London, South East, England, United Kingdom Hybrid / WFH Options
Crimson
Cyber Security GRC Manager - London Remote working Salary up to £60,000 per annum This is a fully remote position, with occasional meetings in London and possible travel to India twice yearly. Cyber Security Manager (GRC) position available for a client based in London. The role involves shaping and implementing a governance, risk, andcompliance (GRC) strategy. Responsibilities include establishing … implementing technical controls. Skilled in articulating technical risks in terms of business impact. Professional certifications such as CISM, CISSP, CRISC, ISO 27001 Lead Auditor, and hands-on experience with GRC tools (e.g., Vanta, Drata) are highly desirable. Responsible for developing and maintaining security policies in alignment with ISO 27001, GDPR, HIPAA, and OWASP standards. Lead risk assessments and oversee the More ❯
Aberdeen, City of Aberdeen, United Kingdom Hybrid / WFH Options
Orion Group
ongoing attestation for Suppliers and Third Parties. Collaborate with Legal to ensure that contractual SLAs/KPIs include security requirements and be involved in remediation where gaps exist. Reporting & Governance Maintain risk registers, control libraries and test plans; provide CIO-ready reporting on issues and residual risk. Coordinate with the Business and 1st Line risk owners, as well as with … ICS riskand understanding of SCADA/PI/EC interfaces. Skilled at stakeholder managementandrisk communication to senior audiences (clear, concise, business-outcome focused). Tooling familiarity: GRC/IRM platforms (e.g., ServiceNow), and common cloud services (M365/Azure) for workflows and evidence capture. Advantageous Certifications: Governance & Audit: ISO 27001 Lead Auditor, CISM Architecture & Design: SABSA, CISSP More ❯
Portsmouth, Hampshire, South East, United Kingdom Hybrid / WFH Options
Robert Half
to best-in-class standards through internationally recognised security certifications and industry-wide assurance frameworks, delivering confidence to clients and meeting regulatory expectations. As a core team member in Governance, Risk, andCompliance (GRC) , you will lead certification efforts, influence operational processes, and engage directly with customers and auditors to showcase security credentials that differentiate our SOC from the competition. More ❯
Edinburgh, City of Edinburgh, United Kingdom Hybrid / WFH Options
Cathcart Technology
Cyber Security Risk Manager required to join a globally recognised SaaS company in Edinburgh, leading the governance, risk, andcompliance (GRC) function and helping shape cyber security strategy in a cutting edge environment. The Company This is a modern, globally recognised SaaS company operating at the forefront of data analytics. Their datasets are relied upon by clients to make very … a collaborative and transparent team that values open communication, shared success, and measurable impact. The Role As Cyber Risk Manager, you will lead the maturity and execution of the governance, risk, andcompliance (GRC) function. You will ensure the business has clear visibility of its cyber risk exposure and the processes in place to respond effectively. You will oversee the … exceptions and ensure timely review, tracking, and remediation of risks. ** Drive SOC 2 readiness activities and collaborate with auditors and internal stakeholders to ensure compliance. ** Develop and enforce cybersecurity governance policies, standards, and procedures aligned with industry frameworks. ** Work with IT, SRE, Architecture, and Procurement teams to identify, assess, and mitigate technology and third party risks. ** Provide clear, actionable reporting More ❯
Edinburgh, Midlothian, Scotland, United Kingdom Hybrid / WFH Options
Cathcart Technology
Cyber Security Risk Manager required to join a globally recognised SaaS company in Edinburgh, leading the governance, risk, andcompliance (GRC) function and helping shape cyber security strategy in a cutting edge environment. The Company This is a modern, globally recognised SaaS company operating at the forefront of data analytics. Their datasets are relied upon by clients to make very … a collaborative and transparent team that values open communication, shared success, and measurable impact. The Role As Cyber Risk Manager, you will lead the maturity and execution of the governance, risk, andcompliance (GRC) function. You will ensure the business has clear visibility of its cyber risk exposure and the processes in place to respond effectively. You will oversee the … exceptions and ensure timely review, tracking, and remediation of risks. ** Drive SOC 2 readiness activities and collaborate with auditors and internal stakeholders to ensure compliance. ** Develop and enforce cybersecurity governance policies, standards, and procedures aligned with industry frameworks. ** Work with IT, SRE, Architecture, and Procurement teams to identify, assess, and mitigate technology and third party risks. ** Provide clear, actionable reporting More ❯
