Head of Information Security GRC & Awareness

TRIA
UK
8 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cyber Security IT Management Operational Systems CIS Benchmarks

Job description

Head of Information Security GRC & Awareness

We are seeking an experienced Head of InfoSec GRC & Awareness to lead governance, risk, compliance, and security awareness initiatives across an organisation at a time of significant modernisation. This pivotal role ensures a robust security posture by developing and enforcing policies, standards, and training programmes aligned with business objectives and regulatory requirements.

Duration: 6 months. Rate: Inside IR35, rate to be discussed.

Key Responsibilities

  • Lead the development and enforcement of enterprise-wide information security policies and standards.
  • Drive security governance and cyber maturity through compliance, assurance reviews, and gap analysis.
  • Oversee the Information Security Risk Management process.
  • Conduct in-depth supplier due diligence / third-party assurance processes.
  • Manage audit readiness and support internal/external audit activities.
  • Own and deliver the organisation’s security awareness programme, including campaigns and tailored training.
  • Depending on the candidate, also develop and implement an Operational Technology (OT) Security Assurance Framework.

Candidate Profile

  • Professional certifications such as CISSP, CISM, ISO27001 Lead Auditor, CLAS, etc.
  • Extensive experience in information security or IT governance within large, complex environments.
  • Strong knowledge of security frameworks (ISO/IEC 27001, NIST CSF, CIS Controls, Cyber Essentials).
  • Proven track record in risk management, policy development, and security awareness initiatives.
  • Excellent communication, leadership, and influencing skills.
  • Very strong experience of driving 3rd-party due diligence.
  • Experience in Technical Assurance, OT Security Assurance and Penetration Testing is a bonus.

This is an excellent opportunity to lead a critical function within a dynamic organisation, ensuring security resilience and cultural change across the enterprise.

For further information, please apply and I will be in touch.

Requirements

  • Professional certifications such as CISSP, CISM, ISO27001 Lead Auditor, CLAS, etc.
  • Extensive experience in information security or IT governance within large, complex environments.
  • Strong knowledge of security frameworks (ISO/IEC 27001, NIST CSF, CIS Controls, Cyber Essentials).
  • Proven track record in risk management, policy development, and security awareness initiatives.
  • Excellent communication, leadership, and influencing skills.
  • Very strong experience of driving 3rd-party due diligence.
  • Experience in Technical Assurance, OT Security Assurance and Penetration Testing is a bonus.

This is an excellent opportunity to lead a critical function within a dynamic organisation, ensuring security resilience and cultural change across the enterprise.

Benefits & conditions

Duration: 6 months. Rate: Inside IR35, rate to be discussed.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · World Congress 2025

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all