Lead GRC Consultant at Cathcart Technology
London, London - England, United Kingdom -
Full Time


Start Date

Immediate

Expiry Date

28 Dec, 26

Salary

80000.0

Posted On

29 Sep, 26

Experience

10 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

Yes

Skills

Industry

Information Technology & Services

Description

Lead the day-to-day operation and ongoing improvement of the organisation’s ISO 27001-aligned Information Security Management System.** Own and develop security policies, standards, controls and exception management processes.** Lead information security risk assessments across new technology, projects, services and business initiatives.** Assess the effectiveness of security controls and work with stakeholders to develop and track appropriate risk treatment plans.** Manage third-party security risk, including supplier assessments, due diligence, remediation and ongoing monitoring.** Support internal and external audits, customer security assessments and certification activities.** Analyse and communicate security risks clearly to both technical and non-technical stakeholders, including senior leadership.** Configure and continually improve GRC tooling, supporting risk registers, control libraries, assessments, exceptions and third-party workflows.

How To Apply:

Incase you would like to apply to this job directly from the source, please click here

Responsibilities

Lead the day-to-day operation and ongoing improvement of the organisation’s ISO 27001-aligned Information Security Management System.** Own and develop security policies, standards, controls and exception management processes.** Lead information security risk assessments across new technology, projects, services and business initiatives.** Assess the effectiveness of security controls and work with stakeholders to develop and track appropriate risk treatment plans.** Manage third-party security risk, including supplier assessments, due diligence, remediation and ongoing monitoring.** Support internal and external audits, customer security assessments and certification activities.** Analyse and communicate security risks clearly to both technical and non-technical stakeholders, including senior leadership.** Configure and continually improve GRC tooling, supporting risk registers, control libraries, assessments, exceptions and third-party workflows.

Loading...