Information Security Governance, Risk, and Compliance (GRC) Specialist

Information Security Governance, Risk, and Compliance (GRC) Specialist

Full-Time 50000 - 65000 £ / year (est.) No working from home possible
J

At a Glance

  • Tasks: Develop and maintain cybersecurity policies while ensuring compliance with industry standards.
  • Company: Join a leading firm dedicated to cybersecurity excellence and innovation.
  • Benefits: Enjoy competitive salary, flexible work options, and ongoing professional development.
  • Other info: Be part of a diverse team fostering a culture of cybersecurity awareness.
  • Why this job: Make a real impact in cybersecurity and protect vital information.
  • Qualifications: Bachelor's degree in IT or Cybersecurity; 3-5 years of experience preferred.

The predicted salary is between 50000 - 65000 £ per year.

Responsibilities

  • Develop and maintain comprehensive cybersecurity policies and procedures.
  • Ensure these policies align with industry standards and regulatory requirements.
  • Assist in the integration of security practices and controls across technical and non‑technical departments, enhancing workflow and operational processes.
  • Conduct regular risk assessments to identify vulnerabilities and threats.
  • Collaborate and oversee the implementation of risk mitigation strategies.
  • Monitor emerging threats and evolving technologies to continuously refine risk assessment protocols.
  • Design and evaluate control metrics for assessing the effectiveness of cybersecurity measures.
  • Collaborate with Enterprise Risk Management to embed cyber risk into broader risk registers and board‑level reporting.
  • Monitor and ensure compliance with internal policies, industry standards, and regulatory requirements.
  • Engage with stakeholders in Technology, Legal, Compliance, and Internal Audit as required.
  • Compile and deliver detailed compliance reports to senior management.
  • Monitor upcoming regulations and prepare compliance roadmaps.
  • Support and enhance engaging cybersecurity awareness training programs.
  • Foster a company‑wide culture of cybersecurity awareness.
  • Keep current with the latest cybersecurity trends and best practices to inform training content and security measures.
  • Train and guide wider Tech team members on best practices in cybersecurity risk management.
  • Actively participate in the response to security incidents.
  • Support post‑incident evaluations and reporting.
  • Collaborate with relevant stakeholders to devise and enforce corrective measures to strengthen defences against future incidents.
  • Maintain clear and effective communication with stakeholders at all levels.
  • Provide expert guidance on cybersecurity best practices.
  • Work collaboratively with Technology and other departments to achieve comprehensive security objectives.

Qualifications

  • Bachelor's Degree in Information Technology, Cybersecurity, or a related field; equivalent work experience also considered.
  • 3 to 5 years of professional experience in information security.
  • Certification such as Certified Information Systems Security Professional (CISSP) strongly preferred.
  • Deep understanding of cybersecurity principles, frameworks (e.g., NIST, ISO/IEC 27001), and compliance standards.
  • Experience with financial service regulations such as FCA, SEC, MAS, DORA.
  • Proficient knowledge of network security principles and controls such as Firewalls, IPS/IPD, TCP/IP, DHCP, and DNS.
  • Extensive experience securing Operating Systems including Windows, UNIX/Linux, and Mac systems, including security access rights, configuration best practices.
  • Knowledge of cloud service and deployment models (IaaS, PaaS, SaaS, public, private, hybrid, community) and experience implementing and managing cloud security best practices.
  • In‑depth knowledge of IAM principles and technologies, including Single Sign‑On (SSO), Multi‑Factor Authentication (MFA), and role‑based access control (RBAC) systems.
  • Understanding of Secure DevOps / CI/CD pipeline governance.

You will be expected to understand the regulatory obligations of the firm and abide by the regulated entity requirements and JHI policies applicable to your role.

All applicants must be willing to comply with the provisions of the Janus Henderson Investment Advisory Code of Ethics related to personal securities activities and other disclosure and certification requirements, including past political contributions and political activities.

Janus Henderson is an equal opportunity / affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. All applications are subject to background checks.

Information Security Governance, Risk, and Compliance (GRC) Specialist employer: Janus Henderson

At Janus Henderson, we pride ourselves on being an exceptional employer that fosters a culture of collaboration and inclusivity. Our commitment to employee growth is evident through our comprehensive professional development programs, generous health and wellbeing benefits, and a supportive hybrid working environment. Join us in London, where you can contribute to meaningful financial outcomes while enjoying a vibrant work-life balance and engaging community events.

J

Contact Details:

Janus Henderson Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Governance, Risk, and Compliance (GRC) Specialist

✨Tip Number 1

Network like a pro! Reach out to folks in the cybersecurity field, attend industry events, and join online forums. The more connections we make, the better our chances of landing that GRC Specialist role.

✨Tip Number 2

Show off your skills! Create a portfolio or a personal website where you can showcase your projects, certifications, and any relevant experience. This gives us a chance to stand out from the crowd and demonstrate our expertise.

✨Tip Number 3

Prepare for interviews by brushing up on common cybersecurity scenarios and risk management questions. We should also be ready to discuss how we can align policies with industry standards and regulatory requirements.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we often have insider tips and updates on new roles that might not be advertised elsewhere.

We think you need these skills to ace Information Security Governance, Risk, and Compliance (GRC) Specialist

Cybersecurity Policy Development
Risk Assessment
Compliance Monitoring
Stakeholder Engagement
Incident Response
Cybersecurity Awareness Training
Knowledge of NIST and ISO/IEC 27001

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in cybersecurity, especially focusing on governance, risk, and compliance. We want to see how your skills align with the responsibilities listed in the job description.

Showcase Relevant Experience:When detailing your work history, emphasise your experience with cybersecurity policies, risk assessments, and compliance standards. We love seeing concrete examples of how you've tackled challenges in previous roles.

Be Clear and Concise:Keep your application straightforward and to the point. Use bullet points where possible to make it easy for us to read through your qualifications and experiences quickly.

Apply Through Our Website:We encourage you to submit your application directly through our website. This ensures that your application gets to the right people and helps us keep track of all candidates efficiently.

How to prepare for a job interview at Janus Henderson

✨Know Your Cybersecurity Frameworks

Make sure you’re well-versed in key cybersecurity frameworks like NIST and ISO/IEC 27001. Be ready to discuss how these frameworks apply to the role and how you've used them in past experiences.

✨Showcase Your Risk Assessment Skills

Prepare to talk about your experience with conducting risk assessments. Have specific examples ready that highlight how you identified vulnerabilities and implemented risk mitigation strategies in previous roles.

✨Understand Compliance Regulations

Brush up on financial service regulations such as FCA, SEC, and DORA. Be prepared to explain how you’ve ensured compliance in your past work and how you would approach compliance roadmaps in this new role.

✨Communicate Effectively

Since this role involves collaboration with various stakeholders, practice articulating your thoughts clearly. Think of examples where you successfully communicated complex cybersecurity concepts to non-technical teams.