At a Glance
- Tasks: Lead cyber risk assessments and enhance security policies while collaborating with tech teams.
- Company: Global investment management organisation with a focus on innovation and security.
- Benefits: Hybrid work model, competitive salary, and opportunities for professional growth.
- Other info: Join a dynamic team with excellent career advancement opportunities.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technology.
- Qualifications: Experience in Information Security and strong stakeholder management skills required.
The predicted salary is between 63000 - 77000 Β£ per year.
Information Security GRC Specialist β Permanent β Hybrid
My client is a leading global investment management organisation seeking a Cyber GRC Specialist to join its Global Technology function in London.
This is a senior hire within the Information Security GRC function, acting as deputy to the Head of Information Security & GRC, supporting the leadership and day-to-day running of the team.
The role combines hands-on delivery with leadership responsibility, operating in a 1.5 line capacity - working closely with technology teams while maintaining strong governance oversight.
The Information Security GRC Specialist is expected to
- Act as second-in-command within the GRC function, supporting the Head of Information Security & GRC across BAU, projects, and stakeholder engagement.
- Operate in a hands-on 1.5 line capacity, working closely with Sec Ops, IAM, and cloud teams to ensure controls are effective in practice.
- Lead cyber risk assessments and control reviews, identifying gaps and driving remediation through to closure.
- Act as a bridge between GRC and technical teams, confidently challenging and validating control design and implementation.
- Support board-level reporting and risk metrics, translating technical issues into clear, business-focused insights.
- Contribute to the development and rollout of GRC tooling, with a focus on automation, reporting, and adoption across technical teams.
- Support incident response oversight, including post-incident reviews and control improvements.
- Maintain and enhance security policies, standards, and frameworks aligned to ISO 27001 and NIST.
- Work across Technology, Risk, Compliance, and Audit to embed security into business processes and decision-making.
The successful Information Security GRC Specialist will possess
- Proven experience within financial services.
- Proven experience in Information Security, Cyber GRC, or Technology Risk within a regulated environment.
- Experience operating in a hands-on capacity across both governance and technical security domains (e. g. vulnerability management, SIEM/SOC, IAM, cloud security).
- Strong understanding of security frameworks such as ISO 27001 and/or NIST.
- Ability to engage with and challenge technical teams, ensuring controls are implemented effectively rather than existing as policy only.
- Experience producing senior-level reporting, including risk metrics and board-facing outputs.
- Exposure to GRC tooling and/or automation initiatives.
- Strong stakeholder management skills, with the ability to work across technical and non-technical audiences.
- Certifications (e. g. CISSP, CISM) are not essential - practical, real-world experience is key.
- #J-18808-Ljbffr
Information Security GRC Specialist employer: Morson Edge (Financial Services)
Morson Edge offers a dynamic and supportive work environment for the Financial Crime QA Manager role, where employees are encouraged to take ownership and drive innovation within the bank's assurance capabilities. With a strong focus on professional development and progression, this London-based position allows for meaningful engagement with stakeholders at all levels, fostering a culture of collaboration and growth. The unique blend of a start-up pace within an established bank provides an exciting opportunity for those looking to make a significant impact in the financial crime sector.
Contact Details:
Morson Edge (Financial Services) Recruitment Team