Назад
Company hidden
9 часов назад

Cyber Governance, Risk & Compliance Lead (GRC)

50 000 - 60 000GBP
Формат работы
remote (только United_kingdom)
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cyber Governance, Risk & Compliance Lead (GRC): Maintaining and developing a group-wide cyber governance framework across subsidiary businesses with an accent on ISO 27001 compliance, risk management, audit readiness, and security maturity assessments. Focus on integrating acquired businesses, managing cyber risk registers and incident response plans, and translating security risks into actionable controls for technical and non-technical stakeholders.

Location: Remote role based in Leeds with some travel

Salary: £50,000–£60,000 per annum plus car allowance and package

Company

hirify.global is a recruitment and professional services organisation supporting technology, cybersecurity, and specialist business roles.

What you will do

  • Act as the main point of contact for cyber governance, risk, compliance, security audits, and audit readiness across the Group.
  • Maintain and challenge IT and cyber risk registers, coordinate remediation, and recommend appropriate risk treatment.
  • Support subsidiaries with ISO 27001 compliance, audits, certification activity, and ongoing security maturity improvements.
  • Conduct cyber risk, control, and security maturity assessments using NIST and CIS Controls frameworks.
  • Support the integration of newly acquired businesses into the Group’s cyber governance and security frameworks.
  • Maintain information security policies, procedures, and the Group Cyber Incident Response Plan while producing assurance reports for senior stakeholders.

Requirements

  • Strong practical experience in cybersecurity governance, risk, and compliance.
  • Good knowledge of ISO 27001, including supporting or leading audits and certification activity.
  • Practical experience with NIST and CIS security frameworks.
  • Experience conducting cyber risk assessments, control assessments, security maturity reviews, and managing technology risk registers.
  • Experience coordinating internal or external security audits and managing audit readiness.
  • Strong stakeholder management skills, with the ability to communicate technical security risks clearly to technical and non-technical audiences.

Culture & Benefits

  • Work across a diverse portfolio of subsidiary businesses in a stable and growing organisation.
  • Influence group-wide cybersecurity standards and support the continued maturity of the security environment.
  • Collaborate with IT, infrastructure, architecture, legal, privacy, business, and subsidiary teams.
  • Remote working arrangement with some travel required.
  • Car allowance and employment package included.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →