NIST, ISO 27001, COBIT). Deep understanding of IT general controls, cyber security principles, and technology risk domains. Experience in control ownership, control testing, and remediation planning. Familiarity with GRC platforms and control lifecycle management. Experience in a riskmanagement, IT audit, or cyber security role within a financial services or regulated environment. Excellent communication and stakeholder engagement skills. Ability More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Albany Beck
and Head of Function. Engage regularly with IT, Security, and Business stakeholders to align risk reporting with organizational objectives. What We’re Looking For: RSA Archer expertise or other GRC tooling Proven experience with NIST or other regulatory-aligned frameworks. Deep understanding of Cyber RiskManagement principles. Exceptionally organized, with strong attention to detail and ability to manage multiple priorities. More ❯
and Head of Function. Engage regularly with IT, Security, and Business stakeholders to align risk reporting with organizational objectives. What We’re Looking For: RSA Archer expertise or other GRC tooling Proven experience with NIST or other regulatory-aligned frameworks. Deep understanding of Cyber RiskManagement principles. Exceptionally organized, with strong attention to detail and ability to manage multiple priorities. More ❯
london, south east england, united kingdom Hybrid / WFH Options
Albany Beck
and Head of Function. Engage regularly with IT, Security, and Business stakeholders to align risk reporting with organizational objectives. What We’re Looking For: RSA Archer expertise or other GRC tooling Proven experience with NIST or other regulatory-aligned frameworks. Deep understanding of Cyber RiskManagement principles. Exceptionally organized, with strong attention to detail and ability to manage multiple priorities. More ❯
london (city of london), south east england, united kingdom Hybrid / WFH Options
Albany Beck
and Head of Function. Engage regularly with IT, Security, and Business stakeholders to align risk reporting with organizational objectives. What We’re Looking For: RSA Archer expertise or other GRC tooling Proven experience with NIST or other regulatory-aligned frameworks. Deep understanding of Cyber RiskManagement principles. Exceptionally organized, with strong attention to detail and ability to manage multiple priorities. More ❯
protection frameworks and global privacy regulations (e.g., GDPR,CCPA). Professional certifications such as from the International Compliance Association (ICA), or other relevant credentials preferred. Technical : Experience with complianceGRC, DPIA, ROPA and privacy management technologies and automation tools.Strong project management skills with experience leading cross-functional initiatives. Team : Strong communication and influencing skills, capable of working with senior leaders More ❯
City of London, London, United Kingdom Hybrid / WFH Options
EML
protection frameworks and global privacy regulations (e.g., GDPR,CCPA). Professional certifications such as from the International Compliance Association (ICA), or other relevant credentials preferred. Technical : Experience with complianceGRC, DPIA, ROPA and privacy management technologies and automation tools.Strong project management skills with experience leading cross-functional initiatives. Team : Strong communication and influencing skills, capable of working with senior leaders More ❯
london, south east england, united kingdom Hybrid / WFH Options
EML
protection frameworks and global privacy regulations (e.g., GDPR,CCPA). Professional certifications such as from the International Compliance Association (ICA), or other relevant credentials preferred. Technical : Experience with complianceGRC, DPIA, ROPA and privacy management technologies and automation tools.Strong project management skills with experience leading cross-functional initiatives. Team : Strong communication and influencing skills, capable of working with senior leaders More ❯
london (city of london), south east england, united kingdom Hybrid / WFH Options
EML
protection frameworks and global privacy regulations (e.g., GDPR,CCPA). Professional certifications such as from the International Compliance Association (ICA), or other relevant credentials preferred. Technical : Experience with complianceGRC, DPIA, ROPA and privacy management technologies and automation tools.Strong project management skills with experience leading cross-functional initiatives. Team : Strong communication and influencing skills, capable of working with senior leaders More ❯
commercial experience working as a SOC Analyst in large, complex organisations. Active SC clearance. Strong working knowledge of cloud technologies including AWS and Azure. The ability to liaise with GRC teams to ensure compliance with and company adherence to relevant regulations and control frameworks e.g. NCSC CAF, ONR SyAPs, ISO27001. Proven knowledge of adversary TTPs and frameworks like MITRE ATT More ❯
