Information Security Manager GRC
An iconic media outlet are looking for an Information Security Manager to join their growing team in London. This role is based in Kings Cross and you will need to be in the office 3 days per week. My client does NOT offer sponsorship.
About the IT Security GRC Manager role:
Responsible for leading and overseeing the day-to-day execution of Information Security risk management activities across the organisation, including risk identification, assessment, and tracking, as well as the creation and management of risk artefacts. The role also owns and maintains the Information Security policy framework, ensuring policies and standards are effectively governed, communicated, and aligned to organisational risk appetite. Acts as a key point of coordination between Information Security and the wider business, providing oversight and challenge to ensure risks are appropriately managed.
Purpose of the role:
Support the Information Security GRC Lead in delivering effective Information Security risk management, ensuring risks are consistently identified, assessed, and managed, and that appropriate governance, including policies and standards, supports effective risk mitigation across the organisation.
Key responsibilities and accountabilities
Risk Management & Governance ● Own and operate the Information Security risk management framework, ensuring alignment with enterprise risk management (ERM) practices
● Act as the central point of accountability for Information Security risk, driving consistent identification, assessment, and management of risks across the organisation.
● Creation and management of risk artefacts required for the management of information security risk i.e. risk acceptance documents, risk management plans, issue logs, risk statements etc.
● Lead risk assessments and workshops, ensuring risks are clearly articulated, appropriately rated, and aligned to defined risk appetite
● Challenge , drive and validate risk positions and treatment plans, ensuring they are robust, proportionate, and business-aligned
● Drive risk-based decision-making, including escalation of material risks to senior leadership and governance forums.
● Prepare and document risk acceptance decisions, clearly articulating residual risk, and drive these through appropriate governance forums to obtain formal sign-off
● Maintain and continuously enhance the information security risk register, ensuring accuracy, completeness, and actionable insight
● Identify and manage emerging risks, including those associated with AI/ML systems (e.g. bias, privacy, security, and model integrity)
Reporting & Risk Insight
● Own and deliver risk reporting to senior stakeholders and governance forums, providing clear visibility of risk exposure and remediation progress
● Define and track KPIs and KRIs to measure the effectiveness and maturity of the security and risk programme
● Highlight systemic issues, control weaknesses, and emerging threats, driving visibility and action at leadership level
Stakeholder Leadership
● Act as the primary interface between Information Security and ERM, ensuring alignment with organisational risk practices
● Influence and challenge senior stakeholders (C-suite) to drive accountability for risk ownership and mitigation
● Provide expert guidance on risk, controls, and governance, supporting informed decision making across the business
● Lead responses to information security risk queries, assessments, and assurance activities
● Deliver targeted risk training and awareness to embed a strong risk management culture
Policy Governance
● Own and maintain the Information Security policy framework, ensuring policies and standards remain current, aligned to risk appetite, and meet regulatory requirements
● Drive policy governance, including defined review cycles, approvals, and version control
● Ensure policies are effectively communicated, adopted, and consistently applied across the organisation
● Oversee and govern policy exceptions, ensuring they are risk-assessed, formally approved, and time-bound Key skills
● Strong experience in identifying, assessing, and managing information security risks, with the ability to apply structured risk methodologies and align to business risk appetite
● Ability to take ownership of risk processes, make informed decisions, and confidently escalate and challenge risk positions where required
● Working knowledge of industry frameworks and standards (e.g. ISO 27005, ISO 42001, NIST CSF 2.0, NIST 800-53) and relevant regulations (e.g. GDPR, EU AI Principles)
● Strong interpersonal skills with the ability to influence, challenge, and engage senior stakeholders, translating technical risk into clear business impact
● Highly disciplined and methodical approach to risk analysis, with the ability to break down complex issues and provide clear, actionable insights
● Experience producing clear, concise risk reporting, including KPIs/KRIs, and presenting insights to leadership
● Strong organisational skills with the ability to manage multiple priorities, maintain momentum on risk treatment, and ensure follow-through
● Awareness of emerging technology risks, including AI/ML-related risks, and the ability to incorporate these into risk assessments
● Experience with GRC tools (e.g. DiligentOne) and risk tracking systems is of benefit
If the above is of interest please apply to this role or call me on 0207 509 8040 or email me darius.goodarzi@robertwalters.com
Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates
About the job
Contract Type: Permanent
Specialism: Technology & Digital
Focus: Information Security
Industry: Banking
Salary: £75,000 - £95,000 per annum
Workplace Type: Hybrid
Experience Level: Senior Management
Location: London
FULL_TIMEJob Reference: HKCOTK-8488013C
Date posted: 14 July 2026
Consultant: Darius Goodarzi
london information-technology/information-security 2026-07-14 2026-09-12 banking London London GB GBP 75000 95000 95000 YEAR Robert Walters https://www.robertwalters.co.uk https://www.robertwalters.co.uk/content/dam/robert-walters/global/images/logos/web-logos/square-logo.png true