Senior Cyber GRC Specialist - Technical Controls


Company 

air-recruitment

Location 

London

Employment Hours 

Full Time

Employment Type 

Permanent

Salary 

£120,000 Per Annum

Job Requirements/Description

Senior Cyber GRC Specialist - Technical Controls

London / Hybrid

Up to £120,000

Are you an experienced Cyber GRC professional with a genuinely strong understanding of cyber engineering and technical security controls?

We're working with a major global investment management organisation looking for a Senior Cyber GRC Specialist.

This is not a purely policy, audit or compliance-focused position. To be considered, you must combine substantial Cyber GRC experience with the technical knowledge to understand and challenge controls across networks, operating systems, cloud security, IAM and Secure DevOps.

You may have started your career in cyber engineering, infrastructure security, security operations or cloud security before moving into GRC, cyber risk or controls. Alternatively, you may already be working in a technically focused Cyber GRC position within financial services or another highly regulated organisation.

This is a highly visible opportunity to help strengthen cybersecurity governance, risk management and regulatory compliance across a complex international business.

THE ROLE

Working closely with Technology, Enterprise Risk, Legal, Compliance and Internal Audit, you will:

Develop and maintain comprehensive cybersecurity policies, standards and procedures

Ensure security policies align with regulatory requirements and recognised industry frameworks

Integrate effective security practices and controls across technical and non-technical departments

Conduct cyber risk assessments to identify vulnerabilities and emerging threats

Help develop, implement and monitor appropriate risk-mitigation strategies

Design and evaluate control metrics to assess the effectiveness of cybersecurity measures

Embed cyber risk within wider enterprise risk registers and board-level reporting

Monitor compliance with internal policies, regulatory requirements and industry standards

Produce clear compliance reports and updates for senior management

Monitor regulatory developments and create appropriate compliance roadmaps

Support cybersecurity awareness and training across the organisation

Participate in incident response and post-incident reviews

Help develop and implement corrective measures following security incidents

Provide credible cybersecurity guidance to stakeholders across the business

ABOUT YOU

You'll need:

Strong professional experience across cybersecurity governance, risk and compliance

A solid technical cybersecurity or cyber engineering background

Deep knowledge of cybersecurity principles and recognised frameworks, including NIST and ISO 27001

Experience within financial services or another highly regulated environment

Knowledge of relevant financial-services regulations, ideally including FCA requirements and DORA

Strong understanding of network security principles and controls, including firewalls, IDS/IPS, TCP/IP, DHCP and DNS

Experience of security across Windows, UNIX/Linux and ideally Mac environments

Knowledge of operating-system access rights, secure configuration and security best practice

Strong understanding of cloud security across IaaS, PaaS and SaaS environments

Knowledge of public, private and hybrid cloud deployment models

A thorough understanding of IAM, SSO, MFA and role-based access control

Understanding of Secure DevOps and CI/CD pipeline governance

The ability to translate technical cyber risks into clear business and regulatory implications

Strong stakeholder-management skills, with the credibility to work across Technology, Risk, Legal, Compliance, Audit and senior leadership

A CISSP or similar recognised cybersecurity qualification would be highly beneficial.

This position would suit a Cyber GRC, Cyber Risk or Security Controls specialist who has retained strong technical knowledge-or a cybersecurity engineer who has developed substantial experience across governance, risk, controls and regulation.

If you combine strong Cyber GRC expertise with a genuine understanding of cyber engineering and technical security controls, we'd love to hear from you.

Please get in touch quoting job reference AP1203.

Company 

air-recruitment

Location 

London

Employment Hours 

Full Time

Employment Type 

Permanent

Salary 

£120,000 Per Annum

An unhandled error has occurred. Reload 🗙