Information Security GRC Lead

Reference: jop7x8x9powpehxu7w89

We are seeking an experienced Information Security GRC Lead to strengthen governance, risk management and compliance capabilities across a complex technology and business environment. This role will provide strategic direction while remaining closely involved in the delivery of practical security initiatives, ensuring that information security risks are identified, assessed and managed in line with business priorities and regulatory expectations.

Key responsibilities will include developing and maintaining information security policies, standards and control frameworks; coordinating enterprise-wide risk assessments; managing risk treatment plans and tracking remediation activities; and preparing clear reporting for senior leadership and relevant governance forums. You will lead internal and external audit activity, support regulatory and client assurance requests, and oversee the collection of evidence for compliance assessments. The role will also contribute to third-party risk management, business continuity and resilience activities, security awareness programmes, and the continuous improvement of governance processes. You will work collaboratively with technology, legal, privacy, procurement and operational teams to embed effective controls without creating unnecessary barriers to delivery.

The successful candidate will have substantial experience in information security governance, risk and compliance, with a strong understanding of recognised frameworks and standards such as ISO 27001, NIST, COBIT or equivalent. Experience leading audits, control assessments, risk reporting and remediation programmes is essential, ideally within a regulated or highly complex organisation. Professional qualifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer or Lead Auditor are desirable. You will combine sound technical knowledge with excellent communication, stakeholder management and influencing skills, and be confident presenting complex risks to both technical and executive audiences. A proactive, analytical and pragmatic approach is essential, together with the ability to manage multiple priorities and deliver measurable improvements in security maturity.

£50,000.00 - £60,000.00
Per annum
Added 21/09/2026
Reference: jop7x8x9powpehxu7w89

Other similar jobs

Information Security GRC Lead

Added 08/09/2026

We are seeking an experienced Information Security GRC Lead to strengthen and mature governance, risk and compliance activities across the organisation. In this role, you will lead the development, implementation and continuous improvement of information security policies, standards, procedures and control frameworks. You will work closely with technology, legal, privacy, risk, audit and business stakeholders to ensure that security requirements are clearly defined, consistently applied and aligned with business objectives and regulatory obligations. Your responsibilities will include maintaining the information security risk management programme, coordinating risk assessments, documenting remediation plans and monitoring progress against agreed actions. You will lead internal...

Learn more

Information Security GRC Lead

Added 04/08/2026

We are seeking an experienced Information Security GRC Lead to join our dynamic team. In this role, you will be responsible for developing, implementing, and managing the Governance, Risk, and Compliance (GRC) framework to ensure the organization meets its security and regulatory requirements. You will work closely with various departments to identify risks, establish security policies, and ensure compliance with industry standards and regulations. Your expertise will be critical in conducting risk assessments, audits, and continuous monitoring of the organization's security posture. The ideal candidate will possess a deep understanding of information security principles, risk management, and compliance mandates. You...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic direction and hands-on leadership across governance, risk and compliance activities. In this role, you will advise senior stakeholders on cybersecurity risk, regulatory obligations and control effectiveness, while helping to strengthen security governance and embed sustainable risk management practices across the organisation. You will lead complex engagements from assessment through to remediation, ensuring that security objectives are aligned with business priorities. Key responsibilities will include developing and maintaining cybersecurity policies, standards, frameworks and control libraries; conducting risk assessments, control reviews, maturity assessments and compliance gap analyses; and preparing clear...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance initiatives. In this role, you will help strengthen the organisation’s security posture by developing and maintaining cybersecurity policies, standards, procedures and control frameworks aligned with recognised industry practices and regulatory requirements. You will work closely with technology, risk, legal, audit and business stakeholders to translate security objectives into practical, measurable and sustainable outcomes. Your responsibilities will include leading cybersecurity risk assessments, control evaluations, compliance reviews and third-party risk assessments; identifying gaps; and recommending prioritised remediation plans. You will coordinate evidence collection and...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking a Lead Cybersecurity GRC Consultant to provide strategic leadership across governance, risk, and compliance initiatives. This role will help strengthen the organisation’s cybersecurity posture by translating business objectives, regulatory obligations, and industry standards into practical security policies, controls, and improvement programmes. You will work closely with technology, risk, legal, audit, privacy, and business stakeholders to promote a consistent, risk-based approach to information security. Key responsibilities include leading cybersecurity risk assessments, control reviews, maturity assessments, and remediation planning; maintaining and improving security governance frameworks; and supporting compliance with applicable regulations, contractual requirements, and recognised standards such as ISO...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance activities. In this role, you will lead the development, implementation and continuous improvement of cybersecurity policies, standards, procedures and control frameworks. You will work closely with technology, security, legal, privacy, audit and business stakeholders to ensure that security risks are identified, assessed and managed in line with organisational objectives and regulatory expectations. Key responsibilities include leading enterprise security risk assessments, maintaining risk registers and treatment plans, and advising on appropriate mitigation strategies. You will coordinate internal and external audits, support regulatory and...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking a Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance activities. In this role, you will lead the development, implementation and continuous improvement of cybersecurity frameworks, policies, standards and control environments. You will work with technology, privacy, legal, internal audit and business stakeholders to identify information security risks, assess their potential impact and ensure that appropriate mitigation plans are defined, owned and tracked. Your responsibilities will include leading risk assessments, control reviews, compliance readiness activities and third-party security assessments. You will map regulatory and industry requirements to internal controls, support audit preparation and...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking a Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance initiatives. This role will lead the development, implementation and continuous improvement of cybersecurity frameworks, policies, standards and controls aligned with recognised industry practices and applicable regulatory requirements. You will work closely with technology, privacy, legal, risk and business stakeholders to strengthen security governance and support informed risk-based decision-making. Key responsibilities include managing enterprise security risk assessments, maintaining risk registers and treatment plans, coordinating internal and external audits, and overseeing compliance activities against frameworks such as ISO 27001, NIST, SOC 2 or equivalent standards....

