At a Glance
- Tasks: Develop and maintain cybersecurity policies while assessing risks and implementing controls.
- Company: Major global investment management organisation with a focus on cybersecurity.
- Benefits: Competitive salary up to £120,000, hybrid work model, and professional development opportunities.
- Other info: Ideal for those with a background in cyber engineering or security controls.
- Why this job: Make a real impact on cybersecurity governance in a complex international business.
- Qualifications: Strong Cyber GRC experience with technical knowledge in cybersecurity and risk management.
Are you an experienced Cyber GRC professional with a genuinely strong understanding of cyber engineering and technical security controls? We’re working with a major global investment management organisation looking for a Senior Cyber GRC Specialist. This is not a purely policy, audit or compliance-focused position. To be considered, you must combine substantial Cyber GRC experience with the technical knowledge to understand and challenge controls across networks, operating systems, cloud security, IAM and Secure DevOps. You may have started your career in cyber engineering, infrastructure security, security operations or cloud security before moving into GRC, cyber risk or controls. Alternatively, you may already be working in a technically focused Cyber GRC position within financial services or another highly regulated organisation. This is a highly visible opportunity to help strengthen cybersecurity governance, risk management and regulatory compliance across a complex international business.
THE ROLE
- Develop and maintain comprehensive cybersecurity policies, standards and procedures
- Ensure security policies align with regulatory requirements and recognised industry frameworks
- Integrate effective security practices and controls across technical and non-technical departments
- Conduct cyber risk assessments to identify vulnerabilities and emerging threats
- Help develop, implement and monitor appropriate risk-mitigation strategies
- Design and evaluate control metrics to assess the effectiveness of cybersecurity measures
- Embed cyber risk within wider enterprise risk registers and board-level reporting
- Monitor compliance with internal policies, regulatory requirements and industry standards
- Produce clear compliance reports and updates for senior management
- Monitor regulatory developments and create appropriate compliance roadmaps
- Support cybersecurity awareness and training across the organisation
- Participate in incident response and post-incident reviews
- Help develop and implement corrective measures following security incidents
- Provide credible cybersecurity guidance to stakeholders across the business
ABOUT YOU
- Strong professional experience across cybersecurity governance, risk and compliance
- A solid technical cybersecurity or cyber engineering background
- Deep knowledge of cybersecurity principles and recognised frameworks, including NIST and ISO 27001
- Experience within financial services or another highly regulated environment
- Knowledge of relevant financial-services regulations, ideally including FCA requirements and DORA
- Strong understanding of network security principles and controls, including firewalls, IDS/IPS, TCP/IP, DHCP and DNS
- Experience of security across Windows, UNIX/Linux and ideally Mac environments
- Knowledge of operating-system access rights, secure configuration and security best practice
- Strong understanding of cloud security across IaaS, PaaS and SaaS environments
- Knowledge of public, private and hybrid cloud deployment models
- A thorough understanding of IAM, SSO, MFA and role-based access control
- Understanding of Secure DevOps and CI/CD pipeline governance
- The ability to translate technical cyber risks into clear business and regulatory implications
- Strong stakeholder-management skills, with the credibility to work across Technology, Risk, Legal, Compliance, Audit and senior leadership
A CISSP or similar recognised cybersecurity qualification would be highly beneficial. This position would suit a Cyber GRC, Cyber Risk or Security Controls specialist who has retained strong technical knowledge—or a cybersecurity engineer who has developed substantial experience across governance, risk, controls and regulation. If you combine strong Cyber GRC expertise with a genuine understanding of cyber engineering and technical security controls, we’d love to hear from you. Please get in touch quoting job reference AP1203.
Senior Cyber GRC Specialist – Technical Controls in London employer: air-recruitment Careers
As a Senior Cyber GRC Specialist at our prestigious global investment management organisation in London, you will thrive in a dynamic and inclusive work culture that prioritises innovation and collaboration. We offer competitive salaries, comprehensive benefits, and ample opportunities for professional growth, ensuring that you can advance your career while making a meaningful impact on our cybersecurity governance and risk management efforts. Join us to be part of a forward-thinking team that values your expertise and fosters a supportive environment for continuous learning.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Cyber GRC Specialist – Technical Controls in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including air-recruitment Careers, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through air-recruitment Careers
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at air-recruitment Careers. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Cyber GRC Specialist – Technical Controls in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at air-recruitment Careers insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to air-recruitment Careers that you’re committed to staying ahead in the game.
How to prepare for a job interview at air-recruitment Careers
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at air-recruitment Careers to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at air-recruitment Careers.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.