Information Security GRC Lead

RAC

Bradley Stoke

Hybrid

GBP 70,000 - 90,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Colleague Share Scheme
Car salary sacrifice scheme (EV)
25 days annual leave
Pension up to 6.5% matched
Life assurance
24/7 confidential support
Orange Savings discounts

Job summary

RAC is seeking an experienced Information Security GRC Operations Lead to own the Governance, Risk and Compliance function. You will shape how security is embedded across the organisation and drive the human security risk programme, phishing simulations and security awareness initiatives.

You will design and operate the ISMS, risk management framework, policy governance processes and audits, while supporting ISO27001 readiness and supplier assurance in a hybrid working model from Bradley Stoke

Qualifications

  • Experience leading Information Security Governance, Risk and Compliance (GRC) programmes in complex environments.
  • Strong expertise with ISO27001, ISMS, risk management, audit delivery and supplier assurance.
  • Experience designing and running human security risk or security awareness programmes.
  • Good understanding of FCA, PRA or similarly regulated environments.

Responsibilities

  • Lead the design, operation and continuous improvement of the RAC's GRC framework.
  • Own and develop the ISMS, ensuring ISO27001 readiness, audits and continual improvement.
  • Design and manage the security risk management programme.
  • Operate and improve the human security risk programme including phishing simulations and training.
  • Lead internal and external audits, coordinate evidence and manage findings.
  • Oversee the security policy framework and ensure relevance and effectiveness.
  • Embed security requirements into supplier onboarding and due diligence.
  • Deliver supplier assurance and customer security questionnaires.
  • Identify opportunities to leverage automation and AI to improve reporting across GRC activities.

Skills

GRC governance
ISO27001
ISMS management
Risk management
Audit delivery
Policy governance
Supplier assurance
Security awareness
Phishing simulations
Behavioral risk

Education

CISSP/CISM/CISA

Job description

We're looking for an experienced Information Security GRC Operations Lead to join our Information Security team on a permanent basis.

This is an opportunity to take ownership of the RAC's Information Security Governance, Risk and Compliance (GRC) function, shaping how security is embedded across the organisation and enabling us to move forward with confidence while protecting our members, colleagues and services.

A key part of the role will be leading and continuously enhancing our Human Security Risk Programme, helping to strengthen security culture across the business through phishing simulations, security awareness initiatives and behavioural risk monitoring.

You’ll also lead the design and day-to-day operation of our Information Security Management System, risk management framework, audit programme, policy governance processes, drive ISO27001 certification activities and ensure security risks are understood, managed and reduced.

This is a highly visible role where you’ll drive continuous improvement across our governance, risk and compliance activities, ensuring the RAC has the visibility, assurance and controls needed to confidently manage security risk.

This is a hybrid role, working 2 days a week from our Bradley Stoke office and 3 days a week from home offering flexibility while being part of a dynamic and supportive team.

