Strategic Information Security Risk & GRC Lead

twentyAI

England

On-site

GBP 70,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

twentyAI is seeking an information security risk lead to own a broad risk area, engaging with senior stakeholders across the business to ensure risk is understood, assessed, and managed proportionately.

You will influence governance, policy, audits, and resilience, translating technical alerts into business-focused recommendations while maintaining autonomy and a visible presence at board level.

Qualifications

  • Strong experience in information security risk, GRC, or second line security.
  • Ability to engage senior stakeholders and challenge constructively.
  • Calm, measured approach to cut through noise.
  • Autonomous, taking ownership without close management.
  • Strong business-focused communication on security risks.
  • Experience in risk, policy, audit, controls, governance, or related disciplines.
  • CISSP and broader GRC qualifications are helpful.

Responsibilities

  • Lead from a second line / GRC perspective focusing on risk, policy, control effectiveness, governance, and regulatory alignment.
  • Assess security issues in terms of business impact, risk appetite, and resilience.
  • Collaborate with heads of department and senior leadership.
  • Translate incidents and vendor alerts into clear, business-oriented recommendations.
  • Support risk assessments, audits, policy and procedure development, and operational resilience.
  • Contribute to a small team with board and executive exposure.

Skills

InfoSec risk
GRC
Stakeholder mgmt
Policy development
Governance
Audit
Third-party risk
Operational resilience
Calm demeanor
Business risk language

Education

CISSP or equivalent

Job description

twentyAI is seeking an information security risk lead to own a broad risk area, engaging with senior stakeholders across the business to ensure risk is understood, assessed, and managed proportionately.

You will influence governance, policy, audits, and resilience, translating technical alerts into business-focused recommendations while maintaining autonomy and a visible presence at board level.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
Senior GRC Analyst - AI-Driven Risk & Compliance
Senior GRC Analyst - AI-Driven Risk & Compliance

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
GRC Manager, Security & Compliance
GRC Manager, Security & Compliance

Artificial • United Kingdom

On-site
GBP 70,000 - 110,000
Private medical insurance
Income protection insurance
Life insurance of 4 × base salary
+1
GRC Lead for AI-Driven Insurtech (Hybrid)
GRC Lead for AI-Driven Insurtech (Hybrid)

Artificial Labs Ltd • Greater London

Hybrid
GBP 90,000 - 130,000
Private medical insurance
Income protection insurance
Life insurance of 4 * base salary
+4
Information Security Governance & Risk Analyst
Information Security Governance & Risk Analyst

Made4Tech Global • Greater Manchester

On-site
GBP 50,000 - 75,000
Information Security GRC Lead: ISMS & Risk Champion
Information Security GRC Lead: ISMS & Risk Champion

RAC • West of England

Hybrid
GBP 70,000 - 95,000
Colleague Share Scheme (Owning It.Tog)
RAC Ultimate Breakdown Service
Car salary sacrifice scheme
+7
Lead GRC Security Analyst: ISO 27001 & AI Risk
Lead GRC Security Analyst: ISO 27001 & AI Risk

Cirrus Logic • City of Edinburgh

Hybrid
GBP 90,000 - 130,000
Hybrid work
AI Security Risk Program Lead
AI Security Risk Program Lead

Meta • Greater London

Hybrid
GBP 90,000 - 130,000
Head of IT Risk
Head of IT Risk

Morson Edge (Financial Services) • Manchester

Hybrid
GBP 120,000 - 150,000
Cyber GRC Lead: Secure by Design & Risk Strategy
Cyber GRC Lead: Secure by Design & Risk Strategy

Citizens Advice • Wales

Hybrid
GBP 70,000 - 100,000