Information Security Specialist

Company: Michael James Associates
Apply for the Information Security Specialist
Location: London
Job Description:

Information Security GRC Specialist Role – Insurance, The City, London

We are looking for an experienced Senior Information Security GRC Specialist to join an established and expanding cyber security team. This is a senior role with broad responsibility across security governance, risk and compliance, working closely with both technology and business stakeholders to strengthen the organisation’s overall security posture.

Key Responsibilities

  • Contribute to the development and ongoing delivery of the organisation’s information security strategy and governance approach.
  • Manage cyber and information security risk activities, including risk assessments, control reviews, audits and remediation.
  • Develop, review and maintain security policies, standards, controls and risk documentation.
  • Maintain oversight of security risks and ensure appropriate actions are tracked through to resolution.
  • Produce meaningful reporting on cyber risk, control performance, compliance and key security indicators.
  • Help ensure alignment with relevant regulatory requirements and recognised frameworks, including NIST, GDPR and DORA.
  • Work with business and technology teams to provide practical security and risk guidance.
  • Support security awareness and education activities across the organisation.
  • Contribute to security incident management, lessons learned and the ongoing improvement of security processes.
  • Provide senior-level GRC support and leadership cover when required.

Experience & Skills

  • Extensive experience within Information Security, ideally 10+ years, with a strong background in GRC, cyber risk and security governance.
  • Demonstrable experience leading security or risk initiatives and influencing senior stakeholders.
  • Strong understanding of information security controls, risk management methodologies, governance frameworks and regulatory requirements.
  • Able to translate technical and security risks into clear business language and recommendations.
  • Strong communication, reporting and stakeholder management skills.
  • Previous experience within a regulated environment, particularly financial services or insurance, would be advantageous.

#J-18808-Ljbffr…

Posted: September 21st, 2026