external IT support providers and vendors. The IT Director will be responsible for ensuring that our systems are secure, scalable, and aligned with the Firm's high standards of governanceand performance. Key Responsibilities Infrastructure & Operations - Oversee the Firm's cloud-based infrastructure (AVD on Microsoft Azure), ensuring performance, reliability, and scalability. - Oversee the Firm's line of business applications … the Microsoft suite, Teams, CCH Central, Virtual Cabinet, Caseware, Alphatax) - Manage hardware and software lifecycles, including procurement, deployment, and retirement. - Ensure robust update control, patch management, and system monitoring. Governance & Security - Implement and maintain strong IT governance frameworks, including riskmanagementand compliance. - Lead cybersecurity strategy, including threat detection, incident response, and staff awareness training. - Ensure compliance with GDPR andMore ❯
Liverpool, England, United Kingdom Hybrid / WFH Options
S&W
for an experienced Information Security Risk Professional with expertise in security complianceand assurance, ISO 27001 implementation, PMO (project management office), risk assessments, supply chain and working on other governance, riskandcompliance projects within a team. You’ll be highly motivated, pro-active and will become a productive member of a busy Information Security team, gaining exposure to a … incident. You’ll apply relevant risk mitigations and deal with multiple stakeholders to ensure end to end treatment is applied. You’ll also be part of our PMO andgovernanceandcompliance processes and will deliver updates to senior management in meetings and information security forums, whilst ensuring the business remains compliant to regulatory frameworks and good practice standards. This … of the corresponding compensating control(s) or the need for new controls Qualifications Skills and Experience To be successful in this role, you should have Experience in Information Security governance, riskandcompliance areas Experience managing internal and third-party vendor risk assessments and writing risk assessment reports Experience reviewing risk assessments, and SOC Type II reports for completeness andMore ❯
birkenhead, north west england, united kingdom Hybrid / WFH Options
S&W
for an experienced Information Security Risk Professional with expertise in security complianceand assurance, ISO 27001 implementation, PMO (project management office), risk assessments, supply chain and working on other governance, riskandcompliance projects within a team. You’ll be highly motivated, pro-active and will become a productive member of a busy Information Security team, gaining exposure to a … incident. You’ll apply relevant risk mitigations and deal with multiple stakeholders to ensure end to end treatment is applied. You’ll also be part of our PMO andgovernanceandcompliance processes and will deliver updates to senior management in meetings and information security forums, whilst ensuring the business remains compliant to regulatory frameworks and good practice standards. This … of the corresponding compensating control(s) or the need for new controls Qualifications Skills and Experience To be successful in this role, you should have Experience in Information Security governance, riskandcompliance areas Experience managing internal and third-party vendor risk assessments and writing risk assessment reports Experience reviewing risk assessments, and SOC Type II reports for completeness andMore ❯
warrington, cheshire, north west england, united kingdom Hybrid / WFH Options
S&W
for an experienced Information Security Risk Professional with expertise in security complianceand assurance, ISO 27001 implementation, PMO (project management office), risk assessments, supply chain and working on other governance, riskandcompliance projects within a team. You’ll be highly motivated, pro-active and will become a productive member of a busy Information Security team, gaining exposure to a … incident. You’ll apply relevant risk mitigations and deal with multiple stakeholders to ensure end to end treatment is applied. You’ll also be part of our PMO andgovernanceandcompliance processes and will deliver updates to senior management in meetings and information security forums, whilst ensuring the business remains compliant to regulatory frameworks and good practice standards. This … of the corresponding compensating control(s) or the need for new controls Qualifications Skills and Experience To be successful in this role, you should have Experience in Information Security governance, riskandcompliance areas Experience managing internal and third-party vendor risk assessments and writing risk assessment reports Experience reviewing risk assessments, and SOC Type II reports for completeness andMore ❯
