CGRC Lead

Elevation Recruitment Group
Leeds, UK
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£45,000.0 - £55,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Microsoft Azure Cloud Computing Security CompTIA Security+ Cyber Security RSA Archer Platform CIS Benchmarks

Job description

This is an exciting opportunity to join a business investing heavily in its cyber security capability. Reporting to the Group Information Security Officer (GISO), you’ll take ownership of cyber governance across the Group, working closely with senior stakeholders to strengthen security, risk and compliance practices., * Maintain and develop the Group cyber risk register.

  • Develop and maintain security policies, standards and governance documentation.
  • Support and improve cyber governance frameworks including NIST CSF, CIS Controls and ISO 27001.
  • Conduct cyber risk assessments across projects, systems and suppliers.
  • Coordinate internal and external audits and compliance activities.
  • Produce cyber risk and assurance reporting for senior leadership.
  • Support third-party security assurance and supplier risk management.
  • Promote cyber security awareness and good governance across the organisation.

Requirements

This role would suit a proactive Cyber GRC professional who enjoys working autonomously, influencing change and building strong relationships across multiple businesses., You’ll have experience in Cyber Governance, Risk & Compliance and be confident working independently within a collaborative environment.

You’ll also bring:

  • Strong knowledge of NIST CSF, CIS Controls and ISO 27001.
  • Experience conducting cyber risk assessments and supporting audits.
  • The ability to develop policies, standards and governance documentation.
  • Excellent communication skills, with confidence engaging senior stakeholders.
  • A proactive approach with the ability to manage multiple priorities.

Experience with GRC platforms, ISO 27001 certification, GDPR/NIS2, cloud security (Microsoft 365/Azure) or security certifications (CISA, CISSP, CRISC, Security+ etc.) would be advantageous.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · WWC 2022

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi · WWC 2022

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · WWC 2023

Videos

See all

Related articles

See all