. Professional certifications in information security, audit, risk, or project management would be advantageous. You should be detail-oriented, pragmatic, collaborative, and comfortable working independently in a changing environment.
Read lessLondon, England, United KingdomPermanent
We are seeking a Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) to lead the development and continuous... Read more
We are seeking a Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) to lead the development and continuous improvement of a mature cybersecurity governance and risk management framework. This role will provide strategic direction, independent challenge and practical guidance to ensure security controls, policies and processes align with business objectives, regulatory obligations and recognised industry standards. The successful candidate will work closely with technology, risk, legal, audit and operational teams to strengthen cyber resilience across the organisation.
Key responsibilities include owning and maintaining cybersecurity policies, standards, procedures and control frameworks; overseeing enterprise cyber risk assessments, risk registers, remediation plans and risk acceptance processes; and coordinating compliance activities against applicable laws, regulations and frameworks such as ISO 27001, NIST, CIS Controls and relevant privacy requirements. You will lead the preparation for internal and external audits, assessments and regulatory reviews, track findings through to closure, and provide clear reporting on risk exposure, control effectiveness, compliance status and key performance indicators to senior leadership and governance committees. The role will also support third-party risk management, security exception management, control testing and the development of governance processes for emerging technologies and change initiatives.
To succeed, you will bring significant experience in cybersecurity governance, risk and compliance, including leadership responsibility within a complex or highly regulated environment. You should have strong knowledge of security frameworks, regulatory expectations, risk methodologies, audit practices and control design, alongside the ability to translate technical issues into concise business-focused advice. Relevant professional certifications such as CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer or Lead Auditor are desirable. Excellent stakeholder management, communication, analytical and influencing skills are essential, as is the ability to prioritise competing demands, lead improvement programmes and operate confidently with senior executives. A proactive, pragmatic and collaborative approach will be highly valued.
Read lessLeatherhead, England, United KingdomPermanent
We are seeking an Information Security & GRC Specialist to support the development, implementation and continuous improvement of... Read more
We are seeking an Information Security & GRC Specialist to support the development, implementation and continuous improvement of information security governance, risk and compliance activities. The role will help protect business information and technology assets by translating security requirements into practical policies, processes and controls. You will work with stakeholders across technology, operations, legal, privacy and business functions to promote a strong security culture and ensure that risks are identified, assessed and managed effectively.
Key responsibilities include maintaining information security policies, standards and procedures; coordinating risk assessments, control reviews and remediation plans; supporting internal and external audits; and monitoring compliance with applicable laws, regulations, contractual obligations and recognised security frameworks. You will maintain risk registers, prepare management reports and metrics, track security exceptions, and assist with third-party and supplier security assessments. The role will also contribute to incident response governance, business continuity and resilience activities, security awareness initiatives, and the ongoing improvement of governance, risk and compliance tooling and reporting.
The successful candidate will have experience in information security, governance, risk management, compliance or a related discipline, ideally within a complex technology or regulated environment. Familiarity with frameworks such as ISO 27001, NIST Cybersecurity Framework, CIS Controls, COBIT or equivalent is desirable, as is an understanding of privacy, operational resilience and third-party risk requirements. Relevant professional certifications, such as CISM, CRISC, CISSP, ISO 27001 Lead Implementer or Lead Auditor, are advantageous. You should be analytical, organised and confident engaging with stakeholders at all levels, with the ability to communicate complex security matters clearly. Strong report-writing, documentation and project coordination skills are essential, along with a proactive approach, sound judgement and a commitment to confidentiality and continuous improvement.
Read lessManchester, England, United KingdomPermanent
We are seeking a Senior Cyber Security Governance, Risk & Compliance (GRC) Engineer to strengthen enterprise-wide security governance... Read more
We are seeking a Senior Cyber Security Governance, Risk & Compliance (GRC) Engineer to strengthen enterprise-wide security governance and support the continuous improvement of cyber risk management practices. This role will provide expert guidance across security frameworks, policies, controls and assurance activities, helping to ensure that technology, business processes and third-party services meet regulatory, contractual and organisational requirements.
Key responsibilities include developing, maintaining and reviewing information security policies, standards and procedures; conducting risk assessments and control reviews; supporting audit and compliance programmes; and tracking remediation activities through to completion. You will coordinate evidence gathering, prepare clear reports for senior stakeholders, and advise on risk acceptance, treatment plans and control effectiveness. The role will also contribute to security architecture and project reviews, supplier and third-party risk assessments, business continuity activities, incident response governance, and the implementation of improvements aligned with recognised frameworks such as ISO 27001, NIST, CIS Controls or similar.
The successful candidate will have substantial experience in cyber security governance, risk and compliance, with a strong understanding of security controls, regulatory obligations, audit principles and risk management methodologies. Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer or Lead Auditor are desirable. You should be confident engaging with technical and non-technical audiences, able to challenge constructively, and skilled at translating complex security issues into practical business recommendations. Strong analytical, documentation and stakeholder-management skills are essential, along with the ability to prioritise competing demands and work independently in a changing environment. Experience with GRC platforms, cloud security risk, third-party assurance and security metrics would be advantageous.