globally. What You’ll Do Advise executive stakeholders on defining and executing risk-based cyber security strategies. Design and deliver cyber transformation programmes that align with business goals. Define governance frameworks, target operating models, and maturity roadmaps. Support clients in achieving regulatory compliance (e.g., NIS2, GDPR, ISO27001). Lead or support project delivery across multiple sectors and stakeholder levels. What … and team management (Agile or Waterfall). Analytical and lateral problem-solving mindset. Bonus if you have: Security clearance or the ability to obtain it. Hands-on experience across GRC, cyber threat management, or vulnerability management. If you’re ready to work on some of the most pressing and complex cyber challenges facing organisations today and want to do it More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Anson McCade
globally. What You’ll Do Advise executive stakeholders on defining and executing risk-based cyber security strategies. Design and deliver cyber transformation programmes that align with business goals. Define governance frameworks, target operating models, and maturity roadmaps. Support clients in achieving regulatory compliance (e.g., NIS2, GDPR, ISO27001). Lead or support project delivery across multiple sectors and stakeholder levels. What … and team management (Agile or Waterfall). Analytical and lateral problem-solving mindset. Bonus if you have: Security clearance or the ability to obtain it. Hands-on experience across GRC, cyber threat management, or vulnerability management. If you’re ready to work on some of the most pressing and complex cyber challenges facing organisations today and want to do it More ❯
resilience and enable growth. What You’ll Do Advise executives on actionable cyber strategies to support digital transformation Shape and deliver cyber transformation programmes aligned with organisational objectives Design governanceand operational models to enhance cyber maturity and regulatory readiness Assess and define risk-based roadmaps that embed cyber security into business operations Work across a range of industries and … of relevant standards: NIST CSF, ISO27001, NCSC CAF, GDPR, NIS2, etc. Certifications such as CISSP, CISM, CISA, M.Inst.ISP, or MSc in Cyber Security Hands-on experience in areas like GRC, cyber threat management, vulnerability management Strong communication skills – written and verbal – with the ability to present to both technical and business stakeholders Consulting: Proven project delivery using Agile and Waterfall More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Anson McCade
resilience and enable growth. What You’ll Do Advise executives on actionable cyber strategies to support digital transformation Shape and deliver cyber transformation programmes aligned with organisational objectives Design governanceand operational models to enhance cyber maturity and regulatory readiness Assess and define risk-based roadmaps that embed cyber security into business operations Work across a range of industries and … of relevant standards: NIST CSF, ISO27001, NCSC CAF, GDPR, NIS2, etc. Certifications such as CISSP, CISM, CISA, M.Inst.ISP, or MSc in Cyber Security Hands-on experience in areas like GRC, cyber threat management, vulnerability management Strong communication skills – written and verbal – with the ability to present to both technical and business stakeholders Consulting: Proven project delivery using Agile and Waterfall More ❯
london, south east england, united kingdom Hybrid / WFH Options
Anson McCade
resilience and enable growth. What You’ll Do Advise executives on actionable cyber strategies to support digital transformation Shape and deliver cyber transformation programmes aligned with organisational objectives Design governanceand operational models to enhance cyber maturity and regulatory readiness Assess and define risk-based roadmaps that embed cyber security into business operations Work across a range of industries and … of relevant standards: NIST CSF, ISO27001, NCSC CAF, GDPR, NIS2, etc. Certifications such as CISSP, CISM, CISA, M.Inst.ISP, or MSc in Cyber Security Hands-on experience in areas like GRC, cyber threat management, vulnerability management Strong communication skills – written and verbal – with the ability to present to both technical and business stakeholders Consulting: Proven project delivery using Agile and Waterfall More ❯
site into London Role Description: As a Senior Information Security Analyst, you will be instrumental in executing the company's Information Security strategies and initiatives, focusing on supporting the Governance, Risk, andCompliance (GRC) function and implementing the NIST Cyber Security Framework (CSF) throughout the organization. You will lead day-to-day GRC activities, including designing security controls, enforcing requirements … activities with the Group Information Security Framework, Cyber Essentials, and PCI DSS attestation. Collaborating with the wider organization to integrate control testing andriskmanagement activities into the existing governance framework. Assisting cross-functional teams and business units in integrating security measures into business operations. Facilitating regular reviews and updates of control andriskmanagement processes to remain effective and … responsive to emerging threats and changes in the organizational landscape. Documenting and visualizing reports for governance forums, providing insights and recommendations to inform decision-making andriskmanagement strategy across the business. Essential Skills: Minimum of 4 years of experience in information security with a solid understanding of Information Security control andgovernance frameworks. Practical experience of implementing NIST CSF More ❯
site into London Role Description: As a Senior Information Security Analyst, you will be instrumental in executing the company's Information Security strategies and initiatives, focusing on supporting the Governance, Risk, andCompliance (GRC) function and implementing the NIST Cyber Security Framework (CSF) throughout the organization. You will lead day-to-day GRC activities, including designing security controls, enforcing requirements … activities with the Group Information Security Framework, Cyber Essentials, and PCI DSS attestation. Collaborating with the wider organization to integrate control testing andriskmanagement activities into the existing governance framework. Assisting cross-functional teams and business units in integrating security measures into business operations. Facilitating regular reviews and updates of control andriskmanagement processes to remain effective and … responsive to emerging threats and changes in the organizational landscape. Documenting and visualizing reports for governance forums, providing insights and recommendations to inform decision-making andriskmanagement strategy across the business. Essential Skills: Minimum of 4 years of experience in information security with a solid understanding of Information Security control andgovernance frameworks. Practical experience of implementing NIST CSF More ❯
site into London Role Description: As a Senior Information Security Analyst, you will be instrumental in executing the company's Information Security strategies and initiatives, focusing on supporting the Governance, Risk, andCompliance (GRC) function and implementing the NIST Cyber Security Framework (CSF) throughout the organization. You will lead day-to-day GRC activities, including designing security controls, enforcing requirements … activities with the Group Information Security Framework, Cyber Essentials, and PCI DSS attestation. Collaborating with the wider organization to integrate control testing andriskmanagement activities into the existing governance framework. Assisting cross-functional teams and business units in integrating security measures into business operations. Facilitating regular reviews and updates of control andriskmanagement processes to remain effective and … responsive to emerging threats and changes in the organizational landscape. Documenting and visualizing reports for governance forums, providing insights and recommendations to inform decision-making andriskmanagement strategy across the business. Essential Skills: Minimum of 4 years of experience in information security with a solid understanding of Information Security control andgovernance frameworks. Practical experience of implementing NIST CSF More ❯
london (city of london), south east england, united kingdom
Sanderson
site into London Role Description: As a Senior Information Security Analyst, you will be instrumental in executing the company's Information Security strategies and initiatives, focusing on supporting the Governance, Risk, andCompliance (GRC) function and implementing the NIST Cyber Security Framework (CSF) throughout the organization. You will lead day-to-day GRC activities, including designing security controls, enforcing requirements … activities with the Group Information Security Framework, Cyber Essentials, and PCI DSS attestation. Collaborating with the wider organization to integrate control testing andriskmanagement activities into the existing governance framework. Assisting cross-functional teams and business units in integrating security measures into business operations. Facilitating regular reviews and updates of control andriskmanagement processes to remain effective and … responsive to emerging threats and changes in the organizational landscape. Documenting and visualizing reports for governance forums, providing insights and recommendations to inform decision-making andriskmanagement strategy across the business. Essential Skills: Minimum of 4 years of experience in information security with a solid understanding of Information Security control andgovernance frameworks. Practical experience of implementing NIST CSF More ❯
IT Governance Officer The successful candidate will serve as the subject matter expert on the IT operational risk assessment, controls andgovernance ("IT GRC"). Sitting within the IT team and acting as the first line of defence. You will closely partner with internal IT teams, Business OPC, Central IT OPC and other control functions to strengthen IT operational processes. … IT Operational Permanent Control (OPC) Assessment Group Cybersecurity Assessment IT Audits Client Due Diligence Questionnaire and Security clauses The successful candidate will have strong and relevant experience in IT governanceand operational riskmanagement in a similar sized organisation. Knowledge of external certifications and the ability to audit the organisation's conformance to those standards; Working experience within ISO …/NIST standards Good level of experience and competency within an IT OPC andGovernance environment. Personal experience of implementing high quality standards (ideally ISO etc.) within an organisation and the ability to drive quality standards through the organisation. Desirable qualifications ITIL Life cycle/Capability certification ISACA Certificate in the Governance of Enterprise IT (CGEIT) CISA certification Due to More ❯
