Information Security Governance, Risk, and Compliance (GRC) Specialist

Company: Janus Henderson
Apply for the Information Security Governance, Risk, and Compliance (GRC) Specialist
Location: London
Job Description:

Overview

In this role you will shape and manage the cybersecurity policy framework to protect clients and the firm. You will integrate security practices across tech and non-tech teams, enhancing governance and risk controls. You’ll drive regulatory alignment, incident response, and ongoing awareness to sustain a strong security posture. You join a values-driven, inclusive team that values collaboration and practical risk-based improvements. This position offers scope to influence security at scale and through cross-functional partnerships.

Pay / Benefits

  • hybrid working environment
  • inclusive and supportive culture
  • flexible working arrangements
  • accommodation during recruitment process
  • opportunity to influence security at scale

Responsibilities

  • Develop and maintain comprehensive cybersecurity policies and procedures aligned with standards and regulations
  • Lead risk assessments and oversee implementation of risk mitigation strategies across the organization
  • Ensure compliance management, monitoring policies, and regulatory requirements; prepare senior management reports
  • Support cybersecurity awareness training programs and foster a security-conscious culture
  • Participate in incident response and post-incident evaluations, driving corrective actions
  • Engage with stakeholders across Technology, Legal, Compliance, and Internal Audit to align security objectives

Key requirements

  • Bachelor’s Degree in Information Technology, Cybersecurity, or related field; equivalent work experience considered
  • 3 to 5 years of information security experience
  • CISSP certification strongly preferred
  • Strong understanding of cybersecurity frameworks (NIST, ISO/IEC 27001) and regulatory standards
  • Experience with financial service regulations (FCA, SEC, MAS, DORA)
  • Proficient in network security concepts (Firewalls, IPS/IDS, TCP/IP, DHCP, DNS)
  • Experience securing Windows, UNIX/Linux, and Mac OS
  • Knowledge of cloud security (IaaS, PaaS, SaaS) and cloud deployment models
  • IAM knowledge including SSO, MFA, RBAC; understands secure DevOps/CI/CD governance
  • Stakeholder engagement
  • Collaborative teamwork
  • Clear communication
  • Firewalls
  • IPS/IDS
  • TCP/IP

Posted: September 14th, 2026