S

Senior Information Security & GRC Specialist

St Luke's
1 hour ago
Full-time
On-site
London
£75,000 - £85,000 GBP yearly
Security
Senior Information Security & GRC Specialist | London | Hybrid | £75,000 - £85,000

Zachary Daniels is delighted to be working with a growing international organisation within the logistics and supply chain sector on the appointment of a Senior Information Security & GRC Specialist.

This is a hands-on role with real ownership across ISO 27001, ISMS, NIS2, information security risk, controls, audit readiness and regulatory compliance. The business is looking for someone who enjoys being close to the detail and can translate security and compliance requirements into practical controls that work in a real operational environment.

The Opportunity

You will work closely with senior technology and security leadership to help mature the organisation's Information Security Management System and wider GRC framework.

This is not a broad Head of Cyber Security or people management role. The focus is on hands-on delivery across ISO 27001, NIS2, risk, policy, audit, supplier assurance and regulatory compliance.

What You'll Be Doing

Supporting and driving ISO 27001 certification and ongoing ISMS maturity
Conducting gap assessments and identifying remediation requirements
Maintaining risk registers, risk treatment plans and the Statement of Applicability
Developing and maintaining information security policies, standards and procedures
Translating ISO 27001 requirements into practical controls across the business
Supporting NIS2 readiness, gap assessments and control alignment
Assessing how NIS2 requirements may apply across the organisation's operations, entities and jurisdictions
Translating relevant NIS2 obligations into practical governance, controls, ownership and evidence
Coordinating internal and external audits, evidence gathering and remediation activity
Assessing control design and effectiveness and tracking actions through to closure
Conducting information security and cyber risk assessments
Managing third-party and supplier security assurance activity
Supporting supply chain security requirements, including supplier risk and third-party assurance
Working with Technology, Procurement, Legal and operational teams to embed security requirements
Supporting security awareness, governance reporting and continual improvement
Monitoring changes in cyber security regulation and determining which requirements are relevant to the organisation
Supporting operational resilience and business continuity activityAbout You

Strong hands-on experience within Information Security, GRC or ISMS environments
Strong practical knowledge of ISO 27001
Good working knowledge of NIS2 and its information security requirements
Experience completing NIS2 gap assessments, readiness reviews or control mapping would be highly desirable
Experience implementing, maintaining or improving an ISMS
Experience supporting or leading ISO 27001 certification, recertification or surveillance audits
Hands-on experience with risk registers, risk treatment, control mapping and remediation
Experience developing information security policies and procedures
Experience preparing evidence for internal and external audits
Third-party or supplier security assurance experience
Strong understanding of security governance, risk and compliance
Ability to assess whether regulatory requirements apply to a particular organisation, sector or jurisdiction
Ability to translate regulatory requirements into proportionate, practical security controls
Strong stakeholder management skills across technical and non-technical teams
Experience within logistics, supply chain, manufacturing, transport, food distribution, retail or another operational environment would be particularly useful.Apply today with your most up-to-date CV!

BH36687