Gleeson Recruitment Group
GRC Manager - Cyber Security

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
We are looking for an experienced GRC Manager to join a growing Information Security function within a PE-backed international organisation undergoing significant growth and transformation.
Reporting directly to the Director of Information Security, you'll take ownership of Governance, Risk and Compliance activities across the business, with an immediate focus on supporting the organisation through ISO 27001 certification.
This is an opportunity to have genuine ownership. We're not looking for someone who has simply contributed to GRC within a large team; we need someone who understands how to take frameworks, controls and best practice and implement them effectively within a lean, fast-moving organisation.
The Role
You'll take ownership across:
- Driving the organisation's ISO 27001 certification journey and ongoing ISMS maturity.
- Developing and maintaining security policies, standards and governance frameworks.
- Managing information security risks, risk registers, treatment plans and remediation.
- Coordinating audit evidence, control assessments and audit readiness.
- Supporting compliance with NIS2, NCSC CAF, GDPR and Cyber Essentials.
- Managing third-party security assessments, supplier assurance and customer security questionnaires.
- Producing meaningful security KPIs, KRIs and executive reporting.
- Working across IT, OT, Legal, Procurement, Operations and Commercial teams to drive security improvements.
- Supporting security awareness, business continuity and post-incident improvement activities.
- Continuously improving and automating GRC processes as the organisation grows.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Experience
The key requirement is someone who has personally helped take an organisation through ISO 27001 certification and understands what successful implementation looks like in practice.
You'll ideally bring:
- Strong practical experience across information security Governance, Risk & Compliance.
- Experience developing or significantly maturing a GRC function or ISMS.
- End-to-end ownership of ISO 27001 controls, evidence, audits and remediation.
- Experience managing security risks and driving actions through to completion.
- Exposure to third-party/supplier assurance and customer security requirements.
- Knowledge of NIS2 would be particularly valuable.
- Excellent stakeholder management and communication skills.
- You'll need the confidence to challenge and influence people across the organisation, translating complex security risks into clear business language for audiences ranging from technical teams through to senior executives.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
We're open on industry background. More important is your ability to operate autonomously, adapt best practice to a lean environment and take genuine ownership rather than being one part of a large GRC function.
Why Join?
The organisation is undergoing significant growth, including acquisitions across Europe, making Information Security an important part of its wider transformation and value-creation strategy.
You'll work directly with the Director of Information Security, have access to specialist external partners and wider group security expertise and can shape how GRC develops as the organisation continues to scale.
There will also be occasional travel to other UK and European locations.
At Gleeson Recruitment Group, we embrace inclusivity and welcome applicants of all backgrounds, experiences, and abilities. We are proud to be a disability confident employer.
By applying you will be registered as a candidate with Gleeson Recruitment Limited. Our Privacy Policy is available on our website and explains how we will use your data.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills