Governance, Risk & Compliance Lead

GRC / Cyber Compliance Lead
Remote - 1 day a month in either London or Manchester (fully expensed)
Competitive Salary & 20% Bonus & car allowance & private health
We're looking for an experienced GRC / Cyber Compliance Lead to join a growing Group Security function and build a new Governance, Risk and Compliance capability from the ground up.
This is an opportunity to take genuine ownership. Rather than stepping into an established GRC function and simply maintaining existing processes, you'll be responsible for defining how GRC operates across the organisation - establishing the controls framework, developing meaningful security metrics and risk reporting, strengthening compliance and assurance, and giving senior leadership and the Board a clear view of the organisation's security posture.
The role
Reporting to the Head of Cyber Security, Compliance and Risk Management, you will lead the development and ongoing operation of the Group's cyber GRC capability across multiple divisions, locations and business functions.
You'll build the foundations of a mature GRC function, including:
This is a role where you'll need to be comfortable operating at both strategic and detailed levels - able to discuss security posture and risk with senior leadership while also getting into the detail of controls, evidence and remediation when required.
About you
We're looking for someone with proven cyber/information security GRC experience who can demonstrate what a good GRC function looks like and, importantly, has experience of building or significantly improving one.
You are likely to have experience across:
What matters most is your ability to understand security risk, establish effective governance and make things happen.
We're looking for someone with the attitude and curiosity to build something, rather than someone who wants to work within a tightly defined specialist remit.
You'll need to be:
The organisation is deliberately building its security capability over the next few years, so this role offers significant scope to develop and grow. As the function matures, there is the potential for the role to develop into a broader leadership position with a team underneath it.
You'll be joining at a genuinely interesting point in the organisation's security journey. The foundations are being established, but there is still significant opportunity to shape the future operating model.
Your work will directly influence how the organisation understands and manages cyber risk, how security is reported to the Board, how confidently it can demonstrate its security posture to customers, and ultimately how security can become an enabler of new commercial opportunities.
Candidates will need to be Security Clearable.
If you're an experienced cyber GRC professional who enjoys building, improving and challenging rather than simply maintaining, this is an opportunity to make a significant impact.