Information Security GRC Lead
We are seeking an experienced Information Security GRC Lead to strengthen governance, risk management and compliance capabilities across a complex technology and business environment. This role will provide strategic direction while remaining closely involved in the delivery of practical security initiatives, ensuring that information security risks are identified, assessed and managed in line with business priorities and regulatory expectations.
Key responsibilities will include developing and maintaining information security policies, standards and control frameworks; coordinating enterprise-wide risk assessments; managing risk treatment plans and tracking remediation activities; and preparing clear reporting for senior leadership and relevant governance forums. You will lead internal and external audit activity, support regulatory and client assurance requests, and oversee the collection of evidence for compliance assessments. The role will also contribute to third-party risk management, business continuity and resilience activities, security awareness programmes, and the continuous improvement of governance processes. You will work collaboratively with technology, legal, privacy, procurement and operational teams to embed effective controls without creating unnecessary barriers to delivery.
The successful candidate will have substantial experience in information security governance, risk and compliance, with a strong understanding of recognised frameworks and standards such as ISO 27001, NIST, COBIT or equivalent. Experience leading audits, control assessments, risk reporting and remediation programmes is essential, ideally within a regulated or highly complex organisation. Professional qualifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer or Lead Auditor are desirable. You will combine sound technical knowledge with excellent communication, stakeholder management and influencing skills, and be confident presenting complex risks to both technical and executive audiences. A proactive, analytical and pragmatic approach is essential, together with the ability to manage multiple priorities and deliver measurable improvements in security maturity.
Information Security GRC Lead
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- Security Engineer
- Security Analyst
- Security Architect
- Security Consultant
- IT Security Manager
- SOC Analyst
- Identity Access Management IAM
- Cyber Security Consultant
- Cloud Security
- Application Security
- Incident Response
- Penetration Tester
LATEST JOBS
- Cyber SOC Specialist - ESN
- End User Platform Vulnerabilit...
- Lead Security Engineer
- Member of Technical Staff (Sof...
- Cyber Security Consultant - As...
- Cyber Security Analyst - Enter...
- Technical Leader - Splunk Secu...
- Digital & Cyber Resilience – M...
- Data Protection Engineer
- Security Advisor
- Information Security Engineer
- Test Automation Engineer - Sec...
TOP SEARCHES
LOCATIONS
- Engineer
- Data Scientist
- Senior Data Scientist
- Head of Data Science
- Trainee Data Scientist
- Data Science Graduate
- Senior Financial Accountant
- Management Accountant
- Cost Accountant
- Civil Engineer
- Senior Civil Engineer
- Civil Design Engineer