GRC Jobs in London

1 to 25 of 92 GRC Jobs in London

Technology and Cyber Risk & Controls SME - Insurance

London, South East, England, United Kingdom
Lorien
NIST, ISO 27001, COBIT). Deep understanding of IT general controls, cyber security principles, and technology risk domains. Experience in control ownership, control testing, and remediation planning. Familiarity with GRC platforms and control lifecycle management. Experience in a risk management, IT audit, or cyber security role within a financial services or regulated environment. Excellent communication and stakeholder engagement skills. Ability More ❯
Employment Type: Contractor
Rate: Salary negotiable
Posted:

Security Metrics & Reporting Consultant

City of London, London, United Kingdom
Hybrid / WFH Options
Albany Beck
and Head of Function. Engage regularly with IT, Security, and Business stakeholders to align risk reporting with organizational objectives. What We’re Looking For: RSA Archer expertise or other GRC tooling Proven experience with NIST or other regulatory-aligned frameworks. Deep understanding of Cyber Risk Management principles. Exceptionally organized, with strong attention to detail and ability to manage multiple priorities. More ❯
Posted:

Security Metrics & Reporting Consultant

London Area, United Kingdom
Hybrid / WFH Options
Albany Beck
and Head of Function. Engage regularly with IT, Security, and Business stakeholders to align risk reporting with organizational objectives. What We’re Looking For: RSA Archer expertise or other GRC tooling Proven experience with NIST or other regulatory-aligned frameworks. Deep understanding of Cyber Risk Management principles. Exceptionally organized, with strong attention to detail and ability to manage multiple priorities. More ❯
Posted:

Security Metrics & Reporting Consultant

london, south east england, united kingdom
Hybrid / WFH Options
Albany Beck
and Head of Function. Engage regularly with IT, Security, and Business stakeholders to align risk reporting with organizational objectives. What We’re Looking For: RSA Archer expertise or other GRC tooling Proven experience with NIST or other regulatory-aligned frameworks. Deep understanding of Cyber Risk Management principles. Exceptionally organized, with strong attention to detail and ability to manage multiple priorities. More ❯
Posted:

Security Metrics & Reporting Consultant

london (city of london), south east england, united kingdom
Hybrid / WFH Options
Albany Beck
and Head of Function. Engage regularly with IT, Security, and Business stakeholders to align risk reporting with organizational objectives. What We’re Looking For: RSA Archer expertise or other GRC tooling Proven experience with NIST or other regulatory-aligned frameworks. Deep understanding of Cyber Risk Management principles. Exceptionally organized, with strong attention to detail and ability to manage multiple priorities. More ❯
Posted:

Compliance Manager – Consumer and Privacy Programmes

London Area, United Kingdom
Hybrid / WFH Options
EML
protection frameworks and global privacy regulations (e.g., GDPR,CCPA). Professional certifications such as from the International Compliance Association (ICA), or other relevant credentials preferred. Technical : Experience with compliance GRC, DPIA, ROPA and privacy management technologies and automation tools.Strong project management skills with experience leading cross-functional initiatives. Team : Strong communication and influencing skills, capable of working with senior leaders More ❯
Posted:

Compliance Manager – Consumer and Privacy Programmes

City of London, London, United Kingdom
Hybrid / WFH Options
EML
protection frameworks and global privacy regulations (e.g., GDPR,CCPA). Professional certifications such as from the International Compliance Association (ICA), or other relevant credentials preferred. Technical : Experience with compliance GRC, DPIA, ROPA and privacy management technologies and automation tools.Strong project management skills with experience leading cross-functional initiatives. Team : Strong communication and influencing skills, capable of working with senior leaders More ❯
Posted:

