Information Security Lead (GRC)

Enorth Resourcing Limited

Bedford

Hybrid

GBP 60,000 - 70,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Enorth Resourcing Limited is recruiting an Information Security Lead for a leading international SaaS software business. The role focuses on GRC, ISO 27001, security governance, risk management, and audits, with hands-on security experience.

You will work with the Head of Information Security to maintain and improve ISMS, support certification activities, and drive security improvements across technical teams.

Qualifications

  • Experience with ISO 27001, ISMS, Risk Management and Information Security governance.
  • Experience in internal, external and certification audits and remediation.
  • Strong knowledge of vulnerability management, penetration testing, patch management and incident response.
  • 5+ years across Information Security, Cyber Security, GRC, IT Risk or Security Assurance.
  • Ability to collaborate with Infrastructure, Networks, IT Operations and Software Engineering teams.

Responsibilities

  • Maintain and improve the organisation's Information Security, GRC and compliance environment.
  • Oversee ISO 27001, ISMS, security audits, risk assessments, policies and controls.
  • Coordinate with technical teams on vulnerability management, remediation and security improvements.
  • Communicate audit findings and controls with senior stakeholders and customers.

Skills

GRC & Governance
Security Audits
Cyber Security
Resilience & Compliance
ISO 27001

Job description

CYBER SECURITY LEAD / INFORMATION SECURITY LEAD

Bedford Hybrid - 1 Day a week Office

£60,000 - £70,000 + Excellent Benefits Permanent

PLEASE NOTE WE CANT ACCEPT ANY VISA APPLICATIONS, MUST BE 3YRS Plus in the UK Due to Security Clearance

GRC ISO 27001 ISMS Security Audits Risk Management Cyber Security Information Security Networks

Are you an experienced Information Security / Cyber Security professional with strong hands-on GRC, ISO 27001 and Security Audit experience, combined with a technical understanding of Cyber Security?

We're recruiting an Information Security Lead / Cyber Security Lead for a leading international SaaS software business, offering the opportunity to take greater ownership across Information Security, GRC, Security Governance, Risk, Compliance and Cyber Security.

Strong GRC and audit experience is essential. We're looking for someone who understands how to operate and improve an ISMS, support ISO 27001, manage security risk and controls, and work confidently across internal audits, external certification audits, customer assurance and supplier security.

Ideally, you'll have developed your career from an IT, Infrastructure, Network or technical Cyber Security background before moving into broader Information Security and GRC.

THE ROLE

You'll work closely with the Head of Information Security, helping maintain and continually improve the organisation's Information Security, GRC and compliance environment.

Your remit will include ISO 27001, ISMS, security audits, risk assessments, policies and controls, customer assurance, supplier security and audit remediation, alongside Cyber Essentials and wider certification activities.

You'll also work closely with technical teams across vulnerability management, patching, penetration testing, incident response, Business Continuity and Disaster Recovery, ensuring security risks and audit findings translate into practical improvements.

SKILLS & EXPERIENCE

We're particularly interested in strong experience across:

  • GRC & Security Governance: ISO 27001, ISMS, Risk Management, Security Policies, Controls, Compliance and Information Security Governance.
  • Security Audits & Assurance: Internal Audits, External Audits, Certification Audits, Audit Evidence, Remediation, Customer Assurance and Supplier Assurance.
  • Cyber Security: Vulnerability Management, Penetration Testing, Patch Management, Incident Response and Security Controls.
  • Resilience & Compliance: Cyber Essentials, Business Continuity, Disaster Recovery, DPIAs, BIAs and Third-Party Risk.

You'll ideally have 5+ years' experience across Information Security, Cyber Security, GRC, IT Risk, Compliance or Security Assurance.

You don't necessarily need to already be an Information Security Manager. We'd also like to hear from Information Security Leads, GRC Leads, Senior Information Security Analysts, Senior Cyber Security Analysts, Information Security Consultants, IT Risk & Compliance professionals and Security Engineers who have developed substantial GRC and audit experience.

THE BALANCE WE'RE LOOKING FOR

This is not a purely technical Security Engineering position.

The strongest candidates will bring genuine GRC, ISO 27001 and audit experience, but also enough technical understanding to work credibly with Infrastructure, Networks, IT Operations and Software Engineering teams.

You'll be equally comfortable discussing audit findings, risk and ISO 27001 controls with senior stakeholders as you are working with technical teams on vulnerabilities, remediation and security improvements.

A great opportunity to join a leading international SaaS software business and take broader ownership across Information Security, GRC, Audit and Cyber Security.

£60,000 - £70,000 + Excellent Benefits

Bedford Hybrid - 1 day a week Office

If you have strong GRC + ISO 27001 + Security Audit + Information Security experience, combined with a good technical security foundation, we'd like to hear from you.

KEY SKILLS: Information Security Lead, Cyber Security Lead, Information Security Manager, GRC, GRC Lead, Information Security, Cyber Security, ISO 27001, ISMS, Information Security Management System, Security Audit, Internal Audit, External Audit, Certification Audit, Security Governance, Risk Management, Compliance, Security Controls, Audit Remediation, Customer Assurance, Supplier Assurance, Third Party Risk, Cyber Essentials, Vulnerability Management, Penetration Testing, Incident Response, Business Continuity, Disaster Recovery, DPIA, BIA, Infrastructure Security, Network Security.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

Nuvion Tech • Bedford

On-site
GBP 80,000 - 110,000
Information Security Officer
Information Security Officer

Maxwell Bond • Reading

On-site
GBP 55,000 - 57,000
Lead GRC Consultant
Lead GRC Consultant

Cathcart Technology • City of Edinburgh

Hybrid
GBP 90,000 - 130,000
Bonus
Share scheme
Information Security Consultant
Information Security Consultant

Reed Technology • Horsham

On-site
GBP 45,000 - 55,000
Company car
Annual bonus
Private medical insurance
+3
GRC Lead
GRC Lead

Precise Placements • City Of London

On-site
GBP 65,000 - 95,000
Lead Information Security Analyst
Lead Information Security Analyst

Hovis Bakeries • Liverpool City Region

On-site
GBP 45,000 - 55,000
Lead GRC Consultant
Lead GRC Consultant

Cathcart Technology • Easter Howgate

Hybrid
GBP 70,000 - 110,000
Bonus
Share scheme
Information Security Officer
Information Security Officer

TyneStack Ltd • Newcastle upon Tyne

On-site
GBP 45,000 - 70,000
Hybrid working
Exposure to ISO 27001/NIST in cloud
Regulated financial tech environment
Governance, Risk & Compliance Lead
Governance, Risk & Compliance Lead

Elevation Recruitment Group • Leeds

On-site
GBP 50,000 - 60,000
Car Allowance
Bonus
Benefits
Information Security Manager/GRC Consultant
Information Security Manager/GRC Consultant

The Nippon Telegraph and Telephone Corporation (NTT) • Birmingham

Hybrid
GBP 60,000 - 90,000