Senior Cyber GRC Specialist – Technical Controls

air-recruitment

Greater London

Hybrid

GBP 108,000 - 132,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Job summary

air-recruitment is seeking a Senior Cyber GRC Specialist – Technical Controls for a London-based hybrid role with a leading global investment manager. You will bridge governance, risk and compliance with hands-on security controls across networks, OS, cloud, IAM and Secure DevOps.

The role requires deep knowledge of NIST and ISO 27001, experience in regulated finance, and the ability to translate cyber risks into business impact.

Qualifications

  • Extensive experience in cybersecurity governance, risk and compliance.
  • Solid technical background in cyber engineering and security controls.
  • Knowledge of NIST and ISO 27001 frameworks.
  • Experience in financial services or regulated environments.
  • Understanding of FCA requirements and DORA.
  • Ability to translate cyber risks into business impact and regulatory implications.

Responsibilities

  • Develop and maintain cybersecurity policies, standards and procedures
  • Ensure security policies align with regulatory requirements and recognised industry frameworks
  • Integrate effective security practices and controls across technical and non-technical departments
  • Conduct cyber risk assessments to identify vulnerabilities and emerging threats
  • Help develop, implement and monitor appropriate risk-mitigation strategies
  • Design and evaluate control metrics to assess the effectiveness of cybersecurity measures
  • Embed cyber risk within wider enterprise risk registers and board-level reporting
  • Monitor compliance with internal policies, regulatory requirements and industry standards
  • Produce clear compliance reports and updates for senior management
  • Monitor regulatory developments and create appropriate compliance roadmaps
  • Support cybersecurity awareness and training across the organisation
  • Participate in incident response and post-incident reviews
  • Help develop and implement corrective measures following security incidents
  • Provide credible cybersecurity guidance to stakeholders across the business

Skills

Cyber GRC
Regulatory compliance
NIST
ISO 27001
Cloud security
IAM
Secure DevOps
Stakeholder management
Risk assessment

Job description

Senior Cyber GRC Specialist – Technical Controls

London / Hybrid

Up to £120,000

Are you an experienced Cyber GRC professional with a genuinely strong understanding of cyber engineering and technical security controls?

We’re working with a major global investment management organisation looking for a Senior Cyber GRC Specialist.

This is not a purely policy, audit or compliance-focused position. To be considered, you must combine substantial Cyber GRC experience with the technical knowledge to understand and challenge controls across networks, operating systems, cloud security, IAM and Secure DevOps.

You may have started your career in cyber engineering, infrastructure security, security operations or cloud security before moving into GRC, cyber risk or controls. Alternatively, you may already be working in a technically focused Cyber GRC position within financial services or another highly regulated organisation.

This is a highly visible opportunity to help strengthen cybersecurity governance, risk management and regulatory compliance across a complex international business.

THE ROLE
  • * Develop and maintain comprehensive cybersecurity policies, standards and procedures
  • * Ensure security policies align with regulatory requirements and recognised industry frameworks
  • * Integrate effective security practices and controls across technical and non-technical departments
  • * Conduct cyber risk assessments to identify vulnerabilities and emerging threats
  • * Help develop, implement and monitor appropriate risk-mitigation strategies
  • * Design and evaluate control metrics to assess the effectiveness of cybersecurity measures
  • * Embed cyber risk within wider enterprise risk registers and board-level reporting
  • * Monitor compliance with internal policies, regulatory requirements and industry standards
  • * Produce clear compliance reports and updates for senior management
  • * Monitor regulatory developments and create appropriate compliance roadmaps
  • * Support cybersecurity awareness and training across the organisation
  • * Participate in incident response and post-incident reviews
  • * Help develop and implement corrective measures following security incidents
  • * Provide credible cybersecurity guidance to stakeholders across the business
ABOUT YOU

You’ll need:

  • * Strong professional experience across cybersecurity governance, risk and compliance
  • * A solid technical cybersecurity or cyber engineering background
  • * Deep knowledge of cybersecurity principles and recognised frameworks, including NIST and ISO 27001
  • * Experience within financial services or another highly regulated environment
  • * Knowledge of relevant financial-services regulations, ideally including FCA requirements and DORA
  • * Strong understanding of network security principles and controls, including firewalls, IDS/IPS, TCP/IP, DHCP and DNS
  • * Experience of security across Windows, UNIX/Linux and ideally Mac environments
  • * Knowledge of operating-system access rights, secure configuration and security best practice
  • * Strong understanding of cloud security across IaaS, PaaS and SaaS environments
  • * Knowledge of public, private and hybrid cloud deployment models
  • * A thorough understanding of IAM, SSO, MFA and role-based access control
  • * Understanding of Secure DevOps and CI/CD pipeline governance
  • * The ability to translate technical cyber risks into clear business and regulatory implications
  • * Strong stakeholder-management skills, with the credibility to work across Technology, Risk, Legal, Compliance, Audit and senior leadership

A CISSP or similar recognised cybersecurity qualification would be highly beneficial.

This position would suit a Cyber GRC, Cyber Risk or Security Controls specialist who has retained strong technical knowledge—or a cybersecurity engineer who has developed substantial experience across governance, risk, controls and regulation.

If you combine strong Cyber GRC expertise with a genuine understanding of cyber engineering and technical security controls, we’d love to hear from you.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber GRC & Technical Controls Lead
Senior Cyber GRC & Technical Controls Lead

air-recruitment • Greater London

Hybrid
GBP 108,000 - 132,000
Senior Information Security (GRC) Specialist
Senior Information Security (GRC) Specialist

La Fosse • Greater London

Hybrid
GBP 81,000 - 99,000
Pension
Benefits
Governance, Risk & Compliance Lead
Governance, Risk & Compliance Lead

Elevation Recruitment Group • Leeds

Hybrid
GBP 50,000 - 60,000
Car Allowance
Bonus
Benefits
Head of Cyber GRC
Head of Cyber GRC

Cyber UK • United Kingdom

On-site
IT GRC Senior Analyst
IT GRC Senior Analyst

Nigel Wright Recruitment • Newcastle upon Tyne

Hybrid
GBP 70,000 - 90,000
Hybrid work policy
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
GRC Analyst - Cyber Security
GRC Analyst - Cyber Security

TEC Partners Limited • Enfield

On-site
GBP 50,000 - 60,000
Fully remote
Cyber GRC Controls SME
Cyber GRC Controls SME

Cyber UK • Greater London

Hybrid
GBP 111,000 - 148,000
Cyber Compliance Manager
Cyber Compliance Manager

Harvey Nash Group • Manchester

On-site
GBP 70,000 - 90,000
Information Security Specialist (GRC)
Information Security Specialist (GRC)

La Fosse Associates • Greater London

Hybrid
GBP 54,000 - 90,000
Pension