Compliance Manager – Consumer and Privacy Programmes

london, south east england, united kingdom
Hybrid / WFH Options
EML
protection frameworks and global privacy regulations (e.g., GDPR,CCPA). Professional certifications such as from the International Compliance Association (ICA), or other relevant credentials preferred. Technical : Experience with compliance GRC, DPIA, ROPA and privacy management technologies and automation tools.Strong project management skills with experience leading cross-functional initiatives. Team : Strong communication and influencing skills, capable of working with senior leaders More ❯
Posted:

Compliance Manager – Consumer and Privacy Programmes

london (city of london), south east england, united kingdom
Hybrid / WFH Options
EML
protection frameworks and global privacy regulations (e.g., GDPR,CCPA). Professional certifications such as from the International Compliance Association (ICA), or other relevant credentials preferred. Technical : Experience with compliance GRC, DPIA, ROPA and privacy management technologies and automation tools.Strong project management skills with experience leading cross-functional initiatives. Team : Strong communication and influencing skills, capable of working with senior leaders More ❯
Posted:

SOC Analyst - Active SC, Cyber, Cloud

London, South East, England, United Kingdom
Hays Specialist Recruitment Limited
commercial experience working as a SOC Analyst in large, complex organisations. Active SC clearance. Strong working knowledge of cloud technologies including AWS and Azure. The ability to liaise with GRC teams to ensure compliance with and company adherence to relevant regulations and control frameworks e.g. NCSC CAF, ONR SyAPs, ISO27001. Proven knowledge of adversary TTPs and frameworks like MITRE ATT More ❯
Employment Type: Contractor
Rate: £370 - £400 per day
Posted:

Cyber Security Consultant

London Area, United Kingdom
Hybrid / WFH Options
Anson McCade
globally. What You’ll Do Advise executive stakeholders on defining and executing risk-based cyber security strategies. Design and deliver cyber transformation programmes that align with business goals. Define governance frameworks, target operating models, and maturity roadmaps. Support clients in achieving regulatory compliance (e.g., NIS2, GDPR, ISO27001). Lead or support project delivery across multiple sectors and stakeholder levels. What … and team management (Agile or Waterfall). Analytical and lateral problem-solving mindset. Bonus if you have: Security clearance or the ability to obtain it. Hands-on experience across GRC, cyber threat management, or vulnerability management. If you’re ready to work on some of the most pressing and complex cyber challenges facing organisations today and want to do it More ❯
Posted:

Cyber Security Consultant

City of London, London, United Kingdom
Hybrid / WFH Options
Anson McCade
globally. What You’ll Do Advise executive stakeholders on defining and executing risk-based cyber security strategies. Design and deliver cyber transformation programmes that align with business goals. Define governance frameworks, target operating models, and maturity roadmaps. Support clients in achieving regulatory compliance (e.g., NIS2, GDPR, ISO27001). Lead or support project delivery across multiple sectors and stakeholder levels. What … and team management (Agile or Waterfall). Analytical and lateral problem-solving mindset. Bonus if you have: Security clearance or the ability to obtain it. Hands-on experience across GRC, cyber threat management, or vulnerability management. If you’re ready to work on some of the most pressing and complex cyber challenges facing organisations today and want to do it More ❯
Posted:

Cyber Security Consultant

London Area, United Kingdom
Hybrid / WFH Options
Anson McCade
resilience and enable growth. What You’ll Do Advise executives on actionable cyber strategies to support digital transformation Shape and deliver cyber transformation programmes aligned with organisational objectives Design governance and operational models to enhance cyber maturity and regulatory readiness Assess and define risk-based roadmaps that embed cyber security into business operations Work across a range of industries and … of relevant standards: NIST CSF, ISO27001, NCSC CAF, GDPR, NIS2, etc. Certifications such as CISSP, CISM, CISA, M.Inst.ISP, or MSc in Cyber Security Hands-on experience in areas like GRC, cyber threat management, vulnerability management Strong communication skills – written and verbal – with the ability to present to both technical and business stakeholders Consulting: Proven project delivery using Agile and Waterfall More ❯
Posted:

