> Markdown version of [/jobs/ext/793791-information-security-technology-risk-regulation-grc-and-awareness-lead](https://www.wearedevelopers.com/jobs/ext/793791-information-security-technology-risk-regulation-grc-and-awareness-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security & Technology Risk, Regulation (GRC) and Awareness Lead - **Company:** Thorpe Molloy McCulloch Recruitment - **Location:** Aberdeen, UK - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Cyber Security, Phishing, Information Technology - **Published:** June 2, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=eb01c538ebcc6457 ## About the Role Do you have experience in NIST standards?, * Degree in Computer Science, Information Security, or equivalent experience * Certifications such as CISSP, GICSP, or similar * Experience leading organisation-wide awareness and culture programmes * Exposure to ISO 27001 audits or similar assurance frameworks ## Description Lead the design and execution of enterprise security governance, risk, policy, and awareness frameworks. Drive compliance with key regulations, embed cyber risk into business decision-making, and strengthen organisational culture through training and engagement. Provide senior-level reporting and assurance across cyber posture, controls, and risk management. An organisation is seeking an Information Security GRC & Awareness Lead to own and evolve its security governance, risk management, policy framework, and awareness strategy. This role ensures cyber security is effectively governed, risk-managed, and embedded across the organisation through structured frameworks and strong stakeholder engagement. You will operate at a senior level, working across IT, Risk, Legal, Compliance, and business functions to ensure alignment with regulatory frameworks and organisational risk appetite., Security Governance & Frameworks: * Design and maintain the organisation's information security governance model * Define roles, responsibilities, escalation paths, and governance structures * Align frameworks with recognised standards (e.g. ISO 27001, NIST CSF, UK CAF) * Integrate cyber governance into wider enterprise governance structures Information Security Risk Management: * Lead the development and operation of the cyber risk management framework * Oversee risk identification, assessment, treatment, and reporting processes * Ensure risk registers are maintained and embedded into governance forums * Align cyber risk with enterprise risk management (ERM) practices Policy, Standards & Compliance: * Own the lifecycle of security policies, standards, and procedures * Ensure compliance with legal and regulatory requirements (e.g. NIS2, GDPR) * Establish governance processes for policy review, approval, and communication * Maintain consistency and alignment across the policy ecosystem Awareness, Culture & Training: * Develop and deliver a comprehensive cyber security awareness strategy * Drive behavioural change through campaigns, phishing simulations, and engagement * Engage senior stakeholders to promote a strong security culture * Measure effectiveness via KPIs, surveys, and cultural assessments Executive Reporting & Assurance: * Deliver regular reporting to senior leadership and board-level stakeholders * Provide insight into governance effectiveness, risk posture, and compliance * Support internal and external audits and remediation activities * Lead maturity assessments (e.g. ISO 27001, CAF) and track improvement plans Stakeholder Engagement & Integration: * Partner with Legal, Compliance, HR, and IT teams to embed GRC practices * Act as a subject matter expert across governance, risk, and policy * Support secure-by-design processes within business and technology initiatives * Adapt governance and awareness approaches across diverse teams and regions ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Top HR Tech Conferences in 2024](https://www.wearedevelopers.com/magazine/303-top-hr-tech-conferences-in-2024) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)