> Markdown version of [/jobs/ext/3207840-information-security-lead-grc](https://www.wearedevelopers.com/jobs/ext/3207840-information-security-lead-grc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Lead (GRC) - **Company:** Enorth Resourcing Limited - **Location:** Bedford, UK - **Experience:** Expert - **Salary:** £60,000.0 - £70,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Disaster Recovery, Information Technology Security Auditing, Software Vulnerability Management, Information Security Management System, Patch Management - **Published:** September 27, 2026 - **Apply:** https://find.jobs/jobs-near-me/apply/ats-redirect/?id=2989423629-2 ## About the Role We're particularly interested in strong experience across: * GRC & Security Governance: ISO 27001, ISMS, Risk Management, Security Policies, Controls, Compliance and Information Security Governance. * Security Audits & Assurance: Internal Audits, External Audits, Certification Audits, Audit Evidence, Remediation, Customer Assurance and Supplier Assurance. * Cyber Security: Vulnerability Management, Penetration Testing, Patch Management, Incident Response and Security Controls. * Resilience & Compliance: Cyber Essentials, Business Continuity, Disaster Recovery, DPIAs, BIAs and Third-Party Risk. You'll ideally have 5+ years' experience across Information Security, Cyber Security, GRC, IT Risk, Compliance or Security Assurance. You don't necessarily need to already be an Information Security Manager. We'd also like to hear from Information Security Leads, GRC Leads, Senior Information Security Analysts, Senior Cyber Security Analysts, Information Security Consultants, IT Risk & Compliance professionals and Security Engineers who have developed substantial GRC and audit experience., If you have strong GRC + ISO 27001 + Security Audit + Information Security experience, combined with a good technical security foundation, we'd like to hear from you. ## Description GRC ISO 27001 ISMS Security Audits Risk Management Cyber Security Information Security Networks Are you an experienced Information Security / Cyber Security professional with strong hands-on GRC, ISO 27001 and Security Audit experience, combined with a technical understanding of Cyber Security? We're recruiting an Information Security Lead / Cyber Security Lead for a leading international SaaS software business, offering the opportunity to take greater ownership across Information Security, GRC, Security Governance, Risk, Compliance and Cyber Security. Strong GRC and audit experience is essential. We're looking for someone who understands how to operate and improve an ISMS, support ISO 27001, manage security risk and controls, and work confidently across internal audits, external certification audits, customer assurance and supplier security. Ideally, you'll have developed your career from an IT, Infrastructure, Network or technical Cyber Security background before moving into broader Information Security and GRC. THE ROLE You'll work closely with the Head of Information Security, helping maintain and continually improve the organisation's Information Security, GRC and compliance environment. Your remit will include ISO 27001, ISMS, security audits, risk assessments, policies and controls, customer assurance, supplier security and audit remediation, alongside Cyber Essentials and wider certification activities. You'll also work closely with technical teams across vulnerability management, patching, penetration testing, incident response, Business Continuity and Disaster Recovery, ensuring security risks and audit findings translate into practical improvements. ## Related Videos - [ The attacker's footprint](https://www.wearedevelopers.com/videos/375-the-attacker-s-footprint) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Convincing Product teams to Adopt Gitops in a Large Org](https://www.wearedevelopers.com/videos/1936-convincing-product-teams-to-adopt-gitops-in-a-large-org) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany)