Governance, Risk & Compliance Lead

Tria

Greater London, Manchester

Remote

GBP 90,000 - 120,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

20% Bonus
Car allowance
Private health
Remote work

Job summary

Tria is seeking an experienced GRC / Cyber Compliance Lead to build a new Group GRC capability. You will define the controls framework, risk reporting, and governance, reporting to Cyber Security leadership and the Board.

Key duties include establishing a mature GRC function, leading Cyber Essentials initiatives, and guiding audits and supplier assurance while enabling business growth and commercial opportunities.

Qualifications

  • Experience in cyber information security GRC across large organisations.
  • Capability to design or improve a GRC function from scratch.
  • Knowledge of Cyber Essentials and ISO 27001 is beneficial.
  • Ability to translate risk into board-level insights.

Responsibilities

  • Design and own the Group's governance, risk and compliance framework.
  • Develop cyber risk methodologies, assessment and treatment processes.
  • Create KRIs, KPIs and security posture reporting for leadership.
  • Lead governance around policies, standards, exceptions and ownership.
  • Coordinate internal/external audits and assurance activities.
  • Engage with suppliers and manage third-party security assurance.

Skills

GRC governance
Cyber risk management
Compliance frameworks
Security metrics & reporting
Audits & assurance
Stakeholder engagement
ISO 27001 / NIST

Job description

GRC / Cyber Compliance Lead

Remote - 1 day a month in either London or Manchester (fully expensed)

Competitive Salary & 20% Bonus & car allowance & private health

We're looking for an experienced GRC / Cyber Compliance Lead to join a growing Group Security function and build a new Governance, Risk and Compliance capability from the ground up.

This is an opportunity to take genuine ownership. Rather than stepping into an established GRC function and simply maintaining existing processes, you'll be responsible for defining how GRC operates across the organisation - establishing the controls framework, developing meaningful security metrics and risk reporting, strengthening compliance and assurance, and giving senior leadership and the Board a clear view of the organisation's security posture.

The role

Reporting to the Head of Cyber Security, Compliance and Risk Management, you will lead the development and ongoing operation of the Group's cyber GRC capability across multiple divisions, locations and business functions.

You'll build the foundations of a mature GRC function, including:

  • Designing and owning the Group's security controls framework and control library
  • Developing cyber risk methodology, risk assessment and treatment processes
  • Establishing meaningful KRIs, KPIs and security posture reporting for senior leadership and Board-level audiences
  • Developing governance processes around security policies, standards, exceptions, waivers and control ownership
  • Working with stakeholders across the business to improve control maturity and manage security risks
  • Leading the organisation's compliance and certification activities, including Cyber Essentials and Cyber Essentials Plus
  • Supporting the longer-term development towards ISO 27001
  • Managing relationships with internal and external auditors, certification bodies and independent assurance partners
  • Establishing robust control testing, evidence management and audit-readiness processes
  • Providing governance oversight of activities such as phishing testing and security awareness
  • Developing practical, pre-approved security responses and evidence that can be used by commercial and sales teams during tenders and bids
  • Providing security governance and assurance around key suppliers and third parties
  • Translating complex security and compliance issues into clear business risks, recommendations and actions
  • Challenging existing ways of working and driving pragmatic improvements across the organisation

This is a role where you'll need to be comfortable operating at both strategic and detailed levels - able to discuss security posture and risk with senior leadership while also getting into the detail of controls, evidence and remediation when required.

About you

We're looking for someone with proven cyber/information security GRC experience who can demonstrate what a good GRC function looks like and, importantly, has experience of building or significantly improving one.

You are likely to have experience across:

  • Cyber security / information security governance, risk and compliance
  • Designing or implementing security controls frameworks
  • Cyber and information security risk management
  • Security metrics, KRIs/KPIs and executive reporting
  • Internal and external audit and assurance
  • Control testing and evidence management
  • Cyber security policies, standards and governance frameworks
  • Cyber Essentials / Cyber Essentials Plus
  • ISO 27001 / ISMS, ideally including hands-on implementation or certification experience
  • NIST or other recognised security frameworks
  • Third-party / supplier security assurance
  • Security questionnaires, customer assurance or tender/RFP responses

What matters most is your ability to understand security risk, establish effective governance and make things happen.

We're looking for someone with the attitude and curiosity to build something, rather than someone who wants to work within a tightly defined specialist remit.

You'll need to be:

  • Pragmatic - able to deliver what is needed now while keeping sight of the longer-term direction
  • Curious and willing to challenge established thinking
  • Comfortable working with ambiguity and building structure where little currently exists
  • Commercially minded, understanding how good security can enable rather than restrict the business
  • Comfortable influencing senior stakeholders without relying on formal authority
  • Collaborative and willing to work across organisational boundaries
  • Confident enough to challenge the status quo and find practical solutions
  • Able to communicate complex security and risk matters clearly to both technical and non-technical audiences

The organisation is deliberately building its security capability over the next few years, so this role offers significant scope to develop and grow. As the function matures, there is the potential for the role to develop into a broader leadership position with a team underneath it.

You'll be joining at a genuinely interesting point in the organisation's security journey. The foundations are being established, but there is still significant opportunity to shape the future operating model.

Your work will directly influence how the organisation understands and manages cyber risk, how security is reported to the Board, how confidently it can demonstrate its security posture to customers, and ultimately how security can become an enabler of new commercial opportunities.

Candidates will need to be Security Clearable.

If you're an experienced cyber GRC professional who enjoys building, improving and challenging rather than simply maintaining, this is an opportunity to make a significant impact

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Governance, Risk & Compliance Lead
Governance, Risk & Compliance Lead

Elevation Recruitment Group • Leeds

On-site
GBP 50,000 - 60,000
Car Allowance
Bonus
Benefits
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
Lead GRC Consultant
Lead GRC Consultant

Cathcart Technology • Easter Howgate

Hybrid
GBP 70,000 - 110,000
Bonus
Share scheme
Cyber Compliance Manager
Cyber Compliance Manager

Harvey Nash Group • Manchester

On-site
GBP 70,000 - 90,000
IT GRC Senior Analyst
IT GRC Senior Analyst

Nigel Wright Recruitment • Newcastle upon Tyne

Hybrid
GBP 70,000 - 90,000
Hybrid work policy
GRC Security Specialist
GRC Security Specialist

Remote Worker LTD. • Greater London

Hybrid
GBP 70,000 - 100,000
Senior Cyber GRC Specialist – Technical Controls
Senior Cyber GRC Specialist – Technical Controls

air-recruitment • Greater London

On-site
GBP 108,000 - 132,000
GRC Analyst - Cyber Security
GRC Analyst - Cyber Security

TEC Partners Limited • Enfield

On-site
GBP 50,000 - 60,000
Fully remote
GRC Consultant
GRC Consultant

Big Red Recruitment • City Of London

Hybrid
GBP 59,000 - 72,000
Bonus & Benefits
Hybrid work (1 day per week in Central
Risk Management Officer
Risk Management Officer

Propel • Greater London

Hybrid
GBP 90,000 - 120,000
Market-leading compensation
Share options
Private healthcare
+3