GRC Lead

Walkers Global

Greater London

On-site

GBP 90,000 - 130,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Walkers Global is seeking a Governance, Risk and Compliance Lead to oversee the firm’s ISMS across its global operations. The role includes policy development, risk management, audits and compliance, with senior management reporting across regions.

You will lead security capability improvements, coordinate change governance of projects, and liaise with internal teams to ensure robust security controls for clients in a fast‑moving, international environment.

Qualifications

  • Proven experience in assessing information security risk and developing an ISMS.
  • Experience of ISO 27001/2 version 2022.
  • Experience of risk frameworks such as ISO 27005/31000.
  • Knowledge of applicable data privacy practices and laws.
  • Demonstrable experience in a similar role.
  • ISO 27001 Lead Implementer / Lead Auditor certification or, extensive security audit experience
  • CISSP and CISM or equivalent certifications
  • Strong written, oral and presentation communication skills.
  • Excellent inter-personal skills and ability to present ideas and proposals in user-friendly language.
  • A passion for information security and keeping current on emerging technologies, regulations, threats and trends.
  • Highly self-motivated and directed, with a hands‑on approach.
  • Good technical-writing skills and the ability to prepare quality documentation, reports and training material.
  • Able to effectively prioritise tasks in a high‑pressure environment.
  • Experience working in geographically dispersed team‑oriented, collaborative environment.

Responsibilities

  • ISMS Management: Communicate risks and requirements to senior management.
  • Develop and maintain security compliance program.
  • Support local offices to update country-specific IS documentation.
  • Establish security metrics to assess effectiveness.
  • Coordinate and maintain the management review process.
  • Manage internal and external audits and certifications.
  • Manage third party providers including security consultants and assessors.
  • Ownership of the Security Awareness Program and Centre and support of Security Culture Change.
  • Manage identified improvements through to completion.
  • Develop, maintain and publish security strategies, policies and procedures.
  • Support global IT departments on implementation of security policy and products.

Skills

ISMS development
Risk assessment
Security governance
Policy development
Audits & certifications
Communication skills
Stakeholder management
Security awareness program
Technical security knowledge
Project management

Education

ISO 27001 Lead Implementer
CISSP
CISM
Lead Auditor Certification

Job description

We are a leading international law firm for global corporations, financial institutions, capital market participants and investment fund managers. With a global presence spanning the Americas, Europe, the Middle East and Asia, we advise on the laws of Bermuda, the British Virgin Islands, the Cayman Islands, Guernsey, Ireland and Jersey.

We treat everyone as the intelligent professional they are. Our approach is to trust and empower our people to deliver consistently, and enable them to succeed. Diversity is our secret weapon – it’s the sheer breadth of Walkers people that makes us who we are – gathered from across the globe and fluent in languages, jurisdictions and cultures that help us to mirror our clients and keep our own thinking in tune with the world in which we operate.

Overview of role

Office: London (40% min hybrid required)

The Governance, Risk, and Compliance Lead will be responsible for the management of the Information Security Management System (ISMS) across Walkers globally. This covers a broad range of information security activities including policy development, risk management, internal and external audit and compliance. It will involve communication with senior management across all regions, liaising with internal teams, and development of the firm’s security capabilities to meet the changing needs of clients. The role will be responsible for managing the change governance of projects through business change partnering.

Duties, Responsibilities & Person Specification
  • ISMS Management
    • Communicate to senior management on risks and requirements
    • Understand business objectives and support development of budget for information security objectives
    • Develop and maintain security compliance program
    • Provide support where necessary to local offices to update and maintain country specific IS documentation
    • Establish security metrics to assess effectiveness
    • Coordinate and maintain the management review process
    • Make written and oral reports to ISSC
  • Security Audits
    • Manage internal and external audits and certifications
    • Manage third party providers including security consultants and assessors
  • Security Awareness
    • Ownership of the Security Awareness Program and the Security Awareness Centre and support of Security Culture Change including owning and managing the quarterly phishing simulation campaigns and the third party relationship.
  • Improvement management
    • Manage identified improvements through to completion
  • Policy
    • Develop, maintain and publish security strategies, policies and procedures
    • Manage security policy and implementation
    • Support global IT departments on implementation of security policy and products
Education, Skills & Experience
  • Proven experience in assessing information security risk and developing an ISMS.
  • Experience of ISO 27001/2 version 2022.
  • Experience of risk frameworks such as ISO 27005/31000.
  • Knowledge of applicable data privacy practices and laws.
  • Demonstrable experience in a similar role.
  • ISO 27001 Lead Implementer / Lead Auditor certification or, extensive security audit experience
  • CISSP and CISM or equivalent certifications
  • Strong written, oral and presentation communication skills.
  • Excellent inter-personal skills and ability to present ideas and proposals in user-friendly language.
  • A passion for information security and keeping current on emerging technologies, regulations, threats and trends.
  • Highly self-motivated and directed, with a hands‑on approach.
  • Good technical‑writing skills and the ability to prepare quality documentation, reports and training material.
  • Able to effectively prioritise tasks in a high‑pressure environment.
  • Experience working in a geographically dispersed team‑oriented, collaborative environment.

Please note; this position requires the ability and willingness to occasionally work outside normal working hours/days when requested. Additionally, an understanding that international business travel may be necessary.

Walkers will not accept any applications received from agencies at this time. Only candidates selected for an interview will be contacted.

Walkers global is an equal opportunity employer. Equality and diversity are key to our global identity and an integral part of our goal to continue being an employer of choice. We are committed to a work environment that supports all individuals irrespective of gender, ethnicity, nationality, race, religion, marital status, age, disability, pregnancy, sexual orientation, gender identity or any other applicable legally protected characteristics. We make every effort to ensure that employment opportunities are open and accessible to all purely on the basis of personal ability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Lead
GRC Lead

Walkers • Greater London

On-site
GBP 85,000 - 110,000
GRC Lead — Hybrid London (ISMS & Security Governance)
GRC Lead — Hybrid London (ISMS & Security Governance)

Walkers Global • Greater London

Hybrid
GBP 90,000 - 130,000
Hybrid London GRC & ISMS Lead
Hybrid London GRC & ISMS Lead

Walkers • Greater London

Hybrid
GBP 85,000 - 110,000
Senior Associate - Insolvency & Dispute Resolution - London at Walkers
Senior Associate - Insolvency & Dispute Resolution - London at Walkers

Walkers • Greater London

On-site
GBP 90,000 - 130,000
Business Continuity Manager
Business Continuity Manager

Walkers Global • Greater London

Hybrid
GBP 80,000 - 110,000
Associate/Senior Associate - Corporate- London
Associate/Senior Associate - Corporate- London

Walkers • Greater London

On-site
GBP 60,000 - 90,000
Security Architect
Security Architect

Walkers • Greater London

Hybrid
GBP 110,000 - 160,000
Information Security Governance, Risk and Compliance Specialist
Information Security Governance, Risk and Compliance Specialist

GWI • Greater London

Hybrid
GBP 70,000 - 100,000
25 days annual leave
Health cash plan
4% pension matching
+6
Business Continuity Manager
Business Continuity Manager

Walkers • Greater London

Hybrid
GBP 90,000 - 130,000
Senior Network Engineer
Senior Network Engineer

Walkers • Greater London

On-site
GBP 70,000 - 110,000