> Markdown version of [/jobs/ext/2259213-head-of-information-security-grc-awareness](https://www.wearedevelopers.com/jobs/ext/2259213-head-of-information-security-grc-awareness). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of Information Security GRC & Awareness - **Company:** TRIA - **Location:** UK - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Software System Penetration Testing, Cyber Security, IT Management, Operational Systems, CIS Benchmarks - **Published:** August 26, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815048954-head-of-information-security-grc--awareness ## About the Role * Professional certifications such as CISSP, CISM, ISO27001 Lead Auditor, CLAS, etc. * Extensive experience in information security or IT governance within large, complex environments. * Strong knowledge of security frameworks (ISO/IEC 27001, NIST CSF, CIS Controls, Cyber Essentials). * Proven track record in risk management, policy development, and security awareness initiatives. * Excellent communication, leadership, and influencing skills. * Very strong experience of driving 3rd-party due diligence. * Experience in Technical Assurance, OT Security Assurance and Penetration Testing is a bonus. This is an excellent opportunity to lead a critical function within a dynamic organisation, ensuring security resilience and cultural change across the enterprise. ## Description Head of Information Security GRC & Awareness We are seeking an experienced Head of InfoSec GRC & Awareness to lead governance, risk, compliance, and security awareness initiatives across an organisation at a time of significant modernisation. This pivotal role ensures a robust security posture by developing and enforcing policies, standards, and training programmes aligned with business objectives and regulatory requirements. Duration: 6 months. Rate: Inside IR35, rate to be discussed. Key Responsibilities * Lead the development and enforcement of enterprise-wide information security policies and standards. * Drive security governance and cyber maturity through compliance, assurance reviews, and gap analysis. * Oversee the Information Security Risk Management process. * Conduct in-depth supplier due diligence / third-party assurance processes. * Manage audit readiness and support internal/external audit activities. * Own and deliver the organisation's security awareness programme, including campaigns and tailored training. * Depending on the candidate, also develop and implement an Operational Technology (OT) Security Assurance Framework. Candidate Profile * Professional certifications such as CISSP, CISM, ISO27001 Lead Auditor, CLAS, etc. * Extensive experience in information security or IT governance within large, complex environments. * Strong knowledge of security frameworks (ISO/IEC 27001, NIST CSF, CIS Controls, Cyber Essentials). * Proven track record in risk management, policy development, and security awareness initiatives. * Excellent communication, leadership, and influencing skills. * Very strong experience of driving 3rd-party due diligence. * Experience in Technical Assurance, OT Security Assurance and Penetration Testing is a bonus. This is an excellent opportunity to lead a critical function within a dynamic organisation, ensuring security resilience and cultural change across the enterprise. For further information, please apply and I will be in touch. ## Related Videos - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)