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking a Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance initiatives. In this role, you will lead the development, implementation and continuous improvement of cybersecurity frameworks, policies, standards and procedures aligned with recognised industry practices and regulatory requirements. You will work closely with technology, risk, legal, compliance, audit and business stakeholders to strengthen security governance and embed effective risk management across the organisation. Key responsibilities include leading cybersecurity risk assessments, control reviews, compliance gap analyses and remediation programmes. You will advise on regulatory obligations, customer and third-party assurance requirements, and the design and...

Learn more

Cyber Risk and Compliance Lead (GRC) - Up to £80k

Added 29/07/2026

Are you passionate about cyber risk management and governance? An exciting opportunity has arisen for an experienced Cyber Risk and Compliance Lead (GRC) to join a dynamic team, offering up to £80k for the right candidate. In this pivotal role, you will be responsible for overseeing the development and implementation of the organisation's governance, risk, and compliance framework. You will lead efforts to identify, assess, and mitigate cyber risks, ensuring alignment with regulatory requirements and industry best practices. Your expertise will be crucial in conducting risk assessments, managing compliance audits, and supporting the implementation of security controls across the business....

Learn more

Information Security & GRC Specialist

Added 17/09/2026

We are seeking an Information Security & GRC Specialist to support the development, implementation and continuous improvement of information security governance, risk and compliance activities. The role will help protect business information and technology assets by translating security requirements into practical policies, processes and controls. You will work with stakeholders across technology, operations, legal, privacy and business functions to promote a strong security culture and ensure that risks are identified, assessed and managed effectively. Key responsibilities include maintaining information security policies, standards and procedures; coordinating risk assessments, control reviews and remediation plans; supporting internal and external audits; and monitoring compliance...

Learn more

Information Security Governance, Risk, and Compliance (GRC) Specialist

Added 09/09/2026

An opportunity is available for an Information Security Governance, Risk, and Compliance (GRC) Specialist to support the development, implementation, and continuous improvement of information security governance and risk management practices. The successful candidate will help ensure that security policies, controls, and processes align with business objectives, regulatory obligations, and recognised industry frameworks. This role will work closely with technology, operational, legal, privacy, and business stakeholders to promote a consistent and effective approach to managing information security risk. Key responsibilities will include maintaining information security policies, standards, procedures, and control documentation; coordinating risk assessments and tracking remediation activities; supporting internal and...

Learn more

Information Security GRC Analyst

Added 03/09/2026

We are seeking an Information Security GRC Analyst to support the development, maintenance, and continuous improvement of information security governance, risk, and compliance activities. This role will help ensure that security policies, processes, and controls remain aligned with business objectives, regulatory obligations, and recognised industry standards. The successful candidate will work closely with technology, risk, legal, privacy, and operational teams to promote a consistent and effective approach to managing information security risk. Key responsibilities include maintaining security policies, standards, procedures, and control frameworks; coordinating risk assessments, control reviews, and remediation activities; and supporting internal and external audits. You will collect...

Learn more

Information Security GRC Analyst

Added 03/09/2026

We are seeking an Information Security GRC Analyst to support the development, implementation and continuous improvement of governance, risk and compliance activities. This role will help ensure that information security policies, standards and controls are aligned with business objectives, regulatory obligations and recognised industry frameworks. You will work closely with technology, privacy, legal, procurement and operational teams to promote a consistent and effective approach to managing information security risk. Key responsibilities include maintaining information security policies, procedures, standards and control documentation; supporting risk assessments, control testing and remediation tracking; coordinating internal and external audit activities; and preparing clear reports for...

Learn more

Junior Information Security Analyst (GRC) - Engine by Starling

Added 02/09/2026

We are seeking a motivated Junior Information Security Analyst to support governance, risk and compliance activities across a fast-paced technology environment. This is an excellent opportunity for someone at the start of their information security career who is keen to develop practical experience in risk management, security controls, regulatory requirements and assurance. You will work with colleagues across technology, operations and business teams to help maintain a strong security culture and support the continuous improvement of the organisation’s information security framework. Your responsibilities will include assisting with security risk assessments, control reviews and the maintenance of risk and compliance registers....

Learn more
Required for two factor authentication
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.