At a Glance
- Tasks: Lead the Information Security GRC function and manage risk compliance across the organisation.
- Company: Join Ageas, a leading car and home insurer in the UK with a creative culture.
- Benefits: Enjoy flexible working, 35+ days holiday, health support, and tech discounts.
- Other info: Inclusive employer with excellent career growth opportunities and a supportive work environment.
- Why this job: Make a real impact in security governance while using cutting-edge AI tools.
- Qualifications: Significant experience in GRC leadership and relevant professional certifications required.
The predicted salary is between 70000 - 85000 £ per year.
- Job
- Title: Information Security GRC Lead
- Target
- Start
- Date: ASAP Contract
- Type: Permanent, Part Time, Full Time, Job Share option available
- Salary
Range: Up to £105,000 Location: Eastleigh, hybrid Closing Date for applications: Friday 14th August
Information Security GRC Lead: The Governance, Risk and Compliance (GRC) Leadis a senior leadership role within the Information Security function, responsible for defining, operating, and continuously improving theorganisation’s security governance, risk management, and compliance capabilities.
Reporting directly to the CISO, the roleensures that information security risks are identified, assessed, managed, andreported in line with organisational risk appetite, regulatory obligations, andindustry best practice.
The role provides authoritative oversight of securitycompliance frameworks, third‑party risk management, and human risk management, and ensures clear, high‑qualityrisk reporting to governance forums.
The GRC Lead also plays a key role in modernising GRC practices through the use ofautomation and AI‑enabled tools, including AI agents to supportrisk assessments and security awareness programmes.
Main Responsibilities as Information Security GRC Lead
- Lead and manage the Information Security GRC function, ensuring effective governance, risk, and compliance across the organisation.
- Define and maintain the information security governance framework, policies, standards, and procedures.
- Own and oversee the implementation and ongoing maintenance of key compliance frameworks, including: ISO/IEC 27001, PCI DSS and Alignment with NIST and ISF frameworks.
- Lead and oversee security risk management, ensuring risks are identified, assessed, treated, and tracked through to resolution or acceptance.
- Manage the organisation's third party and supplier security risk assessment programme, including due diligence, ongoing assurance, and risk remediation.
- Lead the human risk management programme, including security awareness, behaviour change initiatives, and insider risk considerations.
- Drive the use of AI enabled capabilities within GRC, including: AI agents to support and streamline risk assessments, AI assisted analysis of control effectiveness and risk trends, and AI enhanced security awareness and training programmes.
- Oversee IT risk and controls management, ensuring alignment between technology risks, security controls, and enterprise risk management.
- Produce clear, accurate, and timely information security KRIs and KPIs, including trend analysis and risk insights.
- Provide high quality reporting for security governance forums, executive committees, and second line risk functions.
- Coordinate and support internal and external audits, certifications, and assurance activities.
- Work closely with Security Architecture, Engineering, and Operations to ensure GRC requirements are practical, risk based, and effectively implemented.
Skills and experience you need as Information Security GRC Lead
- Significant experience in information security governance, risk, and compliance leadership roles.
- Proven experience implementing and maintaining ISO/IEC 27001 and PCI DSS compliance programmes.
- Strong understanding of security and risk frameworks, including NIST, SCF and ISF.
- Experience leading third-party / supplier security risk management programmes.
- Experience designing and operating security awareness and human risk management initiatives.
- Experience producing executive level risk, KRI, and KPI reporting for governance forums.
- Proven people leadership experience managing multi disciplinary teams.
- Strong leadership and stakeholder management capability.
- Relevant professional certifications, such as: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor
- Experience implementing or using GRC tooling and automation platforms.
- Experience applying AI or automation to risk assessments, control testing, or awareness programmes.
Here are some of the benefits you can enjoy at Ageas
- Flexible Working- Smart Working @ Ageasgives employees flexibility around location (as long as it’s within the UK) and, for many of our roles, flexibility within the working day to manage other commitments, such as school drop offs etc.
We also offer all our vacancies part-time/job-shares.
We also offer a minimum of 35 days holiday (inc. bank holidays) and you can buy and sell days.
- Supporting your Health- Dental Insurance Health Cash Plan, Health Screening, Will Writing, Voluntary Critical Illness, Mental Health First Aiders, Well Being Activities – Mindfulness.
- Supporting your Wealth- 50% off esure and Sheilas' Wheels motor and home insurance, Annual Bonus Schemes, Annual Salary Reviews, Competitive Pension, Employee Savings, Employee Loans.
- Supporting you at Work- Well-being activities, mindfulness sessions, Sports and Social Club events and more.
- Supporting you and your Family- Maternity/pregnant parent/primary adopter entitlement of 16 weeks at full pay and paternity/non-pregnant parent/co-adopter at 8 weeks’ full pay.
- Benefits for Them- Partner Life Assurance and Critical Illness cover.
- Get some Tech- Deals on various gadgets including Wearables, Tablets and Laptops.
- Getting around- Car Salary Exchange, Cycle Scheme, Vehicle Breakdown Cover.
- Supporting you back to work- Returnto work programme after maternity leave.
About Ageas
We are one of the largest car and home insurers in the UK.
Our People help Ageas to be a thriving, creative and innovative place to work.
We show this in the service we provide to over four million customers.
As an inclusive employer, we encourage anyone to apply.
We’re a signatory of the Race at Work Charter and Women in Finance Charter, member of i CANand GAIN.
As a Disability Confident Leader, we are committed to ensuring our recruitment processes are fully inclusive.
That means if you are applying for a job with us, you will have fair access to support and adjustments throughout your recruitment experience.
If the list does not cover the support you need, please contact our Recruitment Team to discuss how they can help.
We also guarantee an interview for applicants with a disability who meet the minimum criteria for the role.
For more information, please see Ageas Everyone.
We have a zero-tolerance approach towards any form of harassment during the recruitment process, ensuring that everyone is treated with respect and professionalism.
Our aim is to have great people everywhere in our business and we’re always looking for outstanding people to join us.
Most roles across Ageas allow a proportion of your time to be spent working from home and we’re open to discussing flexible working, including full-time, part-time or job share arrangements.
To find out more about Ageas, see About Us.
#J-18808-Ljbffr
Information Security GRC Lead employer: Ageas
At Ageas, we pride ourselves on being an excellent employer, offering a supportive and flexible work culture that prioritises employee wellbeing and growth. Our Payroll & Benefits Officer role not only provides competitive salary packages and comprehensive health benefits but also fosters a collaborative environment where you can thrive professionally while enjoying the balance of hybrid working in the beautiful Eastleigh/Bournemouth area.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security GRC Lead
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Ageas, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Ageas
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Ageas. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Information Security GRC Lead
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Ageas insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Ageas that you’re committed to staying ahead in the game.
How to prepare for a job interview at Ageas
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Ageas to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Ageas.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.