Cyber Security Consultant

City of London, London, United Kingdom
Hybrid / WFH Options
Anson McCade
resilience and enable growth. What You’ll Do Advise executives on actionable cyber strategies to support digital transformation Shape and deliver cyber transformation programmes aligned with organisational objectives Design governance and operational models to enhance cyber maturity and regulatory readiness Assess and define risk-based roadmaps that embed cyber security into business operations Work across a range of industries and … of relevant standards: NIST CSF, ISO27001, NCSC CAF, GDPR, NIS2, etc. Certifications such as CISSP, CISM, CISA, M.Inst.ISP, or MSc in Cyber Security Hands-on experience in areas like GRC, cyber threat management, vulnerability management Strong communication skills – written and verbal – with the ability to present to both technical and business stakeholders Consulting: Proven project delivery using Agile and Waterfall More ❯
Posted:

Cyber Security Consultant

london, south east england, united kingdom
Hybrid / WFH Options
Anson McCade
resilience and enable growth. What You’ll Do Advise executives on actionable cyber strategies to support digital transformation Shape and deliver cyber transformation programmes aligned with organisational objectives Design governance and operational models to enhance cyber maturity and regulatory readiness Assess and define risk-based roadmaps that embed cyber security into business operations Work across a range of industries and … of relevant standards: NIST CSF, ISO27001, NCSC CAF, GDPR, NIS2, etc. Certifications such as CISSP, CISM, CISA, M.Inst.ISP, or MSc in Cyber Security Hands-on experience in areas like GRC, cyber threat management, vulnerability management Strong communication skills – written and verbal – with the ability to present to both technical and business stakeholders Consulting: Proven project delivery using Agile and Waterfall More ❯
Posted:

Information Security Analyst

City of London, London, United Kingdom
Sanderson
site into London Role Description: As a Senior Information Security Analyst, you will be instrumental in executing the company's Information Security strategies and initiatives, focusing on supporting the Governance, Risk, and Compliance (GRC) function and implementing the NIST Cyber Security Framework (CSF) throughout the organization. You will lead day-to-day GRC activities, including designing security controls, enforcing requirements … activities with the Group Information Security Framework, Cyber Essentials, and PCI DSS attestation. Collaborating with the wider organization to integrate control testing and risk management activities into the existing governance framework. Assisting cross-functional teams and business units in integrating security measures into business operations. Facilitating regular reviews and updates of control and risk management processes to remain effective and … responsive to emerging threats and changes in the organizational landscape. Documenting and visualizing reports for governance forums, providing insights and recommendations to inform decision-making and risk management strategy across the business. Essential Skills: Minimum of 4 years of experience in information security with a solid understanding of Information Security control and governance frameworks. Practical experience of implementing NIST CSF More ❯
Posted:

Information Security Analyst

London Area, United Kingdom
Sanderson
site into London Role Description: As a Senior Information Security Analyst, you will be instrumental in executing the company's Information Security strategies and initiatives, focusing on supporting the Governance, Risk, and Compliance (GRC) function and implementing the NIST Cyber Security Framework (CSF) throughout the organization. You will lead day-to-day GRC activities, including designing security controls, enforcing requirements … activities with the Group Information Security Framework, Cyber Essentials, and PCI DSS attestation. Collaborating with the wider organization to integrate control testing and risk management activities into the existing governance framework. Assisting cross-functional teams and business units in integrating security measures into business operations. Facilitating regular reviews and updates of control and risk management processes to remain effective and … responsive to emerging threats and changes in the organizational landscape. Documenting and visualizing reports for governance forums, providing insights and recommendations to inform decision-making and risk management strategy across the business. Essential Skills: Minimum of 4 years of experience in information security with a solid understanding of Information Security control and governance frameworks. Practical experience of implementing NIST CSF More ❯
Posted:

