CGRC Lead
Location: Hybrid (Leeds with UK travel)Salary: £45,000–£55,000 + Car Allowance + Bonus + Benefits
Elevation Tech & Transformation are exclusively recruiting for a newly created Cyber Governance, Risk & Compliance (GRC) Lead on behalf of a growing UK organisation.
This is an exciting opportunity to join a business investing heavily in its cyber security capability. Reporting to the Group Information Security Officer (GISO), you'll take ownership of cyber governance across the Group, working closely with senior stakeholders to strengthen security, risk and compliance practices.
This role would suit a proactive Cyber GRC professional who enjoys working autonomously, influencing change and building strong relationships across multiple businesses.
Key Responsibilities- Maintain and develop the Group cyber risk register.
- Develop and maintain security policies, standards and governance documentation.
- Support and improve cyber governance frameworks including NIST CSF, CIS Controls and ISO 27001.
- Conduct cyber risk assessments across projects, systems and suppliers.
- Coordinate internal and external audits and compliance activities.
- Produce cyber risk and assurance reporting for senior leadership.
- Support third-party security assurance and supplier risk management.
- Promote cyber security awareness and good governance across the organisation.
You'll have experience in Cyber Governance, Risk & Compliance and be confident working independently within a collaborative environment.
You'll also bring:
- Strong knowledge of NIST CSF, CIS Controls and ISO 27001.
- Experience conducting cyber risk assessments and supporting audits.
- The ability to develop policies, standards and governance documentation.
- Excellent communication skills, with confidence engaging senior stakeholders.
- A proactive approach with the ability to manage multiple priorities.
Experience with GRC platforms, ISO 27001 certification, GDPR/NIS2, cloud security (Microsoft 365/Azure) or security certifications (CISA, CISSP, CRISC, Security+ etc.) would be advantageous.
This is a fantastic opportunity to join a growing organisation where you'll have genuine ownership, visibility and the chance to shape cyber governance across the Group.