Cybersecurity: Senior Specialist (GRC)
An Exciting Opportunity is Available for an Experienced Cyber Security Specialist – Governance, Risk & Compliance (grc) to Join a Leading Organisation Operating Within the Fintech and Digital Financial Services Sector.
The successful candidate will play a key role in strengthening the organisation’s cyber security governance, risk management, compliance, identity and access management, third-party security, and security assurance capabilities.
This is a hands-on governance and assurance role suited to a security professional who can work confidently across technical, operational, risk, audit, and business environments.
Key Responsibilities
- Develop, maintain, and enforce cyber security policies, standards, procedures, and governance frameworks.
- Drive alignment with relevant regulatory requirements and industry standards, including ISO 27001, PCI-DSS, GDPR, and data protection requirements.
- Conduct cyber security risk assessments across systems, projects, processes, and third parties.
- Maintain the cyber risk register and monitor risk treatment plans through to closure.
- Coordinate internal and external cyber security audits, including evidence preparation and remediation tracking.
- Support ongoing security control assurance and compliance monitoring.
- Manage and strengthen Identity & Access Management (IAM) governance, including RBAC, Joiner-Mover-Leaver processes, access certifications, and segregation of duties.
- Support Identity Governance and Administration solutions and drive opportunities for automation.
- Conduct security assessments of vendors, suppliers, and business partners.
- Coordinate third-party security assessments and monitor remediation of identified risks.
- Coordinate penetration testing activities and track vulnerabilities through to remediation.
- Monitor security controls covering areas such as access management, patching, backups, firewalls, DLP, logging and monitoring, and infrastructure hardening.
- Develop and deliver cyber security awareness and phishing simulation programmes.
- Prepare cyber security dashboards, management reports, KPIs, KRIs, and governance updates.
- Collaborate with technology, architecture, operations, project, and business stakeholders to embed security requirements into initiatives.
- Identify opportunities to improve security governance, control effectiveness, compliance, and operational resilience.
Minimum Requirements
Education
A Bachelor's Degree in one of the following, or a related discipline:
- Computer Science
- Information Technology
- Cyber Security
- Information Systems
- Electrical Engineering
- Related technology field
Professional Certification
At least one of the following is required:
- CISSP
- CISM
- CISA
- CEH
The following certifications would be advantageous:
- ISO 27001 Lead Implementer
- ISO 27001 Lead Auditor
- CRISC
- CompTIA Security+
- SailPoint / IdentityIQ certifications