The GRC Lead operates within the Operational Integrator (OI) function and is responsible for leading cyber security governance, risk, and compliance activities across a multi-supplier (SIAM) environment.
The role provides oversight and coordination of supplier security governance activities, ensuring risks, controls, compliance obligations, and assurance requirements are consistently managed and reported.
Acting as a key interface between suppliers, security functions, service management teams, and client stakeholders, the Security GRC Lead enables effective security governance, risk-informed decision making, and regulatory compliance.
The role provides a consolidated view of security risk, control effectiveness, and compliance posture across the service ecosystem while driving accountability and continual improvement.
This is a governance, risk, compliance, and assurance leadership role and does not perform operational security monitoring, vulnerability remediation, incident response, or security engineering activities.
Hybrid working:
Locations are Frimley, Preston and Inverness: The places that you work from day to day will vary according to your role, your needs, and those of the business; it will be a blend of Company offices, client sites, and your home; noting that you will be unable to work at home 100% of the time.