Information Security GRC Specialist

Janus Henderson

Greater London

Hybrid

GBP 80,000 - 83,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid work environment

Job summary

Janus Henderson is seeking a cybersecurity leader in the United Kingdom with 3–5 years of information security experience. You will develop policies, oversee risk management, and ensure regulatory compliance across technology and business units in a hybrid work setting.

The role requires CISSP preference, deep knowledge of NIST/ISO 27001, cloud security, IAM, and Secure DevOps practices, with collaboration across Risk, Legal, Compliance, and IT teams.

Qualifications

  • Bachelor's degree in Information Technology, Cybersecurity, or related field, or equivalent work experience.
  • 3–5 years of professional information security experience.
  • CISSP certification strongly preferred.
  • Solid understanding of cybersecurity frameworks (NIST, ISO/IEC 27001) and compliance standards.
  • Experience with financial services regulations (FCA, SEC, MAS, DORA).
  • Proficient knowledge of network security principles (firewalls, IPS/IDP, TCP/IP, DHCP, DNS).
  • Experience securing Windows, UNIX/Linux, and Mac operating systems with proper access control.
  • Knowledge of cloud service models and deployment, with cloud security best practices.
  • In-depth knowledge of IAM (SSO, MFA, RBAC).
  • Understanding of Secure DevOps and CI/CD governance.

Responsibilities

  • Develop and maintain cybersecurity policies and procedures.
  • Ensure cybersecurity policies align with industry standards and regulatory requirements.
  • Integrate security practices across technical and non-technical departments.
  • Conduct regular risk assessments to identify vulnerabilities and threats.
  • Collaborate on and oversee risk mitigation strategies.
  • Monitor emerging threats and evolving technologies to refine risk protocols.
  • Design and evaluate control metrics for security effectiveness.
  • Embed cyber risk into risk registers and board-level reporting.
  • Monitor compliance with internal policies, standards, and regulatory requirements.
  • Engage with Technology, Legal, Compliance, and Internal Audit as required.
  • Deliver detailed compliance reports to senior management.
  • Monitor upcoming regulations and prepare compliance roadmaps.
  • Support and enhance cybersecurity awareness training programs.
  • Foster a company-wide culture of cybersecurity awareness.
  • Keep current with trends to inform training content and security measures.
  • Train wider tech teams on cybersecurity risk management.
  • Participate in incident response and post-incident evaluations.
  • Collaborate to strengthen defences against future incidents.
  • Maintain clear communication with stakeholders at all levels.
  • Provide expert guidance on cybersecurity best practices.
  • Work with Technology and other departments to achieve security objectives.

Skills

Cybersecurity concepts
Regulatory knowledge
Network security
Cloud security
IAM (SSO, MFA, RBAC)
Secure DevOps & CI/CD
Incident response
Stakeholder communication

