Logo-of-Tria-hiring-for-jobs-in-UK-on-GrabJobs

Governance, Risk & Compliance Lead

icon building Company : Tria
icon briefcase Job Type : Full Time

Job Description - Governance, Risk & Compliance Lead

GRC / Cyber Compliance Lead

Remote - 1 day a month in either London or Manchester (fully expensed)

Competitive Salary & 20% Bonus & car allowance & private health

We're looking for an experienced GRC / Cyber Compliance Lead to join a growing Group Security function and build a new Governance, Risk and Compliance capability from the ground up.

This is an opportunity to take genuine ownership. Rather than stepping into an established GRC function and simply maintaining existing processes, you'll be responsible for defining how GRC operates across the organisation - establishing the controls framework, developing meaningful security metrics and risk reporting, strengthening compliance and assurance, and giving senior leadership and the Board a clear view of the organisation's security posture.

The role

Reporting to the Head of Cyber Security, Compliance and Risk Management, you will lead the development and ongoing operation of the Group's cyber GRC capability across multiple divisions, locations and business functions.

You'll build the foundations of a mature GRC function, including:

Designing and owning the Group's security controls framework and control library
Developing cyber risk methodology, risk assessment and treatment processes
Establishing meaningful KRIs, KPIs and security posture reporting for senior leadership and Board-level audiences
Developing governance processes around security policies, standards, exceptions, waivers and control ownership
Working with stakeholders across the business to improve control maturity and manage security risks
Leading the organisation's compliance and certification activities, including Cyber Essentials and Cyber Essentials Plus
Supporting the longer-term development towards ISO 27001
Managing relationships with internal and external auditors, certification bodies and independent assurance partners
Establishing robust control testing, evidence management and audit-readiness processes
Providing governance oversight of activities such as phishing testing and security awareness
Developing practical, pre-approved security responses and evidence that can be used by commercial and sales teams during tenders and bids
Providing security governance and assurance around key suppliers and third parties
Translating complex security and compliance issues into clear business risks, recommendations and actions
Challenging existing ways of working and driving pragmatic improvements across the organisationThis is a role where you'll need to be comfortable operating at both strategic and detailed levels - able to discuss security posture and risk with senior leadership while also getting into the detail of controls, evidence and remediation when required.

About you

We're looking for someone with proven cyber/information security GRC experience who can demonstrate what a good GRC function looks like and, importantly, has experience of building or significantly improving one.

You are likely to have experience across:

Cyber security / information security governance, risk and compliance
Designing or implementing security controls frameworks
Cyber and information security risk management
Security metrics, KRIs/KPIs and executive reporting
Internal and external audit and assurance
Control testing and evidence management
Cyber security policies, standards and governance frameworks
Cyber Essentials / Cyber Essentials Plus
ISO 27001 / ISMS, ideally including hands-on implementation or certification experience
NIST or other recognised security frameworks
Third-party / supplier security assurance
Security questionnaires, customer assurance or tender/RFP responsesWhat matters most is your ability to understand security risk, establish effective governance and make things happen.

We're looking for someone with the attitude and curiosity to build something, rather than someone who wants to work within a tightly defined specialist remit.

You'll need to be:

Pragmatic - able to deliver what is needed now while keeping sight of the longer-term direction
Curious and willing to challenge established thinking
Comfortable working with ambiguity and building structure where little currently exists
Commercially minded, understanding how good security can enable rather than restrict the business
Comfortable influencing senior stakeholders without relying on formal authority
Collaborative and willing to work across organisational boundaries
Confident enough to challenge the status quo and find practical solutions
Able to communicate complex security and risk matters clearly to both technical and non-technical audiencesThe organisation is deliberately building its security capability over the next few years, so this role offers significant scope to develop and grow. As the function matures, there is the potential for the role to develop into a broader leadership position with a team underneath it.

You'll be joining at a genuinely interesting point in the organisation's security journey. The foundations are being established, but there is still significant opportunity to shape the future operating model.

Your work will directly influence how the organisation understands and manages cyber risk, how security is reported to the Board, how confidently it can demonstrate its security posture to customers, and ultimately how security can become an enabler of new commercial opportunities.

Candidates will need to be Security Clearable.

If you're an experienced cyber GRC professional who enjoys building, improving and challenging rather than simply maintaining, this is an opportunity to make a significant impact
Only candidates based in UK and eligible to work in UK are allowed
Original job Governance, Risk & Compliance Lead posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Share Job
Share Job

Similar GRC / Cyber Compliance Lead Jobs in the UK

GrabJobs is the no1 job portal in the UK, connecting you to thousands of jobs fast! Find the best jobs in the UK, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.