×
Register Here to Apply for Jobs or Post Jobs. X

Information Security GRC Lead

Job in Eastleigh, Hampshire County, EX39, England, UK
Listing for: Ageas
Full Time, Part Time position
Listed on 2026-08-03
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity, IT Consultant, IT Project Manager
Salary/Wage Range or Industry Benchmark: 105000 GBP Yearly GBP 105000.00 YEAR
Job Description & How to Apply Below

Job Title
:
Information Security GRC Lead
Target

Start Date:

ASAP
Contract Type: Permanent, Part Time, Full Time, Job Share option available
Salary Range: Up to £105,000
Location: Eastleigh, hybrid
Closing Date for applications: Friday 14th August

Information Security GRC Lead: The Governance, Risk and Compliance (GRC) Leadis a senior leadership role within the Information Security function,responsible for defining, operating, and continuously improving the organisation’s security governance, risk management, and compliance capabilities.

Reporting directly to the CISO, the role ensures that information security risks are identified, assessed, managed, and reported in line with organisational risk appetite, regulatory obligations, and industry best practice. The role provides authoritative oversight of security compliance frameworks, third‑party risk management,and human risk management, and ensures clear, high‑quality risk reporting to governance forums.

TheGRC Lead also plays a key role in modernising GRC practices through the use of automation and AI‑enabled tools, including AI agents to support risk assessments and security awareness programmes.

Main Responsibilities as
Information Security GRC Lead:

  • Lead and manage the Information Security GRC function, ensuring effective governance, risk, and compliance across the organisation.
  • Define and maintain the information security governance framework, policies, standards, and procedures.
  • Own and oversee the implementation and ongoing maintenance of key compliance frameworks, including: ISO/IEC 27001,PCI DSS and Alignment with NIST and ISF frameworks.
  • Lead and oversee security risk management, ensuring risks are identified, assessed, treated, and tracked through to resolution or acceptance.
  • Manage the organisation's third party and supplier security risk assessment programme, including due diligence, ongoing assurance, and risk remediation.
  • Lead the human risk management programme, including security awareness, behaviour change initiatives, and insider risk considerations.
  • Drive the use of AI enabled capabilities within GRC, including:

    AI agents to support and streamline risk assessments,AI assisted analysis of control effectiveness and risk trends, andAI enhanced security awareness and training programmes.
  • Oversee IT risk and controls management, ensuring alignment between technology risks, security controls, and enterprise risk management.
  • Produce clear, accurate, and timely information security KRIs and KPIs, including trend analysis and risk insights.
  • Provide high quality reporting for security governance forums, executive committees, and second line risk functions.
  • Coordinate and support internal and external audits, certifications, and assurance activities.
  • Work closely with Security Architecture, Engineering, and Operations to ensure GRC requirements are practical, risk based, and effectively implemented.

Skills and experience you need as Information Security GRC Lead:

  • Significant experience in information security governance, risk, and compliance leadership roles.
  • Proven experience implementing and maintaining ISO/IEC 27001 and PCI DSS compliance programmes.
  • Strong understanding of security and risk frameworks, including NIST, SCF and ISF.
  • Experience leading third-party / supplier security risk management programmes.
  • Experience designing and operating security awareness and human risk management initiatives.
  • Experience producing executive level risk, KRI, and KPI reporting for governance forums.
  • Proven people leadership experience managing multi disciplinary teams.
  • Strong leadership and stakeholder management capability.
  • Relevant professional certifications, such as: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor
  • Experience implementing or using GRC tooling and automation platforms.
  • Experience applying AI or automation to risk assessments, control testing, or awareness programmes.

At Ageas we offer a wide range of benefits to support you and your family inside and outside of work, which helped us achieve,
Top Employer status in the UK.

Here are some of the benefits you can enjoy at Ageas:

Flexible Working- Smart Working @ Ageasgives employees flexibility around…

Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary