Information Security GRC Specialist Role - Insurance, The City, London
We are looking for an experienced Senior Information Security GRC Specialist to join an established and expanding cyber security team. This is a senior role with broad responsibility across security governance, risk and compliance, working closely with both technology and business stakeholders to strengthen the organisation’s overall security posture.
Key Responsibilities
- Contribute to the development and ongoing delivery of the organisation’s information security strategy and governance approach.
- Manage cyber and information security risk activities, including risk assessments, control reviews, audits and remediation.
- Develop, review and maintain security policies, standards, controls and risk documentation.
- Maintain oversight of security risks and ensure appropriate actions are tracked through to resolution.
- Produce meaningful reporting on cyber risk, control performance, compliance and key security indicators.
- Help ensure alignment with relevant regulatory requirements and recognised frameworks, including NIST, GDPR and DORA.
- Work with business and technology teams to provide practical security and risk guidance.
- Support security awareness and education activities across the organisation.
- Contribute to security incident management, lessons learned and the ongoing improvement of security processes.
- Provide senior-level GRC support and leadership cover when required.
Experience & Skills
- Extensive experience within Information Security, ideally 10+ years, with a strong background in GRC, cyber risk and security governance.
- Demonstrable experience leading security or risk initiatives and influencing senior stakeholders.
- Strong understanding of information security controls, risk management methodologies, governance frameworks and regulatory requirements.
- Able to translate technical and security risks into clear business language and recommendations.
- Strong communication, reporting and stakeholder management skills.
- Previous experience within a regulated environment, particularly financial services or insurance, would be advantageous.
#J-18808-Ljbffr
Information Security Specialist in London employer: Michael James Associates
Join a top-tier global insurance firm in London, where you will have the unique opportunity to lead the design and implementation of a comprehensive risk and compliance framework across 60 countries. Our dynamic work culture fosters collaboration and innovation, providing you with significant ownership and the chance to make a real impact while enjoying hybrid working arrangements. With a strong focus on employee growth and development, we empower our team members to thrive in their careers while navigating complex international environments.