Governance, Risk & Compliance Lead

TRIA
United Kingdom
Today
Seniority
Lead
Posted
2 Oct 2026 (Today)

GRC / Cyber Compliance Lead

Remote - 1 day a month in either London or Manchester (fully expensed)

Competitive Salary & 20% Bonus & car allowance & private health

We're looking for an experienced GRC / Cyber Compliance Lead to join a growing Group Security function and build a new Governance, Risk and Compliance capability from the ground up.

This is an opportunity to take genuine ownership. Rather than stepping into an established GRC function and simply maintaining existing processes, you'll be responsible for defining how GRC operates across the organisation - establishing the controls framework, developing meaningful security metrics and risk reporting, strengthening compliance and assurance, and giving senior leadership and the Board a clear view of the organisation's security posture.

The role

Reporting to the Head of Cyber Security, Compliance and Risk Management, you will lead the development and ongoing operation of the Group's cyber GRC capability across multiple divisions, locations and business functions.

You'll build the foundations of a mature GRC function, including:

Designing and owning the Group's security controls framework and control library

Developing cyber risk methodology, risk assessment and treatment processes

Establishing meaningful KRIs, KPIs and security posture reporting for senior leadership and Board-level audiences

Developing governance processes around security policies, standards, exceptions, waivers and control ownership

Working with stakeholders across the business to improve control maturity and manage security risks

Leading the organisation's compliance and certification activities, including Cyber Essentials and Cyber Essentials Plus

Supporting the longer-term development towards ISO 27001

Managing relationships with internal and external auditors, certification bodies and independent assurance partners

Establishing robust control testing, evidence management and audit-readiness processes

Providing governance oversight of activities such as phishing testing and security awareness

Developing practical, pre-approved security responses and evidence that can be used by commercial and sales teams during tenders and bids

Providing security governance and assurance around key suppliers and third parties

Translating complex security and compliance issues into clear business risks, recommendations and actions

Challenging existing ways of working and driving pragmatic improvements across the organisationThis is a role where you'll need to be comfortable operating at both strategic and detailed levels - able to discuss security posture and risk with senior leadership while also getting into the detail of controls, evidence and remediation when required.

About you

We're looking for someone with proven cyber/information security GRC experience who can demonstrate what a good GRC function looks like and, importantly, has experience of building or significantly improving one.

You are likely to have experience across:

Cyber security / information security governance, risk and compliance

Designing or implementing security controls frameworks

Cyber and information security risk management

Security metrics, KRIs/KPIs and executive reporting

Internal and external audit and assurance

Control testing and evidence management

Cyber security policies, standards and governance frameworks

Cyber Essentials / Cyber Essentials Plus

ISO 27001 / ISMS, ideally including hands-on implementation or certification experience

NIST or other recognised security frameworks

Third-party / supplier security assurance

Security questionnaires, customer assurance or tender/RFP responsesWhat matters most is your ability to understand security risk, establish effective governance and make things happen.

We're looking for someone with the attitude and curiosity to build something, rather than someone who wants to work within a tightly defined specialist remit.

You'll need to be:

Pragmatic - able to deliver what is needed now while keeping sight of the longer-term direction

Curious and willing to challenge established thinking

Comfortable working with ambiguity and building structure where little currently exists

Commercially minded, understanding how good security can enable rather than restrict the business

Comfortable influencing senior stakeholders without relying on formal authority

Collaborative and willing to work across organisational boundaries

Confident enough to challenge the status quo and find practical solutions

Able to communicate complex security and risk matters clearly to both technical and non-technical audiencesThe organisation is deliberately building its security capability over the next few years, so this role offers significant scope to develop and grow. As the function matures, there is the potential for the role to develop into a broader leadership position with a team underneath it.

You'll be joining at a genuinely interesting point in the organisation's security journey. The foundations are being established, but there is still significant opportunity to shape the future operating model.

Your work will directly influence how the organisation understands and manages cyber risk, how security is reported to the Board, how confidently it can demonstrate its security posture to customers, and ultimately how security can become an enabler of new commercial opportunities.

Candidates will need to be Security Clearable.

If you're an experienced cyber GRC professional who enjoys building, improving and challenging rather than simply maintaining, this is an opportunity to make a significant impact

Related Jobs

View all jobs

Governance, Risk Compliance Lead

Infosec London, United Kingdom
£80,000 – £90,000 pa

Financial Crime Architecture Lead

Hydrogen Group London, United Kingdom
£100,000 – £120,000 pa

Security Architect

Precise Placements Ec2A4Bd, United Kingdom
£100,000 – £140,000 pa

IT Security Manager

Headliners Recruitment Easthampstead, Berkshire, United Kingdom
£70,000 – £80,000 pa

GRC Consultant

Big Red Recruitment London, United Kingdom
£60,000 – £70,000 pa

Principal Architect – AI

Career poster London, United Kingdom

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.