Information Security Manager - Governance, Risk & Compliance
- sheffield, south yorkshire, S1 1AY, United Kingdom
- Permanent·Remote
- Full time
- £92,000 - £92,000 Per Annum
Job Description
About the Role
Our client is seeking an experienced Information Security Manager with a focus on Governance, Risk, and Compliance (GRC) to lead their remote security program. This role is pivotal in establishing and maintaining a robust framework for managing information security risks and ensuring compliance with relevant regulations and industry standards. You will be instrumental in developing policies, conducting risk assessments, and driving security initiatives across the organization. This is a fully remote position, offering a significant opportunity to shape and influence the security posture of the company from anywhere within the UK, contributing to a culture of security excellence in information security .
Key Responsibilities
- Develop, implement, and maintain the organization's information security governance framework, policies, and procedures.
- Lead and manage comprehensive risk assessment processes, identifying, analyzing, and prioritizing security risks across the enterprise.
- Ensure compliance with relevant regulations (e.g., GDPR, ISO 27001, NIST) and industry standards through audits and assessments.
- Oversee the development and execution of security awareness training programs for all employees.
- Manage third-party risk by conducting security assessments of vendors and partners.
- Act as the primary point of contact for security audits and regulatory inquiries, ensuring timely and accurate responses for cybersecurity compliance.
Requirements
- Bachelor's degree in Computer Science, Information Security, Law, or a related field; Master's degree preferred.
- 7+ years of experience in information security , with a significant focus on GRC, risk management, and compliance.
- Proven experience in developing and implementing information security policies, standards, and procedures.
- In-depth knowledge of major security frameworks (ISO 27001, NIST CSF) and relevant data privacy regulations.
- Strong understanding of risk assessment methodologies and controls implementation.
- Excellent leadership, communication, and stakeholder management skills, with the ability to drive initiatives in a remote setting.
Benefits
- Highly competitive salary package with executive-level bonuses.
- Fully remote work arrangement with significant autonomy and flexibility.
- Comprehensive executive health, dental, and vision insurance.
- Generous pension contributions and life assurance policies.
- Extensive opportunities for professional development, certifications, and attending GRC-focused conferences in information security .
- A culture that values strategic thinking, continuous improvement, and employee well-being.


