Advanced Resource Managers
GRC - Cyber Assurance and Risk Lead
Job Location
London, United Kingdom
Job Description
GRC - Cyber Assurance and Risk Lead Up to £750 a day Inside IR35 Must hold current SC Clearance 6-month Contract London – Hybrid – 2/3 days office-based A strategic and leadership role. You will be instrumental in shaping and driving security and risk programs to align with internal business objectives as well as industry good practice (including Secure by Design aligned to UK Government principles) and regulatory requirements (including GovAssure and NCSC Cyber Assurance Framework)" RESPONSIBILITIES Develop and execute GRC strategies that align with business objectives and inform appropriate supporting business processes Drive pragmatic and creative solutions to GRC challenges, applying agile methodologies to adapt to new regulations, compliance requirements and business change Advise on and foster continuous improvement and effectiveness of GRC processes, driving improved management information to better allow appropriate prioritisation and risk based decisions Lead initiatives that build a culture of accountability and responsibility across engagements Enhance governance processes and advise on how best to evidence alignment with regulatory requirements (such as NCSC CAF) and industry good practice (including Secure by Design) Providing security expertise across security standards and accreditations, measure and control the effectiveness of the security controls framework and maintain the Information Security Management System. Deriving and delivering documented Information Security Management Plans which incorporate Regulatory, Legal and Compliance in relation to applicable security policies. Standards and guidelines Assisting with the identification of identified risks and emerging cyber security vulnerabilities and threats. The subsequent analysis to quantify and lead risk mitigation plans Work with Service Management to ensure that partners and suppliers adhere to agreed standards, policies and verify/evidence appropriate compliance and security KPIs Work closely with 1st, 2nd and 3rd lines of defence on all matters relating to cyber security, information assurance, cyber risk, data privacy including regulatory and compliance considerations Lead the development and enhancement of governance, risk and compliance aligned to policy, standards an industry good practice Ensure that continuous assessment, identification, analysis and reporting of useful metrics to enable informed risk based decisions to be taken Develops and maintains Information Security Management practice and process to ensure certification to required industry standards (e.g., ISO 27001) within relevant geographic boundaries. Performs focused information risk assessments of existing or new services and technologies, alongside the Operational/Service Management team and technology subject matter experts. As required, will extend the assessment of existing and proposed services to third party suppliers, including the facilitation of IT Security checks during the supplier onboarding and contract lifecycle to ensure coherent approach to risk management Maintains strong working relationships with individuals and groups involved in managing information risk across the in-scope services and aligned suppliers / 3rd parties Chairs and co-ordinates Security Working Groups (SWG) and actively participates in supporting/governing forums EXPERIENCE AND QUALIFICATIONS REQUIRED Requires extensive knowledge of GRC frameworks, regulatory compliance obligations and a proactive approach to risk management Minimum of 10 years’ experience in a Governance, Risk and Compliance role, with at least 5 years in a leadership or managerial position Relevant certifications such as CISSP, CISM, CCSP, CISA, CRISC or equivalent experience Expertise and practical knowledge and understanding of industry security frameworks and guidance such as NIST 800-53, NCSC CAF GovAssure, NIST CSF, DORA and NCSC guidelines Good knowledge and understanding of Cyber Security domains, including; network and cloud security, security operations, vulnerability management, Third Party supplier Risk Management, application security, physical security. Good knowledge of networking (switching, routing, firewalls) A good understanding of security testing and vulnerability management is important (including pen testing/ITHC, CVSS/CVE) Experience working with security standards such as ISO 27001, 27002, 27017, 27108 etc
Location: London, GB
Posted Date: 1/30/2025
Location: London, GB
Posted Date: 1/30/2025
Contact Information
Contact | Human Resources Advanced Resource Managers |
---|