old swan, north west england, united kingdom Hybrid / WFH Options
S&W
for an experienced Information Security Risk Professional with expertise in security complianceand assurance, ISO 27001 implementation, PMO (project management office), risk assessments, supply chain and working on other governance, riskandcompliance projects within a team. You’ll be highly motivated, pro-active and will become a productive member of a busy Information Security team, gaining exposure to a … incident. You’ll apply relevant risk mitigations and deal with multiple stakeholders to ensure end to end treatment is applied. You’ll also be part of our PMO andgovernanceandcompliance processes and will deliver updates to senior management in meetings and information security forums, whilst ensuring the business remains compliant to regulatory frameworks and good practice standards. This … of the corresponding compensating control(s) or the need for new controls Qualifications Skills and Experience To be successful in this role, you should have Experience in Information Security governance, riskandcompliance areas Experience managing internal and third-party vendor risk assessments and writing risk assessment reports Experience reviewing risk assessments, and SOC Type II reports for completeness andMore ❯
Birmingham, West Midlands, United Kingdom Hybrid / WFH Options
Tarmac Trading Limited
to shape the future of how we build, connect, and operate. Join Tarmacs Finance & IT Controls Graduate Programme and be part of a team driving digital transformation through robust governance, riskmanagement, and financial analysis.This unique opportunity blends technology, data, and business value creation- ideal for graduates passionate about automation, compliance, and strategic financial planning. This role sits at the … automation tools to enhance efficiency and insight generation.Graduates will contribute to both control assurance and financial reporting activities, supporting key initiatives across the business. What youll be doing IT Governance & RiskManagement Support control design, risk assessments, andcompliance monitoring (e.g., GDPR, ISO 27001). Financial Planning & Analysis Assist in budgeting, forecasting, and ROI modelling for technology investments. Automation & Insight … from you. Essential A degree (or predicted degree) in Computer Science, Information Systems, Finance, Accounting, Economics , or a related discipline Strong analytical and problem-solving skills Interest in IT governance, risk, compliance, and financial analysis Desirable Familiarity with control frameworks (e.g., COBIT, NIST), financial systems (e.g., SAP), and data tools (e.g., Power BI) Hybrid working available- giving you the flexibility More ❯
Market Harborough, Leicestershire, East Midlands, United Kingdom Hybrid / WFH Options
4C Resourcing
to Incident Response where needed. There will also be opportunities to define and lead other areas of cyber security. What youll be doing Lead and deliver client engagements across governance, riskandcompliance (GRC), including audits, assessments and improvement plans aligned to frameworks such as ISO/IEC 27001, NCSC CAF, and PCI DSS. Lead independent assurance, review and test … Chartered status (or demonstrable readiness to achieve this in the near term). Significant experience in cyber security consulting or assurance, ideally within the public sector. Deep knowledge of GRC frameworks and standards (e.g. CAF, ISO/IEC 27001, PCI DSS).Strong client-facing skills, able to communicate complex issues clearly to technical and non-technical audiences. Proven track record … and influencing decision-making. Excellent written and verbal communication, including the ability to produce polished consultancy reports. Desirable certifications: ISO 27001 Lead Auditor/Implementer, CISSP, CISM, CRISC, CCP (GRC), or equivalent. Driving license and willingness to travel to client sites across the UK as required. Why join 4C Strategies? Work with a growing cyber team in a respected consultancy More ❯
Bristol, England, United Kingdom Hybrid / WFH Options
Hays
IT Security & GRC Manager Permanent - £48k - £52k + strong benefits Location: Hybrid - Bristol Your new company I am looking to recruit an IT Security & GRC Manager to join a great public sector organisation. You'll join a forward-thinking organisation with a national footprint and a user base exceeding 2,000 people. With ambitious plans for IT Security transformation, this … to join a great organisation at a key time when they are investing in and transforming their IT and Security estate. You will be running the IT Security andGRC department, reporting into the Head of IT. Key parts of the role include: Shape and steer the direction of IT security governance, ensuring alignment with business strategy, HMG requirements, and … landscape affecting IT systems and information. Prioritise risk treatment and resources based on impact, human factors, and cost-effectiveness. Assurance andcompliance oversight andmanagement Manage the IT Security, Governance, RiskandCompliance team, ensuring clear direction, support, and professional development. What you'll need to succeed At least one of the following, ideally 2 of CISM/CISA/ More ❯
