Information Security GRC Lead

Ageas


Job Location:

Eastleigh - UK

Monthly Salary: Not Disclosed
Posted on: 13 hours ago
Vacancies: 1 Vacancy

Job Summary

Job Title:Information Security GRC Lead
Target Start Date:ASAP
Contract Type:Permanent Part Time Full Time Job Share option available
Salary Range:Up to 105000
Location:Eastleigh hybrid
Closing Date for applications:Friday 14th August

Information Security GRC Lead:The Governance Risk and Compliance (GRC) Leadis a senior leadership role within the Information Security functionresponsible for defining operating and continuously improving theorganisations security governance risk management and compliance capabilities.

Reporting directly to the CISO the roleensures that information security risks are identified assessed managed andreported in line with organisational risk appetite regulatory obligations andindustry best practice. The role provides authoritative oversight of securitycompliance frameworks thirdparty risk managementand human risk management and ensures clear highqualityrisk reporting to governance forums.

TheGRC Lead also plays a key role in modernising GRC practices through the use ofautomation and AIenabled tools including AI agents to supportrisk assessments and security awareness programmes.

Main Responsibilities asInformation Security GRC Lead:

  • Lead and manage the Information Security GRC function ensuring effective governance risk and compliance across the organisation.
  • Define and maintain the information security governance framework policies standards and procedures.
  • Own and oversee the implementation and ongoing maintenance of key compliance frameworks including:ISO/IEC 27001PCI DSS andAlignment with NIST and ISF frameworks.
  • Lead and oversee security risk management ensuring risks are identified assessed treated and tracked through to resolution or acceptance.
  • Manage the organisations third party and supplier security risk assessment programme including due diligence ongoing assurance and risk remediation.
  • Lead the human risk management programme including security awareness behaviour change initiatives and insider risk considerations.
  • Drive the use of AI enabled capabilities within GRC including:AI agents to support and streamline risk assessmentsAI assisted analysis of control effectiveness and risk trends andAI enhanced security awareness and training programmes.
  • Oversee IT risk and controls management ensuring alignment between technology risks security controls and enterprise risk management.
  • Produce clear accurate and timely information security KRIs and KPIs including trend analysis and risk insights.
  • Provide high quality reporting for security governance forums executive committees and second line risk functions.
  • Coordinate and support internal and external audits certifications and assurance activities.
  • Work closely with Security Architecture Engineering and Operations to ensure GRC requirements are practical risk based and effectively implemented.

Skills and experience you need as Information Security GRC Lead:

  • Significant experience in information security governance risk and compliance leadership roles.
  • Proven experience implementing and maintaining ISO/IEC 27001 and PCI DSS compliance programmes.
  • Strong understanding of security and risk frameworks including NIST SCF and ISF.
  • Experience leading third-party / supplier security risk management programmes.
  • Experience designing and operating security awareness and human risk management initiatives.
  • Experience producing executive level risk KRI and KPI reporting for governance forums.
  • Proven people leadership experience managing multi disciplinary teams.
  • Strong leadership and stakeholder management capability.
  • Relevant professional certifications such as: CISSP CISM CRISC ISO 27001 Lead Implementer/Lead Auditor
  • Experience implementing or using GRC tooling and automation platforms.
  • Experience applying AI or automation to risk assessments control testing or awareness programmes.

At Ageas we offer a wide range of benefits to support you and your family inside and outside of work which helped us achieveTop Employerstatus in the UK.

Here are some of the benefits you can enjoy at Ageas:

Flexible Working- Smart Working @ Ageasgives employees flexibility around location (as long as its within the UK) and for many of our roles flexibility within the working day to manage other commitments such as school drop offs etc. We also offer all our vacancies part-time/job-shares. We also offer a minimum of 35 days holiday (inc. bank holidays) and you can buy and sell days.

Supporting your Health- Dental InsuranceHealth Cash Plan Health Screening Will Writing Voluntary Critical Illness Mental Health First Aiders Well Being Activities Mindfulness.

Supporting your Wealth- 50% off esure and Sheilas Wheels motor and home insurance Annual Bonus Schemes Annual Salary Reviews Competitive Pension Employee Savings Employee Loans.

Supporting you at Work- Well-being activities mindfulness sessions Sports and Social Club events and more.

Supporting you and your Family- Maternity/pregnant parent/primary adopter entitlement of 16 weeks at full pay and paternity/non-pregnant parent/co-adopter at 8 weeks full pay.

Benefits for Them- Partner Life Assurance and Critical Illness cover.

Get some Tech- Deals on various gadgets including Wearables Tablets and Laptops.

Getting around- Car Salary Exchange Cycle Scheme Vehicle Breakdown Cover.

Supporting you back to work- Returnto work programme after maternity leave.

About Ageas:
We are one of the largest car and home insurers in the UK.Our Peoplehelp Ageas to be a thriving creative and innovative place to work. We show this in the service we provide to over four million customers.

As an inclusive employer we encourage anyone to apply. Were a signatory of theRace at Work CharterandWomen in Finance Chartermember ofiCANandGAIN.As aDisability Confident Leaderwe are committed to ensuring our recruitment processes are fully inclusive. That means if you are applying for a job with us you will have fair access to support and adjustments throughout your recruitment the list does not cover the support you need please contact our Recruitment Team to discuss how they can help. We also guarantee an interview for applicants with a disability who meet the minimum criteria for the role. For more information please seeAgeas Everyone.


We have a zero-tolerance approach towards any form of harassment during the recruitment process ensuring that everyone is treated with respect and professionalism.

Our aim is to have great people everywhere in our business and were always looking for outstanding people to join us. Most roles across Ageas allow a proportion of your time to be spent working from home and were open to discussingflexible working including full-time part-time or job share find out more about Ageas seeAbout Us.

Want to be part of a Winning Team Come and join Ageas.

Click on the Apply button to be considered.

Important Notice Recruitment Scam Alert: We are aware of fraudulent activity whereby individuals are being contacted with fake job offers claiming to be from Ageas often for remote roles such as Administrative Assistants. These scams may include offers of high hourly pay and requests for upfront payments or deposits. Please be aware that Ageas will never ask for money at any stage of the recruitment process. Ageas will always ask you to make an application via our Company Websites and all legitimate Ageas job opportunities are listed on our official careers pages within. Communication will only come from verified Ageas email addresses and if you are unsure about the legitimacy of a job offer or communications you are receiving please contact with the subject FRAUD.

Job Title:Information Security GRC LeadTarget Start Date:ASAPContract Type:Permanent Part Time Full Time Job Share option availableSalary Range:Up to 105000Location:Eastleigh hybridClosing Date for applications:Friday 14th August Information Security GRC Lead:The Governance Risk and Compliance (GRC)...