Quick Overview
Job Description
GRC/Cyber Compliance Lead
Remote - 1 day a month in either London or Manchester (fully expensed)
Competitive Salary & 20% Bonus & car allowance & private health
We're looking for an experienced GRC/Cyber Compliance Lead to join a growing Group Security function and build a new Governance, Risk and Compliance capability from the ground up.
This is an opportunity to take genuine ownership. Rather than stepping into an established GRC function and simply maintaining existing processes, you'll be responsible for defining how GRC operates across the organisation - establishing the controls framework, developing meaningful security metrics and risk reporting, strengthening compliance and assurance, and giving senior leadership and the Board a clear view of the organisation's security posture.
The role
Reporting to the Head of Cyber Security, Compliance and Risk Management, you will lead the development and ongoing operation of the Group's cyber GRC capability across multiple divisions, locations and business functions.
You'll build the foundations of a mature GRC function, including:
- Designing and owning the Group's security controls framework and control library
- Developing cyber risk methodology, risk assessment and treatment processes
- Establishing meaningful KRIs, KPIs and security posture reporting for senior leadership and Board-level audiences
- Developing governance processes around security policies, standards, exceptions, waivers and control ownership
- Working with stakeholders across the business to improve control maturity and manage security risks
- Leading the organisation's compliance and certification activities, including Cyber Essentials and Cyber Essentials Plus
- Supporting the longer-term development towards ISO 27001
- Managing relationships with internal and external auditors, certification bodies and independent assurance partners
- Establishing robust control testing, evidence management and audit-readiness processes
- Providing governance oversight of activities such as phishing testing and security awareness
- Developing practical, pre-approved security responses and evidence that can be used by commercial and sales teams during tenders and bids
- Providing security governance and assurance around key suppliers and third parties
- Translating complex security and compliance issues into clear business risks, recommendations and actions
- Challenging existing ways of working and driving pragmatic improvements across the organisation
This is a role where you'll need to be comfortable operating at both strategic and detailed levels - able to discuss security posture and risk with senior leadership while also getting into the detail of controls, evidence and remediation when required.
About you
We're looking for someone with proven cyber/information security GRC experience who can demonstrate what a good GRC function looks like and importantly, has experience of building or significantly improving one.
You are likely to have experience across:
- Cyber security/information security governance, risk and compliance
- Designing or implementing security controls frameworks
- Cyber and information security risk management
- Security metrics, KRIs/KPIs and executive reporting
- Internal and external audit and assurance
- Control testing and evidence management
- Cyber security policies, standards and governance frameworks
- Cyber Essentials/Cyber Essentials Plus
- ISO 27001/ISMS, ideally including hands-on implementation or certification experience
- NIST or other recognised security frameworks
- Third-party/supplier security assurance
- Security questionnaires, customer assurance or tender/RFP responses
What matters most is your ability to understand security risk, establish effective governance and make things happen.
We're looking for someone with the attitude and curiosity to build something, rather than someone who wants to work within a tightly defined specialist remit.
You'll need to be:
- Pragmatic - able to deliver what is needed now while keeping sight of the longer-term direction
- Curious and willing to challenge established thinking
- Comfortable working with ambiguity and building structure where little currently exists
- Commercially minded, understanding how good security can enable rather than restrict the business
- Comfortable influencing senior stakeholders without relying on formal authority
- Collaborative and willing to work across organisational boundaries
- Confident enough to challenge the status quo and find practical solutions
- Able to communicate complex security and risk matters clearly to both technical and non-technical audiences
The organisation is deliberately building its security capability over the next few years, so this role offers significant scope to develop and grow. As the function matures, there is the potential for the role to develop into a broader leadership position with a team underneath it.
You'll be joining at a genuinely interesting point in the organisation's security journey. The foundations are being established, but there is still significant opportunity to shape the future operating model.
Your work will directly influence how the organisation understands and manages cyber risk, how security is reported to the Board, how confidently it can demonstrate its security posture to customers, and ultimately how security can become an enabler of new commercial opportunities.
Candidates will need to be Security Clearable.
If you're an experienced cyber GRC professional who enjoys building, improving and challenging rather than simply maintaining, this is an opportunity to make a significant impact.
Similar jobs
- WI
Sr. Manager, Security Engineering
NewWiz, Inc.
Remote - United Kingdom🇬🇧Remote4 hours agoGCPShellAWS+10 - CA
Director of Mobile and Web Platform
NewCareers at Tide
United Kingdom🇬🇧Hybrid4 hours agoFirebaseMySQLSpring+14 - VA
Programme Manager
NewValtech
London🇬🇧Hybrid4 hours agoSAFeScrumAgile+5 - NA
Sr. Product Engineer
NewNavan
London🇬🇧Hybrid8 hours agoMicroservicesNode.jsAngular+4 - SE
Partner Development Manager, MSSP Ecosystem
NewSentinelOne
United Kingdom🇬🇧Hybrid3 hours agoAccount ManagementCustomer SuccessEnterprise Sales+2 - SE
MSSP Partner Development Manager
NewSentinelOne
United Kingdom🇬🇧Hybrid4 hours agoEnterprise SalesForecastingOnboarding+2