Information Security & Technology Risk, Regulation (GRC) and Awareness Lead

Thorpe Molloy McCulloch Recruitment
Aberdeen, UK
2 months ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Phishing Information Technology

Job description

Lead the design and execution of enterprise security governance, risk, policy, and awareness frameworks. Drive compliance with key regulations, embed cyber risk into business decision-making, and strengthen organisational culture through training and engagement. Provide senior-level reporting and assurance across cyber posture, controls, and risk management.

An organisation is seeking an Information Security GRC & Awareness Lead to own and evolve its security governance, risk management, policy framework, and awareness strategy. This role ensures cyber security is effectively governed, risk-managed, and embedded across the organisation through structured frameworks and strong stakeholder engagement.

You will operate at a senior level, working across IT, Risk, Legal, Compliance, and business functions to ensure alignment with regulatory frameworks and organisational risk appetite., Security Governance & Frameworks:

  • Design and maintain the organisation’s information security governance model
  • Define roles, responsibilities, escalation paths, and governance structures
  • Align frameworks with recognised standards (e.g. ISO 27001, NIST CSF, UK CAF)
  • Integrate cyber governance into wider enterprise governance structures

Information Security Risk Management:

  • Lead the development and operation of the cyber risk management framework
  • Oversee risk identification, assessment, treatment, and reporting processes
  • Ensure risk registers are maintained and embedded into governance forums
  • Align cyber risk with enterprise risk management (ERM) practices

Policy, Standards & Compliance:

  • Own the lifecycle of security policies, standards, and procedures
  • Ensure compliance with legal and regulatory requirements (e.g. NIS2, GDPR)
  • Establish governance processes for policy review, approval, and communication
  • Maintain consistency and alignment across the policy ecosystem

Awareness, Culture & Training:

  • Develop and deliver a comprehensive cyber security awareness strategy
  • Drive behavioural change through campaigns, phishing simulations, and engagement
  • Engage senior stakeholders to promote a strong security culture
  • Measure effectiveness via KPIs, surveys, and cultural assessments

Executive Reporting & Assurance:

  • Deliver regular reporting to senior leadership and board-level stakeholders
  • Provide insight into governance effectiveness, risk posture, and compliance
  • Support internal and external audits and remediation activities
  • Lead maturity assessments (e.g. ISO 27001, CAF) and track improvement plans

Stakeholder Engagement & Integration:

  • Partner with Legal, Compliance, HR, and IT teams to embed GRC practices
  • Act as a subject matter expert across governance, risk, and policy
  • Support secure-by-design processes within business and technology initiatives
  • Adapt governance and awareness approaches across diverse teams and regions

Requirements

Do you have experience in NIST standards?, * Degree in Computer Science, Information Security, or equivalent experience

  • Certifications such as CISSP, GICSP, or similar
  • Experience leading organisation-wide awareness and culture programmes
  • Exposure to ISO 27001 audits or similar assurance frameworks

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all