Information Security GRC Specialist Role – Insurance, The City, London
We are looking for an experienced Senior Information Security GRC Specialist to join an established and expanding cyber security team. This is a senior role with broad responsibility across security governance, risk and compliance, working closely with both technology and business stakeholders to strengthen the organisation’s overall security posture.
Key Responsibilities
- Contribute to the development and ongoing delivery of the organisation’s information security strategy and governance approach.
- Manage cyber and information security risk activities, including risk assessments, control reviews, audits and remediation.
- Develop, review and maintain security policies, standards, controls and risk documentation.
- Maintain oversight of security risks and ensure appropriate actions are tracked through to resolution.
- Produce meaningful reporting on cyber risk, control performance, compliance and key security indicators.
- Help ensure alignment with relevant regulatory requirements and recognised frameworks, including NIST, GDPR and DORA.
- Work with business and technology teams to provide practical security and risk guidance.
- Support security awareness and education activities across the organisation.
- Contribute to security incident management, lessons learned and the ongoing improvement of security processes.
- Provide senior-level GRC support and leadership cover when required.
Experience & Skills
- Extensive experience within Information Security, ideally 10+ years, with a strong background in GRC, cyber risk and security governance.
- Demonstrable experience leading security or risk initiatives and influencing senior stakeholders.
- Strong understanding of information security controls, risk management methodologies, governance frameworks and regulatory requirements.
- Able to translate technical and security risks into clear business language and recommendations.
- Strong communication, reporting and stakeholder management skills.
- Previous experience within a regulated environment, particularly financial services or insurance, would be advantageous.
#J-18808-Ljbffr…
