GRC Principal (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
GRC Principal (Cybersecurity): Providing leadership, compliance continuity, and strategic assurance for the Enterprise Security function with an accent on risk-led security and complex regulatory landscapes. Focus on streamlining the ISMS, managing NIS regulations, and translating technical risk into executive-level insights.
Location: Hybrid (Hub Based). Must be based in the UK (assigned to Bristol, Glasgow, or London hubs) with office attendance at least once a week.
Company
is an energy company on a mission to solve the climate crisis through its Plan Zero initiative.
What you will do
- Provide day-to-day leadership to the security GRC function, managing the GRC vision and people.
- Manage security risks within the corporate GRC framework and navigate a complex regulatory environment (NIS, GDPR).
- Drive the continuous improvement and simplification of the Information Security Management System (ISMS).
- Lead the design and delivery of compliance initiatives, including ISO 27001 certification and the Cybersecurity Assessment Framework.
- Translate technical risks into executive-level narratives and reports for Board-level stakeholders.
- Collaborate with Risk, Business Continuity, and DPO functions to ensure unified governance and cross-functional alignment.
Requirements
- Proven experience as a Security GRC or Risk Manager within UK regulated sectors (e.g., Utilities, Financial Services, or CNI).
- Deep understanding of NIS regulations, GDPR, Ofgem requirements, and the forthcoming Cyber Security and Resilience Bill.
- Practical experience operating within a Three Lines of Defence model.
- Strong executive presence with the ability to engage confidently with Board-level stakeholders.
- Must have the right to work in the UK; sponsorship is not available.
Nice to have
- Experience managing or restructuring security functions during organizational change or mergers and acquisitions.
- Experience managing risk within agile, cloud-native technology estates.
Culture & Benefits
- Competitive compensation with an on-target bonus of 15% and 9% Flex Pay for pensions or cash.
- Generous leave policy with 34 days of holiday (including bank holidays).
- Comprehensive health support: healthcare cash plan, private medical insurance, and life assurance.
- Green benefits: discounts on solar, smart thermostats, EV chargers, and low-emission car leasing.
- Inclusive culture with 8 Belonging Networks to support diversity and inclusion.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →