Enable job alerts via email!

Information Security GRC Specialist - 12 Months

Akkodis

City Of London

On-site

GBP 50,000 - 70,000

Full time

Yesterday
Be an early applicant

Job summary

A leading organisation in the UK is looking for an experienced Information Security GRC Specialist for a 12-month contract. The role involves developing cybersecurity policies, conducting risk assessments, and ensuring compliance with standards. Candidates should have 3–5 years of experience in Information Security/GRC and a strong technical background in infrastructure or cloud environments. This position requires you to work on site in London for 3 days a week.

Qualifications

  • At least 3–5 years’ experience in Information Security / GRC.
  • Hands-on technical foundation in networks, operating systems, or cloud environments.
  • Strong understanding of frameworks such as NIST and ISO/IEC 27001.

Responsibilities

  • Develop and maintain cybersecurity policies, procedures, and controls.
  • Conduct and support risk assessments, mitigation, and reporting.
  • Ensure compliance with regulatory and internal standards.
  • Partner with technology teams to integrate security across platforms and workflows.
  • Support incident response and post-incident reviews.

Skills

Information Security / GRC
Risk Management
Cybersecurity Policies
Security Governance
Cloud Environments

Education

CISSP or similar certification
Job description
Information Security GRC Specialist – 12m Contract

London, UK – 3 days on site non-negotiable

Inside IR35

12-month contract

Role Overview

We're looking for an experienced Information Security GRC Specialist to join a leading organisation undergoing major technology change.

This is a hands‑on role within a growing Information Security team helping to shape and embed GRC strategy across new systems, platforms, and processes.

You’ll play a key part in defining and implementing security governance, risk and compliance frameworks, ensuring alignment with industry standards and upcoming regulations. The role combines policy development, risk management, and compliance oversight with strong technical awareness across infrastructure and cloud environments.

Key Responsibilities
  • Develop and maintain cybersecurity policies, procedures, and controls
  • Conduct and support risk assessments, mitigation, and reporting
  • Ensure compliance with regulatory and internal standards
  • Partner with technology teams to integrate security across platforms and workflows
  • Support incident response and post‑incident reviews
  • Promote security awareness and best practice across the organisation
Essential Experience

You’ll have a technical background (infrastructure, systems, or cloud) and have transitioned into information security, giving you a strong understanding of how security integrates into technology delivery.

  • At least 3‑5 years’ experience in Information Security / GRC
  • Hands‑on technical foundation in networks, operating systems, or cloud environments
  • CISSP or similar certification preferred
  • Strong understanding of frameworks such as NIST and ISO/IEC 27001
  • Knowledge of regulatory environments (FCA, DORA, SEC, MAS)

Both Modis International Ltd and Modis Europe Ltd are Equal Opportunities Employers.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.