Enable job alerts via email!

Cyber Security Lead

TN United Kingdom

London

On-site

GBP 60,000 - 100,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a GRC Lead to ensure compliance with European regulations and global standards. This role demands a strategic thinker with over 5 years of experience in GRC, particularly within financial services. You will be responsible for managing third-party risk, implementing security governance frameworks, and conducting audits. Your expertise in IAM and vulnerability management will be crucial in safeguarding operational resilience and ensuring alignment with regulatory requirements. Join a forward-thinking company where your contributions will significantly impact operational security and compliance.

Benefits

Health Insurance
Retirement Plan
Flexible Working Hours
Professional Development Opportunities

Qualifications

  • 5+ years of experience in Governance, Risk, and Compliance roles.
  • Strong understanding of GDPR, DORA, and third-party risk requirements.

Responsibilities

  • Ensure compliance with GDPR and DORA, focusing on incident reporting.
  • Design and implement third-party risk management programs.

Skills

GRC Management
Regulatory Compliance (GDPR, DORA)
Third-Party Risk Management
Identity and Access Management (IAM)
Vulnerability Management
Audit Participation
Risk Quantification
Security Awareness Management

Education

Bachelor's Degree in a relevant field
Certifications (CRISC, CISSP, CISM, CISA)

Tools

Third-Party Risk Tools
ISO 27001 Implementation

Job description

Social network you want to login/join with:

Role Overview

As a GRC Lead, you will ensure alignment with European regulations (GDPR, DORA, PSD2 SCA, CSSF) and global standards (PCI DSS, SWIFT CSP). This role requires technical knowledge, strategic thinking, and expertise in managing third-party risk, outsourcing compliance, and identity governance to safeguard operational resilience.

What you will be doing:
Regulatory & Technical Compliance:
  • Support compliance with GDPR and regulations like DORA (Digital Operational Resilience Act), ensuring alignment in incident reporting and data protection.
  • Translate requirements from PSD2 SCA, PCI DSS, and SWIFT CSP into technical security controls.
  • Maintain IT security governance frameworks (ISO 27001, NIST CSF, CIS Controls).
  • Manage and maintain Security Policies and procedures.
Third-Party Risk & Outsourcing Management:
  • Design and implement third-party risk management programs to assess vendors, cloud providers, and outsourced services.
  • Ensure compliance with DORA’s outsourcing requirements, including due diligence, contract oversight, and continuity planning.
Audit & Assurance:
  • Participate in internal/external audits (ISO 27001, SOC 2) and regulatory examinations, focusing on third-party and outsourcing compliance.
  • Remediate gaps in processes or documentation.
Risk Management:
  • Maintain the enterprise risk register, prioritizing risks tied to third-party dependencies, outsourcing, and ICT disruptions.
  • Quantify risks using appropriate methodologies.
Technical Compliance & Security:
  • Advise on vulnerability management, endpoint security (EDR/XDR), and cloud compliance.
  • Have a good understanding of IAM (Identity and Access Management) strategies, including role-based access control (RBAC) and privileged access management (PAM).
  • Conduct periodic user access reviews to ensure compliance with least privilege principles and regulatory requirements.
  • Security awareness management experience.
What we are looking for:
  • Experience: 5+ years in GRC roles; financial services or banking experience is a strong plus.
  • Regulatory Knowledge: Understanding of GDPR, DORA, PCI DSS, and outsourcing/third-party risk requirements.
  • Technical Skills: Hands-on experience with ISO 27001 implementation and third-party risk tools.
  • Proficiency in IAM (Identity and Access Management) solutions and conducting user access reviews.
  • Familiarity with cloud technology and IT infrastructure.
  • Framework Expertise: Strong knowledge of NIST frameworks (CSF, 800-53) and CIS Controls.
  • Certifications: CRISC, CISSP, CISM, or CISA preferred (equivalent experience considered).
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.