Read lessHuntingdon, England, United KingdomPermanent
We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic direction and hands-on leadership across governance,... Read more
We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic direction and hands-on leadership across governance, risk and compliance activities. In this role, you will advise senior stakeholders on cybersecurity risk, regulatory obligations and control effectiveness, while helping to strengthen security governance and embed sustainable risk management practices across the organisation. You will lead complex engagements from assessment through to remediation, ensuring that security objectives are aligned with business priorities.
Key responsibilities will include developing and maintaining cybersecurity policies, standards, frameworks and control libraries; conducting risk assessments, control reviews, maturity assessments and compliance gap analyses; and preparing clear reports, risk registers and remediation plans for executive and audit audiences. You will coordinate internal and external audits, support regulatory and client assurance activities, and monitor the timely resolution of findings. The role will also involve mapping controls to recognised frameworks and regulations such as ISO 27001, NIST CSF, SOC 2, PCI DSS and applicable privacy requirements. You will lead workshops, mentor colleagues and collaborate closely with technology, privacy, legal, procurement, internal audit and business teams.
The successful candidate will have substantial experience in cybersecurity governance, risk and compliance, ideally gained in a consulting, advisory or enterprise environment. You will bring strong knowledge of information security frameworks, risk methodologies, audit processes and regulatory expectations, together with the ability to translate technical issues into practical business recommendations. Relevant certifications such as CISSP, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer or Lead Auditor are desirable. Excellent communication, stakeholder management, analytical and report-writing skills are essential, as is the confidence to influence at senior levels and manage multiple priorities. A proactive, collaborative approach and a commitment to continuous improvement will be highly valued.
Read lessLondon, England, United KingdomPermanent
We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance... Read more
We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance initiatives. In this role, you will help strengthen the organisation’s security posture by developing and maintaining cybersecurity policies, standards, procedures and control frameworks aligned with recognised industry practices and regulatory requirements. You will work closely with technology, risk, legal, audit and business stakeholders to translate security objectives into practical, measurable and sustainable outcomes.
Your responsibilities will include leading cybersecurity risk assessments, control evaluations, compliance reviews and third-party risk assessments; identifying gaps; and recommending prioritised remediation plans. You will coordinate evidence collection and responses for internal and external audits, track control effectiveness and provide clear reporting to senior leadership. The role will also involve supporting regulatory and customer assurance activities, maintaining risk registers, advising on security requirements for projects and suppliers, and contributing to the continuous improvement of governance processes. You will mentor consultants and colleagues, promote a strong culture of accountability, and lead workshops to improve awareness of cybersecurity risk and control ownership.
To be successful, you will have substantial experience in cybersecurity governance, risk and compliance, with a strong understanding of frameworks such as ISO 27001, NIST CSF, COBIT or similar. Experience with regulatory obligations, privacy principles, security control testing, audit management and third-party risk is highly desirable. Professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer or Lead Auditor are advantageous. You will bring excellent analytical, communication and stakeholder management skills, with the ability to present complex information clearly to both technical and non-technical audiences. A proactive, collaborative approach, strong attention to detail and the confidence to influence at all levels are essential.
Read lessLeeds, England, United KingdomPermanent
We are seeking a Lead Cybersecurity GRC Consultant to provide strategic leadership across governance, risk, and compliance initiatives.... Read more
We are seeking a Lead Cybersecurity GRC Consultant to provide strategic leadership across governance, risk, and compliance initiatives. This role will help strengthen the organisation’s cybersecurity posture by translating business objectives, regulatory obligations, and industry standards into practical security policies, controls, and improvement programmes. You will work closely with technology, risk, legal, audit, privacy, and business stakeholders to promote a consistent, risk-based approach to information security.
Key responsibilities include leading cybersecurity risk assessments, control reviews, maturity assessments, and remediation planning; maintaining and improving security governance frameworks; and supporting compliance with applicable regulations, contractual requirements, and recognised standards such as ISO 27001, NIST, CIS, or SOC 2. You will coordinate internal and external audits, manage evidence collection, track findings and corrective actions, and prepare clear reports for senior leadership and risk committees. The role will also contribute to third-party risk management, policy development, security exception processes, metrics and dashboards, business continuity activities, and the ongoing enhancement of the cybersecurity control environment.
The successful candidate will have substantial experience in cybersecurity governance, risk, and compliance, ideally gained in a complex or regulated environment. You will be confident interpreting regulatory and assurance requirements, assessing control effectiveness, and communicating risk clearly to both technical and non-technical audiences. Strong stakeholder management, consulting, analytical, and written communication skills are essential, along with the ability to lead initiatives, influence decision-making, and manage competing priorities. Relevant professional certifications such as CISSP, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer or Auditor, or equivalent experience are desirable. A pragmatic, collaborative approach and a commitment to continuous improvement will be important for success in this position.
Read lessPeterborough, England, United KingdomPermanent
We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance... Read more
We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance activities. In this role, you will lead the development, implementation and continuous improvement of cybersecurity policies, standards, procedures and control frameworks. You will work closely with technology, security, legal, privacy, audit and business stakeholders to ensure that security risks are identified, assessed and managed in line with organisational objectives and regulatory expectations.
Key responsibilities include leading enterprise security risk assessments, maintaining risk registers and treatment plans, and advising on appropriate mitigation strategies. You will coordinate internal and external audits, support regulatory and client assurance activities, and oversee the collection and validation of evidence for compliance reviews. The role will also involve mapping controls to recognised frameworks and standards such as ISO 27001, NIST, SOC 2 and relevant data protection requirements. You will prepare clear reports for senior leadership, communicate complex risk matters to non-technical audiences, and mentor colleagues involved in cybersecurity governance and assurance. You may also contribute to third-party risk management, security assessments for new initiatives, metrics development and the continuous improvement of GRC processes and tooling.
The successful candidate will have significant experience in cybersecurity governance, risk management, compliance, audit or assurance, ideally within a complex or regulated environment. Strong knowledge of security frameworks, control design, risk methodologies and regulatory obligations is essential, together with practical experience managing audits and stakeholder relationships. Professional certifications such as CISA, CISM, CRISC, CISSP, ISO 27001 Lead Implementer or Lead Auditor are desirable. You will be confident working independently, managing competing priorities and influencing stakeholders at all levels. Excellent written and verbal communication skills, sound judgement, attention to detail and the ability to translate technical issues into clear business risks are required.
Read lessReading, England, United KingdomPermanent
We are seeking a Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance activities.... Read more
We are seeking a Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance activities. In this role, you will lead the development, implementation and continuous improvement of cybersecurity frameworks, policies, standards and control environments. You will work with technology, privacy, legal, internal audit and business stakeholders to identify information security risks, assess their potential impact and ensure that appropriate mitigation plans are defined, owned and tracked.
Your responsibilities will include leading risk assessments, control reviews, compliance readiness activities and third-party security assessments. You will map regulatory and industry requirements to internal controls, support audit preparation and remediation, and produce clear reports for senior leadership and risk committees. You will also oversee governance processes, including risk acceptance, policy exceptions, security metrics, control testing and issue management. The role will involve mentoring other GRC professionals, improving processes and promoting a risk-aware culture across the organisation. You may also contribute to security strategy, incident lessons learned, business resilience and the development of security awareness initiatives.
The successful candidate will have substantial experience in cybersecurity governance, risk and compliance, with a strong understanding of frameworks such as NIST CSF, ISO 27001, COBIT, CIS Controls or equivalent. Experience interpreting regulations and contractual requirements, conducting risk and control assessments, and engaging with auditors and senior stakeholders is essential. Professional certifications such as CISSP, CISM, CRISC, CISA or ISO 27001 Lead Implementer/Auditor are highly desirable. You should be confident communicating complex security matters to both technical and non-technical audiences, able to influence at all levels and skilled at managing multiple priorities in a changing environment. Strong analytical, writing and stakeholder-management skills are required, along with a practical, collaborative approach to cybersecurity risk.
Read lessBirmingham, England, United KingdomPermanent
We are seeking a Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance initiatives.... Read more
We are seeking a Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance initiatives. In this role, you will lead the development, implementation and continuous improvement of cybersecurity frameworks, policies, standards and procedures aligned with recognised industry practices and regulatory requirements. You will work closely with technology, risk, legal, compliance, audit and business stakeholders to strengthen security governance and embed effective risk management across the organisation.
Key responsibilities include leading cybersecurity risk assessments, control reviews, compliance gap analyses and remediation programmes. You will advise on regulatory obligations, customer and third-party assurance requirements, and the design and operation of security controls. The role will also involve coordinating internal and external audits, preparing risk and compliance reports for senior leadership, tracking remediation activities, and maintaining accurate governance documentation. You will contribute to security strategy and roadmap development, support policy awareness initiatives, and mentor colleagues while promoting a practical, risk-based approach to cybersecurity.
The successful candidate will have substantial experience in cybersecurity governance, risk and compliance, ideally within a complex or regulated environment. You should have strong knowledge of frameworks and standards such as ISO 27001, NIST Cybersecurity Framework, COBIT, SOC 2 or equivalent, together with an understanding of privacy, regulatory and third-party risk requirements. Professional certifications such as CISM, CISSP, CRISC, ISO 27001 Lead Implementer or Lead Auditor are desirable. Excellent communication, stakeholder management, analytical and report-writing skills are essential, along with the ability to translate technical risks into clear business impacts and practical recommendations. Experience leading projects, influencing senior stakeholders and managing competing priorities will be highly valued.
Read lessManchester, England, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria