> Markdown version of [/jobs/ext/2239035-information-security-grc-manager](https://www.wearedevelopers.com/jobs/ext/2239035-information-security-grc-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security GRC Manager - **Company:** Aj Bell - **Location:** Manchester, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Security Information and Event Management, IT General Controls (ITGC) - **Published:** August 26, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815047513-information-security-grc-manager ## About the Role * Strong knowledge of information security risk management tools and techniques * Experience with security frameworks and standards * Understanding of the threat landscape * Awareness of security technologies (e.g. SIEM, endpoint protection, email/web gateways) * Knowledge of IT General Controls frameworks * Awareness of operational risk and RCSA processes, * Experience working within frameworks such as ISO27001, NIST or similar * Ideally 5+ years' experience in an information security role within financial services * Strong attention to detail and ownership of tasks * Confident challenging approaches to improve security outcomes * Self-motivated, organised, and able to work independently * Ability to manage multiple priorities in a fast-paced environment * CISM certification (achieved or in progress) preferred ## Description We're recruiting an Information Security GRC Manager to support the Senior Manager and Chief Information Security Officer in managing and reporting information security risks across Technology Services and the wider business. You'll work closely with stakeholders to ensure appropriate controls, policies, and procedures are in place, aligned to industry best practice and regulatory requirements. You'll also support internal and external audits, as well as due diligence activities with partners and suppliers. Key responsibilities * Develop and maintain information security policies aligned to recognised frameworks (e.g. ISO27001/2) * Manage and report on policy exceptions * Produce management reporting on information security and change programmes * Partner with business and technology teams to track remediation of risks and issues * Support the assessment of third-party security posture * Undertake risk profiling of information and technology assets * Support audit activity and supplier due diligence processes * Ensure all activities support customer protection and regulatory requirements, including Consumer Duty Technical skills * Strong knowledge of information security risk management tools and techniques * Experience with security frameworks and standards * Understanding of the threat landscape * Awareness of security technologies (e.g. SIEM, endpoint protection, email/web gateways) * Knowledge of IT General Controls frameworks * Awareness of operational risk and RCSA processes Skills And Experience * Experience working within frameworks such as ISO27001, NIST or similar * Ideally 5+ years' experience in an information security role within financial services * Strong attention to detail and ownership of tasks * Confident challenging approaches to improve security outcomes * Self-motivated, organised, and able to work independently * Ability to manage multiple priorities in a fast-paced environment * CISM certification (achieved or in progress) preferred About Us AJ Bell is one of the UK's fastest-growing investment platforms, serving over 644,000 customers and managing £103.3 billion in assets. Our award-winning platform supports everyone from financial advisers to first-time investors, making it easier to take control of their financial future. With over 1,500 employees across Manchester, London, and Bristol, we're a FTSE 250 company and have been recognised as one of the UK's Best 100 Companies to Work For for six consecutive years, as well as a Great Place to Work® in 2025 and 2026. What we offer * 27 days' holiday (rising to 31) + buy/sell scheme * Pension with matched contributions up to 8% * Discretionary bonus and annual share awards * Health cash plan and discounted private healthcare * Free gym and wellbeing support * Enhanced family leave and sick pay * Season ticket loans and bike scheme * Regular social events and volunteering opportunities * Personal development programmes tailored to your career goals We offer a hybrid model with 50% office-based working each month. New joiners will spend an initial period in the office to support onboarding and relationship building. AJ Bell is committed to creating an inclusive environment where everyone can thrive. All hiring decisions are based on merit, skills, and business need. If this sounds like the right opportunity for you, we'd love to hear from you. ## Related Videos - [Generative UIs and AI Assistants for Your Angular Applications](https://www.wearedevelopers.com/videos/100074-generative-uis-and-ai-assistants-for-your-angular-applications) - [Create DSL (Domain Specific Language) on top of Swift](https://www.wearedevelopers.com/videos/707-create-dsl-domain-specific-language-on-top-of-swift) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)