Information Security GRC Specialist

Morson Group
Greater London, UK
10 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Cloud Computing Cloud Computing Security Cyber Security Identity and Access Management Security Information and Event Management Software Vulnerability Management

Job description

This is a senior hire within the Information Security GRC function, acting as deputy to the Head of Information Security & GRC, supporting the leadership and day-to-day running of the team. The role combines hands-on delivery with leadership responsibility, operating in a 1.5 line capacity - working closely with technology teams while maintaining strong governance oversight., * Act as second-in-command within the GRC function, supporting the Head of Information Security & GRC across BAU, projects, and stakeholder engagement.

  • Operate in a hands-on 1.5 line capacity, working closely with SecOps, IAM, and cloud teams to ensure controls are effective in practice.
  • Lead cyber risk assessments and control reviews, identifying gaps and driving remediation through to closure.
  • Act as a bridge between GRC and technical teams, confidently challenging and validating control design and implementation.
  • Support board-level reporting and risk metrics, translating technical issues into clear, business-focused insights.
  • Contribute to the development and rollout of GRC tooling, with a focus on automation, reporting, and adoption across technical teams.
  • Support incident response oversight, including post-incident reviews and control improvements.
  • Maintain and enhance security policies, standards, and frameworks aligned to ISO 27001 and NIST.
  • Work across Technology, Risk, Compliance, and Audit to embed security into business processes and decision-making.

Requirements

  • Proven experience within financial services.
  • Proven experience in Information Security, Cyber GRC, or Technology Risk within a regulated environment.
  • Experience operating in a hands-on capacity across both governance and technical security domains (e.g. vulnerability management, SIEM/SOC, IAM, cloud security).
  • Strong understanding of security frameworks such as ISO 27001 and/or NIST.
  • Ability to engage with and challenge technical teams, ensuring controls are implemented effectively rather than existing as policy only.
  • Experience producing senior-level reporting, including risk metrics and board-facing outputs.
  • Exposure to GRC tooling and/or automation initiatives.
  • Strong stakeholder management skills, with the ability to work across technical and non-technical audiences.
  • Certifications (e.g. CISSP, CISM) are not essential - practical, real-world experience is key.

About the company

My client is a leading global investment management organisation seeking a Cyber GRC Specialist to join its Global Technology function in London.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

4:19 min

Differences between mobile infrastructure and application layer security

Moataz Nabil Moataz Nabil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

Videos

See all

Related articles

See all