Information Security GRC Specialist
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
This is a senior hire within the Information Security GRC function, acting as deputy to the Head of Information Security & GRC, supporting the leadership and day-to-day running of the team. The role combines hands-on delivery with leadership responsibility, operating in a 1.5 line capacity - working closely with technology teams while maintaining strong governance oversight., * Act as second-in-command within the GRC function, supporting the Head of Information Security & GRC across BAU, projects, and stakeholder engagement.
- Operate in a hands-on 1.5 line capacity, working closely with SecOps, IAM, and cloud teams to ensure controls are effective in practice.
- Lead cyber risk assessments and control reviews, identifying gaps and driving remediation through to closure.
- Act as a bridge between GRC and technical teams, confidently challenging and validating control design and implementation.
- Support board-level reporting and risk metrics, translating technical issues into clear, business-focused insights.
- Contribute to the development and rollout of GRC tooling, with a focus on automation, reporting, and adoption across technical teams.
- Support incident response oversight, including post-incident reviews and control improvements.
- Maintain and enhance security policies, standards, and frameworks aligned to ISO 27001 and NIST.
- Work across Technology, Risk, Compliance, and Audit to embed security into business processes and decision-making.
Requirements
- Proven experience within financial services.
- Proven experience in Information Security, Cyber GRC, or Technology Risk within a regulated environment.
- Experience operating in a hands-on capacity across both governance and technical security domains (e.g. vulnerability management, SIEM/SOC, IAM, cloud security).
- Strong understanding of security frameworks such as ISO 27001 and/or NIST.
- Ability to engage with and challenge technical teams, ensuring controls are implemented effectively rather than existing as policy only.
- Experience producing senior-level reporting, including risk metrics and board-facing outputs.
- Exposure to GRC tooling and/or automation initiatives.
- Strong stakeholder management skills, with the ability to work across technical and non-technical audiences.
- Certifications (e.g. CISSP, CISM) are not essential - practical, real-world experience is key.
About the company
My client is a leading global investment management organisation seeking a Cyber GRC Specialist to join its Global Technology function in London.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Software Engineer Salary London
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Data Analyst Salary in the UK
IT Salaries in UK