Haystack
← Back to Jobs
Temporary/Casual
Administrative
KF

GRC Security Controls SME - Insurance - Outside IR35

Korn FerryLondon🇬🇧United KingdomPosted 1 Sept 2026

Why This Role Stands Out

You'll drive significant impact by leading the design and implementation of enterprise cyber security control frameworks for a major health insurance client, leveraging your extensive GRC expertise. This high-profile role offers a competitive daily rate and is ideal for a seasoned professional with a strong background in security control frameworks and a proven ability to collaborate with diverse stakeholders. Apply now to shape critical security initiatives within a reputable organization.

Quick Overview

Seniority
Mid Senior
Employment type
Temporary/Casual
Work mode
On Site
Location
London, United Kingdom
Stakeholder Management

Job Description

Korn Ferry Project Solutions is supporting a major health insurance client with a strategic cyber security controls and governance initiative and is seeking an experienced Cyber Controls Framework Lead to join the engagement.

You'll lead the design, development and continuous improvement of enterprise cyber security control frameworks and control libraries, working with Cyber Security, Risk, Compliance, Audit, Technology and business stakeholders.

Requirements:

  • 10+ years' experience in Cyber Security, Information Security, Risk or Governance
  • 5+ years' experience designing and implementing security control frameworks
  • Proven experience developing and managing enterprise security control libraries
  • Cyber control framework and control taxonomy development experience
  • Control measurement, effectiveness and maturity assessment experience
  • Control rationalisation and harmonisation experience
  • Strong experience mapping controls to NIST CSF 2.0
  • Experience supporting audits, assurance activities and regulatory reviews
  • Experience working within large, complex and regulated enterprise environments
  • Strong stakeholder management and communication skills
  • Insurance sector experience required; broader financial services experience considered
  • Willingness and ability to travel globally as required

Desirable:

  • NIST SP 800-53 experience
  • ISF Standard of Good Practice experience
  • CISSP, CISM or CRISC certification
  • Experience developing security metrics and control effectiveness measures
  • Experience with control inheritance and framework integration

This is an initial 10-week consultancy engagement, outside IR35, with a competitive daily rate. The role is office-based in London with global travel as required.

Similar jobs