Education

Bachelor's in IT/Cybersecurity or related field

Tools

CI/CD
Cloud
DevOps
IAM
Linux
Network
Security
RBAC

Job description

Salary: £80,000 - 83,000 per year

Requirements:
  • Bachelors degree in Information Technology, Cybersecurity, or a related field; equivalent work experience also considered.
  • 3 to 5 years of professional experience in information security.
  • Certification such as Certified Information Systems Security Professional (CISSP) strongly preferred.
  • Deep understanding of cybersecurity principles, frameworks such as NIST and ISO/IEC 27001, and compliance standards.
  • Experience with financial services regulations such as FCA, SEC, MAS, and DORA.
  • Proficient knowledge of network security principles and controls such as firewalls, IPS/IPD, TCP/IP, DHCP, and DNS.
  • Extensive experience securing operating systems such as Windows, UNIX/Linux, and Mac systems, including security access rights and configuration best practices.
  • Knowledge of cloud service models and deployment models, with experience implementing and managing cloud security best practices.
  • In-depth knowledge of IAM principles and technologies, including Single Sign-On, Multi-Factor Authentication, and role-based access control systems.
  • Understanding of Secure DevOps and CI/CD pipeline governance.
Responsibilities:
  • Develop and maintain comprehensive cybersecurity policies and procedures.
  • Ensure cybersecurity policies align with industry standards and regulatory requirements.
  • Integrate security practices and controls across technical and non-technical departments to enhance workflow and operational processes.
  • Conduct regular risk assessments to identify vulnerabilities and threats.
  • Collaborate on and oversee the implementation of risk mitigation strategies.
  • Monitor emerging threats and evolving technologies to refine risk assessment protocols.
  • Design and evaluate control metrics to assess the effectiveness of cybersecurity measures.
  • Collaborate with Enterprise Risk Management to embed cyber risk into broader risk registers and board-level reporting.
  • Monitor and ensure compliance with internal policies, industry standards, and regulatory requirements.
  • Engage with stakeholders in Technology, Legal, Compliance, and Internal Audit as required.
  • Compile and deliver detailed compliance reports to senior management.
  • Monitor upcoming regulations and prepare compliance roadmaps.
  • Support and enhance cybersecurity awareness training programs.
  • Foster a company-wide culture of cybersecurity awareness.
  • Keep current with the latest cybersecurity trends and best practices to inform training content and security measures.
  • Train and guide wider tech team members on best practices in cybersecurity risk management.
  • Actively participate in the response to security incidents.
  • Support post-incident evaluations and reporting.
  • Collaborate with relevant stakeholders to devise and enforce corrective measures to strengthen defences against future incidents.
  • Maintain clear and effective communication with stakeholders at all levels.
  • Provide expert guidance on cybersecurity best practices.
  • Work collaboratively with Technology and other departments to achieve comprehensive security objectives.
Technologies:
  • CI/CD
  • Cloud
  • DevOps
  • IAM
  • Support
  • Linux
  • Network
  • Security
  • TCP/IP
  • Unix
  • Windows
  • IaaS
  • Incident Management
  • PaaS
  • RBAC
More:

We are Janus Henderson, and our mission is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service. We are committed to protecting and growing our core business, amplifying our strengths, and diversifying where we have the right. Our values guide everything we do: Clients Come First, Execution Supersedes Intention, Together We Win, Diversity Improves Results, and Truth Builds Trust. We offer a hybrid working environment, support flexibility where possible, and are committed to an inclusive and supportive workplace where diversity is valued. We welcome applicants from all backgrounds and encourage candidates to apply even if they do not meet every requirement. Janus Henderson is an equal opportunity and affirmative action employer, and all applications are subject to background checks.

last updated 36 week of 2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Governance, Risk, and Compliance (GRC) Specialist
Information Security Governance, Risk, and Compliance (GRC) Specialist

Janus Henderson • Greater London

Hybrid
GBP 70,000 - 95,000
Information Security GRC Specialist
Information Security GRC Specialist

Morson Edge (Financial Services) • Greater London

Hybrid
GBP 90,000 - 120,000
Information Security Engineer
Information Security Engineer

AJ Bell • Greater London

Hybrid
GBP 50,000 - 90,000
Discretionary bonus
Pension (matched)
Private healthcare
+4
Information Security Governance, Risk and Compliance Specialist
Information Security Governance, Risk and Compliance Specialist

Global Web Index • Greater London

Hybrid
GBP 71,000 - 82,000
25 days annual leave
Health and wellbeing support
Pension matching 4%
+3
Information Security GRC Manager
Information Security GRC Manager

AJ Bell • Manchester

Hybrid
GBP 65,000 - 85,000
27 days’ holiday
Pension with matched contributions up to 8%
Discretionary bonus and share awards
+3
Assistant Manager – Information Security
Assistant Manager – Information Security

Jobtailor • Greater London

Hybrid
GBP 70,000 - 95,000
Principal Security Engineer
Principal Security Engineer

AJ BELL BUSINESS SOLUTIONS LIMITED • Trafford

Hybrid
GBP 45,000 - 49,000
Hybrid work model
Competitive salary
Pension scheme
+2
Senior Cyber GRC Specialist – Technical Controls
Senior Cyber GRC Specialist – Technical Controls

air-recruitment • Greater London

Hybrid
GBP 108,000 - 132,000
Cyber Operations & 3rd Party Security Manager
Cyber Operations & 3rd Party Security Manager

Arbuthnot Latham • Greater London

Hybrid
GBP 36,000 - 76,000
1 day per week work from home
Private healthcare cover
Pension via market-leading provider
+2
Information Security Officer
Information Security Officer

QinetiQ • Manchester

Hybrid
GBP 43,000 - 83,000
Performance bonus
Pension match
Health cover
+2