Information Security Governance, Risk, and Compliance (GRC) Specialist
- Develop and maintain comprehensive cybersecurity policies and procedures.
- Ensure these policies align with industry standards and regulatory requirements.
- Assist in the integration of security practices and control across various technical and non-technical departments, enhancing workflow and operational processes.
- Conduct regular risk assessments to help identify vulnerabilities and threats.
- Collaborate and oversee the implementation of risk mitigation strategies.
- Monitor emerging threats and evolving technologies to continuously refine risk assessment protocols.
- Ability to design and evaluate control metrics for assessing the effectiveness of cybersecurity measures.
- Collaborate with Enterprise risk management to embed cyber risk into broader risk registers and board-level reporting.
- Monitor and ensure compliance with internal policies, industry standards, and regulatory requirement.
- Engage with required stakeholders in Technology, Legal, Compliance and Internal Audit as required
- Compile and deliver detailed compliance reports to senior management
- Monitor upcoming regulations and prepare compliance roadmaps.
- Support and enhance engaging cybersecurity awareness training programs.
- Foster a company-wide culture of cybersecurity awareness.
- Keep current with the latest cybersecurity trends and best practices to inform training content and security measures
- Train and guide wider Tech team members on best practices in cybersecurity risk management.
- Actively participate in the response to security incidents.
- Support post-incident evaluations and reporting.
- Collaborate with relevant stakeholders to devise and enforce corrective measures aimed at bolstering defences against future incidents.
- Maintain clear and effective communication with stakeholders at all levels.
- Provide expert guidance on cybersecurity best practices.
- Work collaboratively with Technology and other departments to achieve comprehensive security objective
- Bachelor’s Degree in Information Technology, Cybersecurity, or a related field; equivalent work experience also considered.
- 3 to 5 years of professional experience in information security.
- Certification such as Certified Information Systems Security Professional (CISSP) strongly preferred.
- Deep understanding of cybersecurity principles, frameworks (such as NIST, ISO/IEC 27001), and compliance standards.
- Experience with financial service regulations and regulations such as FCA, SEC, MAS, DORA.
- Proficient knowledge of network security principles and controls such as Firewalls, IPS/IPD, TCP/IP, DHCP, and DNS
- Extensive experience in securing Operating Systems such as Windows, UNIX/Linux and Mac systems. This includes security access rights, implementing configuration best practices
- Knowledge of cloud service models (IaaS, PaaS, SaaS) and deployment models (public, private, hybrid, community) and experience in implementing and managing cloud security best practices.
- In-depth knowledge of IAM principles and technologies to manage digital identities and control user access and experience with Single Sign-On (SSO), Multi-Factor Authentication (MFA), and role-based access control (RBAC) systems to enhance security and operational efficiency.
- Understanding of Secure DevOps / CI/CD pipeline governance
- No
Recommended Jobs
Registered Veterinary Nurse
Job Overview South London is calling for a dedicated registered veterinary nurse to step into a thriving practice known for excellent client service and strong team spirit. Working Hours 40 h…
Van Controller
As a Van Controller within GSF Car Parts you will play an important part in ensuring that we continue to commit to our sales promise by coordinating delivery runs and ensuring delivery drivers contin…
Product Manager, GPTN
Join the team redefining how the world experiences design Hiya gday mabuhay kia ora 你好 hallo vítejte! Thanks for stopping by. We know job hunting can be a little time consuming and youre probabl…
Lead Underwriter - Property & Casualty
Lead Underwriter – Property & Casualty Location: London (Hybrid) Salary: £100,000 + excellent benefits A leading name in the commercial insurance market is expanding its Mid Corporate portfolio a…
Electrical Technical Director (Data Centres) - London
Electrical Technical Director (Data Centres) - London RED are an expanding international M&E consultancy, with a proven track record in low energy design, focused on providing excellent design s…
Client Advisor
Bottega Veneta is seeking a Client Advisor for its Sloane Street location in London. This role involves providing exceptional customer service, building strong client relationships, and achieving sale…
Head of Finance and Contracts
The Role CoppaFeel! is looking for a Head of Finance and Contracts to as we continue to grow and develop the organisation’s internal operations. As Head of Finance and Contracts, you’ll oversee al…
Registered Veterinary Nurse
This is a fantastic opportunity for someone looking for an RVN role in a first opinion GP surgery. You will be joining a passionate team where you can enjoy clinical coaching and supporting student n…
Attendance Officer - Data & Intervention - Hackney
Attendance Officer – Lead Attendance Monitoring, Data Analysis, and Welfare Intervention – Hackney A dynamic and supportive secondary school in Hackney is seeking an experienced and dedicated At…
Philanthropy Manager
Philanthropy Manager We are seeking a proactive and relationship-led fundraiser to drive major donor and legacy giving for a growing and ambitious charity. Position: Philanthropy Manager Sa…