Enable job alerts via email!

Governance Risk and Compliance Lead (GRC) - Cyber

Marlin Selection Recruitment

London

On-site

GBP 60,000 - 100,000

Full time

3 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Governance, Risk, and Compliance Lead to enhance their cybersecurity posture. This role offers the chance to work within a dynamic global InfoSec team, leading third-party risk assessments and compliance initiatives. You will have a direct impact on shaping security strategies and managing risks across a major financial institution. With opportunities for career progression and a collaborative culture, this position is perfect for those looking to make a significant impact in a fast-paced environment. Join a team where your expertise will be valued and your contributions will shape the future of cybersecurity.

Qualifications

  • 6+ years of experience in GRC within cybersecurity, ideally in financial services.
  • Proven capability in third-party risk management and compliance frameworks.
  • Excellent communication skills to translate technical concepts.

Responsibilities

  • Leading third-party risk assessments and improving vendor governance.
  • Owning client due diligence responses and ensuring compliance.
  • Developing enterprise-wide awareness training and educational campaigns.

Skills

Governance, Risk, and Compliance (GRC)
Third-party risk management
Regulatory compliance
Audit readiness
Communication skills

Education

Relevant certifications (CISA, CRISC, CISM, CISSP)

Tools

Ninjio
Venminder
CyberGRX
Upguard
Microsoft O365

Job description

Governance Risk and Compliance Lead (GRC) - Cyber

GRC Lead – Cybersecurity (Financial Services)

London | Competitive Package

We're partnering with a leading global financial services firm to appoint a Governance, Risk, and Compliance (GRC) Lead into their high-performing Information Security function. This is an exciting opportunity to join a fast-paced, globally recognised institution with a mature cyber programme and significant investment in its security posture.

As a trusted search partner, we’re looking for an experienced and strategic GRC professional who can bring deep subject matter expertise across third-party risk, regulatory compliance, audit readiness, and awareness training. You’ll play a pivotal role in helping the firm navigate the evolving threat landscape while maintaining compliance with complex global regulations.

The Opportunity

Sitting within a dynamic global InfoSec team, you’ll be responsible for:

  • Leading third-party risk assessments and driving continuous improvement of vendor governance processes.
  • Owning client due diligence responses, ensuring the business meets external compliance and assurance requirements.
  • Developing and delivering enterprise-wide awareness training, phishing simulations, and educational campaigns.
  • Advising technical teams and stakeholders on controls around access management, incident handling, BCP, SDLC, and data protection.
  • Supporting audits and regulatory engagements, including evidence gathering and remediation tracking.
  • Facilitating a governance programme around risk acceptances and policy exceptions.
  • Mentoring junior GRC professionals and driving internal knowledge sharing.

What We’re Looking For

We’re keen to speak with individuals who bring:

  • 6+ years of experience in GRC within cybersecurity, ideally in financial services or highly regulated environments.
  • Proven capability in third-party risk management, client due diligence, and compliance frameworks (e.g., NIST, ISO 27001, DORA, etc.).
  • Experience in managing audits and regulatory engagements across multiple jurisdictions.
  • Excellent communication skills – able to translate complex technical concepts to non-technical stakeholders.
  • A collaborative, proactive approach with the ability to thrive in a global, fast-moving organisation.
  • Bonus points if you hold certifications such as CISA, CRISC, CISM, CISSP or equivalent.

Tools You Might Use

Familiarity with platforms such as:

  • InfoSec training solutions (e.g., Ninjio)
  • Third-party risk platforms (e.g., Venminder, CyberGRX, Upguard)
  • Microsoft O365 suite

Why Apply?

This is a high-impact role offering direct visibility with senior stakeholders, the chance to shape security posture across a global organisation, and real opportunities for career progression. You’ll be supported by a collaborative team culture, continuous learning, and the ability to influence how cyber risk is managed across a major financial institution.

If you would like to discuss this role in confidence, reach out to Javed Hussain at 0208 142 3930 or javed.hussain@marlinselection.com

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Governance Risk and Compliance Lead (GRC) - Cyber

JR United Kingdom

London

On-site

GBP 70.000 - 110.000

7 days ago
Be an early applicant

Governance Risk and Compliance Lead (GRC) - Cyber

Marlin Selection Ltd

London

On-site

GBP 60.000 - 100.000

21 days ago