We offer more than a job. We offer a career with purpose.
As an Information Security GRC Operations Lead at RAC, you’ll get benefits that go the extra mile
  • Earnings That Motivate - enjoy a competitive salary plus automatic enrolment in our ‘Owning It Together’ Colleague Share Scheme - a unique opportunity to share in RAC’s future success and be rewarded for the exceptional work you deliver.
  • Tools to Drive Your Future - get started with a free RAC Ultimate Complete Breakdown Service from day one, plus access to a car salary sacrifice scheme (including electric vehicle options) after 12 months, delivering serious tax savings.
  • Time Off That Matters - enjoy 25 days annual leave, plus bank holidays. We also support work-life balance with paid family leave, flexible schedules, and practical resources to help navigate personal commitments.
  • Financial Security & Perks -pension scheme with up to 6.5% matched contributions alongside life assurance cover up to 4x salary (10x optional with flex benefits), designed to support you long-term.
  • Wellbeing That Works for You - our 24/7 confidential support service is available to you and household members aged 16+, offering reassurance whenever you need it.
  • Extras That Make a Difference - access Orange Savings, our exclusive discount portal with deals across top retailers, holidays, tools, tech and more. After passing probation, you’ll automatically join our Colleague Share Scheme, giving you a stake in our collective success.
What You’ll Do
  • Lead the design, operation and continuous improvement of the RAC's Information Security Governance, Risk and Compliance (GRC) framework.
  • Own and develop the Information Security Management System (ISMS), ensuring ongoing ISO27001 readiness, successful audits and continual improvement.
  • Design and manage the security risk management programme.
  • Operate and continuously improve the human security risk programme - including phishing simulation, security awareness, and behavioural risk monitoring - translating data from platforms such as CultureAI into measurable risk reduction and executive reporting.
  • Lead internal and external audits, coordinating evidence, managing findings and working with auditors, regulators and stakeholders.
  • Oversee the security policy framework, ensuring policies remain relevant and effective.
  • Drive the human security risk programme, including security awareness, phishing simulations and behavioural risk monitoring.
  • Act as the primary Information Security contact for PCI compliance, leading annual compliance activities and external engagement.
  • Embed security requirements into supplier onboarding, due diligence, contract reviews and renewal processes.
  • Deliver supplier assurance and customer security questionnaires.
  • Identify opportunities to leverage automation and AI to improve efficiency, consistency and reporting across GRC activities.
What You’ll Need
  • Proven experience leading Information Security Governance, Risk and Compliance programmes within a complex environment.
  • Strong hands-on expertise with ISO27001, ISMS management, risk management, audit delivery, policy governance and supplier assurance.
  • Experience designing and running human security risk or security awareness programmes.
  • A solid understanding of regulatory and operational resilience requirements, ideally within FCA, PRA or similarly regulated environments.
  • Relevant security qualifications such as CISSP, CISM, CISA or equivalent, alongside excellent stakeholder management and decision‑making skills.
Why RAC?

For more than 128 years, we’ve been keeping drivers moving, and today we’re trusted by over 15 million members. We’re also trusted by our people, with a 4.5‑star Glassdoor rating showing that RAC is a place where support, ambition, and opportunity go hand in hand.

We welcome people from every background, value every voice, and back your growth every step of the way. At the RAC, you can bring your full self to work and we’ll be with you every step of the way to help you grow and develop your career.

Ready to make a difference? Your next career move starts here.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security GRC Lead
Information Security GRC Lead

RAC • West of England

On-site
GBP 70,000 - 95,000
Colleague Share Scheme (Owning It.Tog)
RAC Ultimate Breakdown Service
Car salary sacrifice scheme
+7
Information Security GRC Lead: ISMS & Risk Champion
Information Security GRC Lead: ISMS & Risk Champion

RAC • West of England

Hybrid
GBP 70,000 - 95,000
Colleague Share Scheme (Owning It.Tog)
RAC Ultimate Breakdown Service
Car salary sacrifice scheme
+7
Mid Backend Software Engineer
Mid Backend Software Engineer

RAC • West of England

Hybrid
GBP 50,000 - 75,000
Colleague Share Scheme
Car salary sacrifice
25 days leave
+4
Engineering Manager
Engineering Manager

RAC • West of England

On-site
GBP 90,000 - 135,000
Mid Frontend Software Engineer
Mid Frontend Software Engineer

RAC • West of England

Hybrid
GBP 45,000 - 65,000
Pension scheme with up to 6.5% matched
Life assurance up to 4x salary
24/7 confidential support
+4
Senior GRC / Security Assurance Officer
Senior GRC / Security Assurance Officer

Rowden • West of England

Hybrid
GBP 60,000 - 80,000
Information Security GRC Manager
Information Security GRC Manager

AJ Bell • Manchester

Hybrid
GBP 65,000 - 85,000
27 days’ holiday
Pension with matched contributions up to 8%
Discretionary bonus and share awards
+3
Legal Advisor
Legal Advisor

RAC • West of England

On-site
GBP 25,000 - 31,000
25 days annual leave
Pension scheme
Car salary sacrifice scheme
+1
Security Governance Risk & Compliance Officer
Security Governance Risk & Compliance Officer

Rowden • Bristol

Hybrid
GBP 50,000 - 60,000
Legal Advisor
Legal Advisor

RAC • Bradley Stoke

On-site
GBP 24,000 - 28,000
Owning It Together Share Scheme
Free RAC Breakdown cover
Car salary sacrifice scheme
+4