newport, wales, united kingdom Hybrid / WFH Options
Hays
IT Security & GRC Manager Permanent - £48k - £52k + strong benefits Location: Hybrid - Bristol Your new company I am looking to recruit an IT Security & GRC Manager to join a great public sector organisation. You'll join a forward-thinking organisation with a national footprint and a user base exceeding 2,000 people. With ambitious plans for IT Security transformation, this … to join a great organisation at a key time when they are investing in and transforming their IT and Security estate. You will be running the IT Security andGRC department, reporting into the Head of IT. Key parts of the role include: Shape and steer the direction of IT security governance, ensuring alignment with business strategy, HMG requirements, and … landscape affecting IT systems and information. Prioritise risk treatment and resources based on impact, human factors, and cost-effectiveness. Assurance andcompliance oversight andmanagement Manage the IT Security, Governance, RiskandCompliance team, ensuring clear direction, support, and professional development. What you'll need to succeed At least one of the following, ideally 2 of CISM/CISA/ More ❯
Bristol, Avon, England, United Kingdom Hybrid / WFH Options
Hays Specialist Recruitment Limited
IT Security & GRC Manager Permanent - £48k - £52k + strong benefits Location: Hybrid - Bristol Your new company I am looking to recruit an IT Security & GRC Manager to join a great public sector organisation. You'll join a forward-thinking organisation with a national footprint and a user base exceeding 2,000 people. With ambitious plans for IT Security transformation, this … to join a great organisation at a key time when they are investing in and transforming their IT and Security estate. You will be running the IT Security andGRC department, reporting into the Head of IT. Key parts of the role include: Shape and steer the direction of IT security governance, ensuring alignment with business strategy, HMG requirements, and … landscape affecting IT systems and information. Prioritise risk treatment and resources based on impact, human factors, and cost-effectiveness. Assurance andcompliance oversight andmanagement Manage the IT Security, Governance, RiskandCompliance team, ensuring clear direction, support, and professional development. What you'll need to succeed At least one of the following, ideally 2 of CISM/CISA/ More ❯
bath, south west england, united kingdom Hybrid / WFH Options
Hays
IT Security & GRC Manager Permanent - £48k - £52k + strong benefits Location: Hybrid - Bristol Your new company I am looking to recruit an IT Security & GRC Manager to join a great public sector organisation. You'll join a forward-thinking organisation with a national footprint and a user base exceeding 2,000 people. With ambitious plans for IT Security transformation, this … to join a great organisation at a key time when they are investing in and transforming their IT and Security estate. You will be running the IT Security andGRC department, reporting into the Head of IT. Key parts of the role include: Shape and steer the direction of IT security governance, ensuring alignment with business strategy, HMG requirements, and … landscape affecting IT systems and information. Prioritise risk treatment and resources based on impact, human factors, and cost-effectiveness. Assurance andcompliance oversight andmanagement Manage the IT Security, Governance, RiskandCompliance team, ensuring clear direction, support, and professional development. What you'll need to succeed At least one of the following, ideally 2 of CISM/CISA/ More ❯
bradley stoke, south west england, united kingdom Hybrid / WFH Options
Hays
IT Security & GRC Manager Permanent - £48k - £52k + strong benefits Location: Hybrid - Bristol Your new company I am looking to recruit an IT Security & GRC Manager to join a great public sector organisation. You'll join a forward-thinking organisation with a national footprint and a user base exceeding 2,000 people. With ambitious plans for IT Security transformation, this … to join a great organisation at a key time when they are investing in and transforming their IT and Security estate. You will be running the IT Security andGRC department, reporting into the Head of IT. Key parts of the role include: Shape and steer the direction of IT security governance, ensuring alignment with business strategy, HMG requirements, and … landscape affecting IT systems and information. Prioritise risk treatment and resources based on impact, human factors, and cost-effectiveness. Assurance andcompliance oversight andmanagement Manage the IT Security, Governance, RiskandCompliance team, ensuring clear direction, support, and professional development. What you'll need to succeed At least one of the following, ideally 2 of CISM/CISA/ More ❯
Portsmouth, Hampshire, England, United Kingdom Hybrid / WFH Options
Computappoint
IT services and consulting firm, is seeking a Cyber Security Assurance Manager to ensure their SOC meets and maintains top security certifications and assurance standards. As part of the GRC function, you’ll lead customer assurance activities, manage external audits, and oversee key certifications such as ISO 27001, SOC2 Type II, Cyber Essentials Plus, and CREST SOC accreditation. Key Responsibilities … Lead the delivery and ongoing maintenance of SOC-related certifications (SOC 2 Type II, SOC 3, ISO/IEC 27001, Cyber Essentials Plus, CREST) Embed certification requirements into SOC governance, processes, and operational practices Ensure continuous monitoring, evidence collection, and audit readiness for internal and external assessments Monitor developments in global cybersecurity regulations and frameworks (NIST CSF, UK NCSC guidance More ❯
roadmaps, guiding clients through technology transformations, and ensuring technology initiatives align with business goals. Acting as an IT director on a fractional basis, you will oversee IT governance, riskmanagement, andcompliance, helping organisations manage regulatory requirements and mitigate potential risks. In addition to assessing current technologies and identifying areas for improvement, you will recommend innovative, tailored solutions that drive … and ensuring technology investments deliver measurable value. Develop and maintain comprehensive IT roadmaps and strategies, adjusting plans according to evolving business requirements and emerging technologies. Guide clients on IT governance, compliance, andriskmanagement, ensuring all solutions meet regulatory standards and industry best practices. Oversee IT budgeting and resource allocation, helping clients optimise expenditure while maximising efficiency and innovation. Facilitate … real business impact. As a vCIO Consultant, you’ll guide clients through transformative IT strategies, acting as a trusted advisor and fractional IT Director. Lead high-level IT planning andgovernance Work remotely with flexibility and autonomy Collaborate with diverse clients and expert teams Influence innovation and operational excellence Grow professionally in a dynamic, supportive environment Make your next move More ❯
SAP GRC Security & Authorisations Consultant About NTT DATA Business Solutions: NTT DATA Business Solutions Group is part of the NTT DATA Corporate Group a top 10 global IT services provider, headquartered in Tokyo, operating in more than 50 countries. We combine a global reach with local intimacy to provide premier professional SAP services from deep industry expertise consulting to applied … business by being alert to the customer opportunities that present themselves. Have strength and depth in delivery and configuration expertise in the following; Core SAP Roles & Authorisations Functionality SAP GRC SAP IAG You will support the implementation and use of Governance, RiskandCompliance (GRC/AIG solutions) in the customer’s IT infrastructure. You will help our clients to More ❯
IT Risk & Resilience Lead Location: Hybrid/London Employment Type: Full-Time | Permanent Department: Risk, Governance & Compliance Level: Manager/Senior Manager The Opportunity Our client is looking for an experienced IT Risk & Resilience Lead to drive enterprise-wide initiatives in IT governance, risk, compliance, and operational resilience. In this strategic role, you'll help shape how our client anticipates … be responsible for designing, maintaining, and evolving our IT risk frameworks, ensuring they meet both business needs and regulatory expectations. Your work will span seven key areas: 1. IT Governance & Compliance You'll advise governance forums, monitor compliance across internal policies and regulatory standards (e.g., DORA, GDPR, FCA, BaFin), and ensure our digital resilience strategy is fully embedded across the … risk training initiatives that build resilience awareness across staff and partners, reinforcing policy adherence. 7. Innovation & Emerging Risk (AI Focus) Support development of the firm's approach to AI governance, implementation, andrisk mitigation as new technologies are adopted. What You'll Bring Extensive experience in IT operational risk within financial services or a similarly regulated environment. Strong understanding of More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
McGregor Boyall
IT Risk & Resilience Lead Location: Hybrid/London Employment Type: Full-Time | Permanent Department: Risk, Governance & Compliance Level: Manager/Senior Manager The Opportunity Our client is looking for an experienced IT Risk & Resilience Lead to drive enterprise-wide initiatives in IT governance, risk, compliance, and operational resilience. In this strategic role, you'll help shape how our client anticipates … be responsible for designing, maintaining, and evolving our IT risk frameworks, ensuring they meet both business needs and regulatory expectations. Your work will span seven key areas: 1. IT Governance & Compliance You'll advise governance forums, monitor compliance across internal policies and regulatory standards (e.g., DORA, GDPR, FCA, BaFin), and ensure our digital resilience strategy is fully embedded across the … risk training initiatives that build resilience awareness across staff and partners, reinforcing policy adherence. 7. Innovation & Emerging Risk (AI Focus) Support development of the firm's approach to AI governance, implementation, andrisk mitigation as new technologies are adopted. What You'll Bring Extensive experience in IT operational risk within financial services or a similarly regulated environment. Strong understanding of More ❯
slough, south east england, united kingdom Hybrid / WFH Options
McGregor Boyall
IT Risk & Resilience Lead Location: Hybrid/London Employment Type: Full-Time | Permanent Department: Risk, Governance & Compliance Level: Manager/Senior Manager The Opportunity Our client is looking for an experienced IT Risk & Resilience Lead to drive enterprise-wide initiatives in IT governance, risk, compliance, and operational resilience. In this strategic role, you'll help shape how our client anticipates … be responsible for designing, maintaining, and evolving our IT risk frameworks, ensuring they meet both business needs and regulatory expectations. Your work will span seven key areas: 1. IT Governance & Compliance You'll advise governance forums, monitor compliance across internal policies and regulatory standards (e.g., DORA, GDPR, FCA, BaFin), and ensure our digital resilience strategy is fully embedded across the … risk training initiatives that build resilience awareness across staff and partners, reinforcing policy adherence. 7. Innovation & Emerging Risk (AI Focus) Support development of the firm's approach to AI governance, implementation, andrisk mitigation as new technologies are adopted. What You'll Bring Extensive experience in IT operational risk within financial services or a similarly regulated environment. Strong understanding of More ❯
Leatherhead, Surrey, South East, United Kingdom Hybrid / WFH Options
Hays
IT Riskand Policy (GRC) Analyst Permanent - Up to £38k + strong benefits Location: Hybrid - Leatherhead Your new company A leading construction and development company in Surrey is currently looking for an IT Riskand Policy (GRC) Analyst to come in and support the existing IT Risk & Policy Manager with the day-to-day tasks involved with managing the risks … experience across multiple areas. The Analyst is responsible for managing IT risks, monitoring audit actions, maintaining IT policies and procedures, and supporting GDPR compliance. The role combines technical andgovernance aspects, with a focus on standards and regulations, whilst ensuring collaboration across the business to ensure strong IT practices are put in place. Ensuring that all IT riskand IT … oral and written communication skills, with high attention to detail Ability to produce high-quality, detailed outputs. Good analytical skills Highly organised and able to implement and manage robust governance processes. To undergo a BPSS security check. What you'll get in return This role is available for hybrid working with a typical requirement to work 2 or 3 days More ❯
Fetcham, Surrey, United Kingdom Hybrid / WFH Options
Hays Technology
IT Riskand Policy (GRC) Analyst Permanent - Up to 38k + strong benefits Location: Hybrid - Leatherhead Your new company A leading construction and development company in Surrey is currently looking for an IT Riskand Policy (GRC) Analyst to come in and support the existing IT Risk & Policy Manager with the day-to-day tasks involved with managing the risks … experience across multiple areas. The Analyst is responsible for managing IT risks, monitoring audit actions, maintaining IT policies and procedures, and supporting GDPR compliance. The role combines technical andgovernance aspects, with a focus on standards and regulations, whilst ensuring collaboration across the business to ensure strong IT practices are put in place. Ensuring that all IT riskand IT … oral and written communication skills, with high attention to detail Ability to produce high-quality, detailed outputs. Good analytical skills Highly organised and able to implement and manage robust governance processes. To undergo a BPSS security check. What you'll get in return This role is available for hybrid working with a typical requirement to work 2 or 3 days More ❯