IT Governance Officer The successful candidate will serve as the subject matter expert on the IT operational risk assessment, controls andgovernance (“IT GRC”). Sitting within the IT team and acting as the first line of defence. You will closely partner with internal IT teams, Business OPC, Central IT OPC and other control functions to strengthen IT operational processes. … IT Operational Permanent Control (OPC) Assessment Group Cybersecurity Assessment IT Audits Client Due Diligence Questionnaire and Security clauses The successful candidate will have strong and relevant experience in IT governanceand operational riskmanagement in a similar sized organisation. Knowledge of external certifications and the ability to audit the organisation’s conformance to those standards; Working experience within ISO …/NIST standards Good level of experience and competency within an IT OPC andGovernance environment. Personal experience of implementing high quality standards (ideally ISO etc.) within an organisation and the ability to drive quality standards through the organisation. Desirable qualifications ITIL Life cycle/Capability certification ISACA Certificate in the Governance of Enterprise IT (CGEIT) CISA certification Due to More ❯
Financials, Procurement, Projects) and ensure appropriate mitigation strategies are in place. Coordinate and support internal and external audit engagements, including control walkthroughs, testing, and remediation plans. Leverage Oracle-native GRC tools and/or third-party solutions to automate and monitor control effectiveness. Drive continuous improvement in IT control frameworks, including knowledge transfer and capability building within the team. How More ❯
Job Title: Senior GRC & Compliance Manager (Business GRC role for SAP S/4HANA Transformation Programme) Location: London, UK Job Type: Permanent Working Arrangements: Hybrid (2-3 days a week in office) Job Summary: Join a leading pharmaceutical organisation as a Senior Governance, Risk & Compliance (GRC) Manager to drive compliance excellence across a major SAP S/4HANA transformation programme. … You will lead governance oversight, ensuring SAP Finance & Non-Finance systems meet stringent regulatory, corporate, and quality standards. This is a high-impact role working closely with senior stakeholders, finance, IT, and quality teams to deliver robust compliance in a regulated environment. Key Responsibilities: Lead governance, risk, andcompliance for SAP Finance & Non-Finance systems. Ensure adherence to SOX, GxP … GDPR, and related regulatory requirements. Oversee implementation and maintenance of IT Quality Management Systems (QMS). Provide governance oversight during SAP S/4HANA implementations, upgrades, and integrations. Review and validate SAP design/configuration to meet financial governance standards. Collaborate with cross-functional teams to ensure alignment with corporate and regulatory frameworks. Skills, Experience, and Abilities Required: 10+ years More ❯
degree in related area of study (Computer Science, Engineering, Cyber Security, IT Security Management). Familiarity with cloud computing, technology risks, security and outsourcing. PREFERRED QUALIFICATIONS Experience working on governance, riskandcompliance programs that involve direct engagement with regulators Demonstrated technical acumen in software engineering, security engineering, or cloud architecture, as well as experience leveraging AI to improve productivity. More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Hlx Life Sciences
Information Security RiskandGovernance Lead Location: London or Lausanne Type: Full-time | Hybrid (3 days/week onsite) Company Overview Join a pioneering AI-first biotech company that’s redefining how we discover and develop medicines. This organisation leverages cutting-edge machine learning to unlock new possibilities in drug discovery, aiming to solve some of humanity’s most devastating … world-class team at the intersection of biology, AI, and engineering. Role Overview This role offers a unique opportunity to architect and operationalise a best-in-class information security governance framework. Reporting directly to the Chief Information Security Officer (CISO), you will lead strategic efforts to embed security, trust, and regulatory readiness into a platform that supports world-leading biomedical … research and drug design. You will play a pivotal role in aligning data governance, security operations, andcompliance within an environment that spans regulated biopharma workflows, cloud-native infrastructure, and AI/ML experimentation at scale. Key Responsibilities Design and implement a unified compliance framework across AI, cyber, and life sciences regulatory domains. Own and drive the strategic programme for More ❯