Information Security GRC Risk Manager

Reed
N19Gu, N1 9GU, United Kingdom
3 days ago
£75,000 – £90,000 pa

Salary

£75,000 – £90,000 pa

Job Type
Permanent
Work Pattern
Full-time
Work Location
Hybrid
Seniority
Senior
Education
Degree
Posted
28 May 2026 (3 days ago)

Benefits

35 hours per week Plus benefits

Information Security GRC Risk Manager

North London (Hybrid – 3 days onsite)

Permanent | 35 hours per week

£ plus benefits

About the Role

We’re seeking an experiencedInformation Security GRC Risk Manager to take ownership of our client's growing security risk capability.

This is ahands-on risk practitioner role with senior leadership exposure, not a purely strategic GRC position. You willrun and mature an established risk framework, ensuring it is embedded effectively across the business while driving real outcomes.

Reporting to theInformation Security GRC Lead, you will own the risk function end-to-end, engaging senior stakeholders (including ExCo), challenging risk positions, and shaping how risk is understood and managed.

The GRC function is still evolving (2–3 years old), offering a unique opportunity tobuild, refine, and embed risk practices in a low-to-mid maturity environment.

Key Responsibilities

Risk Management & Governance

  • Own and operate the Information Security risk framework aligned to enterprise risk
  • Lead risk identification, assessment, and treatment across the organisation
  • Maintain and enhance the risk register and supporting artefacts
  • Facilitate workshops and validate risk positions and remediation plans
  • Drive risk-based decisions and escalate material risks to leadership
  • Identify emerging risks, includingAI/ML-related threats

Reporting & Insight

  • Deliver clear, concise reporting to senior stakeholders and ExCo
  • Define and track KPIs/KRIs to measure programme effectiveness
  • Highlight control weaknesses, systemic issues, and emerging threats

Stakeholder Leadership

  • Act as the key interface between Information Security and ERM
  • Influence and challenge senior stakeholders to own and manage risk
  • Provide expert guidance and support audits and assurance activity
  • Help educate the business and embed a strong risk culture

Policy Governance & Improvement

  • Own the Information Security policy framework
  • Ensure policies align to risk appetite and regulatory requirements
  • Drive adoption, governance, and continuous improvement
  • Support the ongoing maturity of a recently scaled GRC team

About You

  • Proven experience inInformation Security risk management
  • Hands-on experienceowning and running risk processes end-to-end
  • Strong knowledge of frameworks (ISO 27005, NIST CSF, NIST 800-53)
  • Understanding ofGDPR and emerging AI risk considerations
  • Ability topresent to and challenge senior leadership (ExCo level)
  • Strong analytical and communication skills, translating risk into business impact
  • Experience with GRC tools (e.g. Diligent One) is beneficial

Why Apply?

  • Own ahigh-visibility risk function in a growing team
  • Combinehands-on delivery with strategic influence
  • Shape risk practices in an evolving GRC environment
  • Exposure to emerging areas includingAI governance

If you’re a hands-on risk professional who thrives in building and embedding capability, this is an excellent opportunity to make a significant impact.


Related Jobs

View all jobs

Information Security Risk Manager (f/m/d)

awin London, United Kingdom
Hybrid

Information Security Specialist

Specsavers Whiteley, PO15 7LW, United Kingdom
£46,500 pa Hybrid

Cyber Security Analyst - Fridays Off

eTech Partners London, United Kingdom
£65,000 – £70,000 pa Hybrid

Cyber Security Analyst - Fridays Off

eTech Partners London, United Kingdom
£65,000 – £70,000 pa On-site

Cyber Security Analyst

Nextech Essex, United Kingdom
£40,000 – £60,000 pa Hybrid

IT Security Assurance Manager

HAYS Specialist Recruitment Bristol, United Kingdom
£40,000 – £43,500 pa Hybrid

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Cyber Security Jobs in the UK (2026 Guide)

Where to advertise cyber security jobs UK in 2026: the specialist boards, communities and channels that reach offensive, defensive and GRC security talent. The candidate pool is small, heavily vetted and in high demand across government, financial services, critical national infrastructure and the private sector simultaneously. Many of the strongest candidates hold active security clearances, are not actively job-searching through general platforms, and move primarily through specialist networks and trusted referrals. General job boards reach a broad audience but lack the specificity that security professionals expect. Specialist platforms, government-affiliated channels and cleared candidate networks each serve a different part of the market. This guide, published by CybersecurityJobs.tech, covers where to advertise cyber security roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Cyber Security Jobs UK 2026: What to Expect Over the Next 3 Years

Cyber Security Jobs UK 2026: roles, salaries and the threat intelligence, cloud security and zero-trust hiring trends shaping UK cyber careers. Cyber security is one of the few sectors where demand for talent has never once dipped. Every major technological shift of the past decade — cloud migration, remote working, AI adoption, the proliferation of connected devices — has expanded the attack surface that security professionals are expected to defend. And every expansion of that attack surface has generated more jobs. But the cyber security jobs market of 2026 is not simply a larger version of what it was three years ago. It is a structurally different market. The threats have evolved, the technologies used to combat them have changed, the regulatory environment has tightened considerably, and the roles being created reflect all of that. A job seeker who understands only the cyber security landscape of 2023 is already working with an outdated map. The candidates who will thrive over the next three years are those who understand where the sector is heading — which specialisms are attracting the most investment, which technologies are reshaping defensive and offensive security practice, and how the definition of a cyber security professional is broadening well beyond the traditional image of a network defender in a SOC. This article breaks down what the UK cyber security jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the curve.