Information Security Analyst

london, south east england, united kingdom
Sanderson
site into London Role Description: As a Senior Information Security Analyst, you will be instrumental in executing the company's Information Security strategies and initiatives, focusing on supporting the Governance, Risk, and Compliance (GRC) function and implementing the NIST Cyber Security Framework (CSF) throughout the organization. You will lead day-to-day GRC activities, including designing security controls, enforcing requirements … activities with the Group Information Security Framework, Cyber Essentials, and PCI DSS attestation. Collaborating with the wider organization to integrate control testing and risk management activities into the existing governance framework. Assisting cross-functional teams and business units in integrating security measures into business operations. Facilitating regular reviews and updates of control and risk management processes to remain effective and … responsive to emerging threats and changes in the organizational landscape. Documenting and visualizing reports for governance forums, providing insights and recommendations to inform decision-making and risk management strategy across the business. Essential Skills: Minimum of 4 years of experience in information security with a solid understanding of Information Security control and governance frameworks. Practical experience of implementing NIST CSF More ❯
Posted:

Information Security Analyst

london (city of london), south east england, united kingdom
Sanderson
site into London Role Description: As a Senior Information Security Analyst, you will be instrumental in executing the company's Information Security strategies and initiatives, focusing on supporting the Governance, Risk, and Compliance (GRC) function and implementing the NIST Cyber Security Framework (CSF) throughout the organization. You will lead day-to-day GRC activities, including designing security controls, enforcing requirements … activities with the Group Information Security Framework, Cyber Essentials, and PCI DSS attestation. Collaborating with the wider organization to integrate control testing and risk management activities into the existing governance framework. Assisting cross-functional teams and business units in integrating security measures into business operations. Facilitating regular reviews and updates of control and risk management processes to remain effective and … responsive to emerging threats and changes in the organizational landscape. Documenting and visualizing reports for governance forums, providing insights and recommendations to inform decision-making and risk management strategy across the business. Essential Skills: Minimum of 4 years of experience in information security with a solid understanding of Information Security control and governance frameworks. Practical experience of implementing NIST CSF More ❯
Posted:

IT Governance Officer

London, United Kingdom
Proactive Appointments
IT Governance Officer The successful candidate will serve as the subject matter expert on the IT operational risk assessment, controls and governance ("IT GRC"). Sitting within the IT team and acting as the first line of defence. You will closely partner with internal IT teams, Business OPC, Central IT OPC and other control functions to strengthen IT operational processes. … IT Operational Permanent Control (OPC) Assessment Group Cybersecurity Assessment IT Audits Client Due Diligence Questionnaire and Security clauses The successful candidate will have strong and relevant experience in IT governance and operational risk management in a similar sized organisation. Knowledge of external certifications and the ability to audit the organisation's conformance to those standards; Working experience within ISO …/NIST standards Good level of experience and competency within an IT OPC and Governance environment. Personal experience of implementing high quality standards (ideally ISO etc.) within an organisation and the ability to drive quality standards through the organisation. Desirable qualifications ITIL Life cycle/Capability certification ISACA Certificate in the Governance of Enterprise IT (CGEIT) CISA certification Due to More ❯
Employment Type: Permanent
Salary: GBP 55,000 - 60,000 Annual
Posted:

IT Governance Officer

London, South East, England, United Kingdom
Proactive Appointments
IT Governance Officer The successful candidate will serve as the subject matter expert on the IT operational risk assessment, controls and governance (“IT GRC”). Sitting within the IT team and acting as the first line of defence. You will closely partner with internal IT teams, Business OPC, Central IT OPC and other control functions to strengthen IT operational processes. … IT Operational Permanent Control (OPC) Assessment Group Cybersecurity Assessment IT Audits Client Due Diligence Questionnaire and Security clauses The successful candidate will have strong and relevant experience in IT governance and operational risk management in a similar sized organisation. Knowledge of external certifications and the ability to audit the organisation’s conformance to those standards; Working experience within ISO …/NIST standards Good level of experience and competency within an IT OPC and Governance environment. Personal experience of implementing high quality standards (ideally ISO etc.) within an organisation and the ability to drive quality standards through the organisation. Desirable qualifications ITIL Life cycle/Capability certification ISACA Certificate in the Governance of Enterprise IT (CGEIT) CISA certification Due to More ❯
Employment Type: Full-Time
Salary: £55,000 - £60,000 per annum
Posted:

Oracle IT Controls Transformation Manager

London, United Kingdom
Hybrid / WFH Options
Betfair Ltd
Financials, Procurement, Projects) and ensure appropriate mitigation strategies are in place. Coordinate and support internal and external audit engagements, including control walkthroughs, testing, and remediation plans. Leverage Oracle-native GRC tools and/or third-party solutions to automate and monitor control effectiveness. Drive continuous improvement in IT control frameworks, including knowledge transfer and capability building within the team. How More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

GRC Manager

London, United Kingdom
Hybrid / WFH Options
Stackstudio Digital Ltd
Job Title: Senior GRC & Compliance Manager (Business GRC role for SAP S/4HANA Transformation Programme) Location: London, UK Job Type: Permanent Working Arrangements: Hybrid (2-3 days a week in office) Job Summary: Join a leading pharmaceutical organisation as a Senior Governance, Risk & Compliance (GRC) Manager to drive compliance excellence across a major SAP S/4HANA transformation programme. … You will lead governance oversight, ensuring SAP Finance & Non-Finance systems meet stringent regulatory, corporate, and quality standards. This is a high-impact role working closely with senior stakeholders, finance, IT, and quality teams to deliver robust compliance in a regulated environment. Key Responsibilities: Lead governance, risk, and compliance for SAP Finance & Non-Finance systems. Ensure adherence to SOX, GxP … GDPR, and related regulatory requirements. Oversee implementation and maintenance of IT Quality Management Systems (QMS). Provide governance oversight during SAP S/4HANA implementations, upgrades, and integrations. Review and validate SAP design/configuration to meet financial governance standards. Collaborate with cross-functional teams to ensure alignment with corporate and regulatory frameworks. Skills, Experience, and Abilities Required: 10+ years More ❯
Employment Type: Permanent, Work From Home
Salary: £80,000
Posted:

Regulatory & Security Compliance Lead, AU, Compliance & Security Assurance

London, United Kingdom
Amazon
degree in related area of study (Computer Science, Engineering, Cyber Security, IT Security Management). Familiarity with cloud computing, technology risks, security and outsourcing. PREFERRED QUALIFICATIONS Experience working on governance, risk and compliance programs that involve direct engagement with regulators Demonstrated technical acumen in software engineering, security engineering, or cloud architecture, as well as experience leveraging AI to improve productivity. More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Information Security Risk and Governance Lead

City of London, London, United Kingdom
Hybrid / WFH Options
Hlx Life Sciences
Information Security Risk and Governance Lead Location: London or Lausanne Type: Full-time | Hybrid (3 days/week onsite) Company Overview Join a pioneering AI-first biotech company that’s redefining how we discover and develop medicines. This organisation leverages cutting-edge machine learning to unlock new possibilities in drug discovery, aiming to solve some of humanity’s most devastating … world-class team at the intersection of biology, AI, and engineering. Role Overview This role offers a unique opportunity to architect and operationalise a best-in-class information security governance framework. Reporting directly to the Chief Information Security Officer (CISO), you will lead strategic efforts to embed security, trust, and regulatory readiness into a platform that supports world-leading biomedical … research and drug design. You will play a pivotal role in aligning data governance, security operations, and compliance within an environment that spans regulated biopharma workflows, cloud-native infrastructure, and AI/ML experimentation at scale. Key Responsibilities Design and implement a unified compliance framework across AI, cyber, and life sciences regulatory domains. Own and drive the strategic programme for More ❯
Posted:
GRC
London
10th Percentile
£54,750
25th Percentile
£69,375
Median
£85,000
75th Percentile
£106,250
90th Percentile
£122,500