Head of Information Security GRC & Awareness

TRIA

England

On-site

GBP 165,000 - 344,000

Part time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

A consultancy firm in the United Kingdom is looking for a Head of Information Security GRC & Awareness. This pivotal role involves leading governance, risk, compliance, and security awareness within the organization. Responsibilities include policy development, risk management, and enhancing the security posture. Ideal candidates will have relevant certifications and extensive experience in complex environments. This role offers a six-month contract inside IR35 with a competitive rate, presenting an opportunity to influence security practices significantly.

Qualifications

  • Extensive experience in information security or IT governance.
  • Strong knowledge of security frameworks.
  • Proven track record in risk management and policy development.

Responsibilities

  • Lead the development and enforcement of information security policies.
  • Drive security governance and cyber maturity.
  • Oversee Information Security Risk Management process.
  • Conduct supplier due diligence and audit readiness.
  • Own and deliver the security awareness programme.
  • Own and deliver the security awareness programme and campaigns.
  • Possibly develop OT Security Assurance Framework depending on candidate.

Skills

CISSP
CISM
ISO27001 Lead Auditor
Risk management
Policy development
Communication skills
Leadership
Third-party due diligence

Education

CISSP/CISM/ISO27001 Lead Auditor

Tools

ISO/IEC 27001
NIST CSF
CIS Controls
Cyber Essentials

Job description

Head of Information Security GRC & Awareness

We are seeking an experienced Head of InfoSec GRC & Awareness to lead governance, risk, compliance, and security awareness initiatives across an organisation at a time of significant modernisation. This pivotal role ensures a robust security posture by developing and enforcing policies, standards, and training programmes aligned with business objectives and regulatory requirements.

Duration: 6 months. Rate: Inside IR35, rate to be discussed.

Key Responsibilities
  • Lead the development and enforcement of enterprise-wide information security policies and standards.
  • Drive security governance and cyber maturity through compliance, assurance reviews, and gap analysis.
  • Oversee the Information Security Risk Management process.
  • Conduct in‑depth supplier due diligence / third‑party assurance processes.
  • Manage audit readiness and support internal/external audit activities.
  • Own and deliver the organisation’s security awareness programme, including campaigns and tailored training.
  • Depending on the candidate, also develop and implement an Operational Technology (OT) Security Assurance Framework.
Candidate Profile
  • Professional certifications such as CISSP, CISM, ISO27001 Lead Auditor, CLAS, etc.
  • Extensive experience in information security or IT governance within large, complex environments.
  • Strong knowledge of security frameworks (ISO/IEC 27001, NIST CSF, CIS Controls, Cyber Essentials).
  • Proven track record in risk management, policy development, and security awareness initiatives.
  • Excellent communication, leadership, and influencing skills.
  • Very strong experience of driving 3rd‑party due diligence.
  • Experience in Technical Assurance, OT Security Assurance and Penetration Testing is a bonus.

This is an excellent opportunity to lead a critical function within a dynamic organisation, ensuring security resilience and cultural change across the enterprise.

For further information, please apply and I will be in touch.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Specialist (GRC)
Information Security Specialist (GRC)

La Fosse Associates • Greater London

Hybrid
GBP 54,000 - 90,000
Pension
Information Security GRC Specialist
Information Security GRC Specialist

Morson Edge (Financial Services) • Greater London

Hybrid
GBP 90,000 - 120,000
InfoSec GRC & Awareness Leader
InfoSec GRC & Awareness Leader

TRIA • England

On-site
GBP 165,000 - 344,000
Information Security Manager
Information Security Manager

Nuvion Tech • Bedford

Hybrid
GBP 80,000 - 110,000
ICT Cyber and Information Security Manager
ICT Cyber and Information Security Manager

ISR RECRUITMENT LIMITED • North East

On-site
GBP 80,000 - 100,000
Head of Information and Cyber Security
Head of Information and Cyber Security

Anderson Quigley • Greater London

On-site
GBP 90,000 - 120,000
IT Security Manager
IT Security Manager

Onyx-Conseil • Greater London

Hybrid
GBP 75,000 - 85,000
IT Information Security Analyst - Compliance
IT Information Security Analyst - Compliance

Adecco • West Midlands

Hybrid
GBP 45,000 - 55,000
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
Head of Cyber GRC
Head of Cyber GRC

Cyber UK • United Kingdom

On-site