Ageas UK
Information Security GRC Lead

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Title: Information Security GRC Lead
Target Start Date: ASAP
Contract Type: Permanent, Part Time, Full Time, Job Share option available
Salary Range: Up to £105,000
Location: Eastleigh, hybrid
Closing Date for applications: Friday 14th August
Information Security GRC Lead
The Governance, Risk and Compliance (GRC) Lead is a senior leadership role within the Information Security function, responsible for defining, operating, and continuously improving the organisation’s security governance, risk management, and compliance capabilities.
Reporting directly to the CISO, the role ensures that information security risks are identified, assessed, managed, and reported in line with organisational risk appetite, regulatory obligations, and industry best practice. The role provides authoritative oversight of security compliance frameworks, third-party risk management, and human risk management, and ensures clear, high-quality risk reporting to governance forums.
The GRC Lead also plays a key role in modernising GRC practices through the use of automation and AI-enabled tools, including AI agents to support risk assessments and security awareness programmes.
Main Responsibilities as Information Security GRC Lead:
- Lead and manage the Information Security GRC function, ensuring effective governance, risk, and compliance across the organisation.
- Define and maintain the information security governance framework, policies, standards, and procedures.
- Own and oversee the implementation and ongoing maintenance of key compliance frameworks, including: ISO/IEC 27001, PCI DSS and Alignment with NIST and ISF frameworks.
- Lead and oversee security risk management, ensuring risks are identified, assessed, treated, and tracked through to resolution or acceptance.
- Manage the organisation's third party and supplier security risk assessment programme, including due diligence, ongoing assurance, and risk remediation.
- Lead the human risk management programme, including security awareness, behaviour change initiatives, and insider risk considerations.
- Drive the use of AI enabled capabilities within GRC, including: AI agents to support and streamline risk assessments, AI assisted analysis of control effectiveness and risk trends, and AI enhanced security awareness and training programmes.
- Oversee IT risk and controls management, ensuring alignment between technology risks, security controls, and enterprise risk management.
- Produce clear, accurate, and timely information security KRIs and KPIs, including trend analysis and risk insights.
- Provide high quality reporting for security governance forums, executive committees, and second line risk functions.
- Coordinate and support internal and external audits, certifications, and assurance activities.
- Work closely with Security Architecture, Engineering, and Operations to ensure GRC requirements are practical, risk based, and effectively implemented.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Skills and experience you need as Information Security GRC Lead:
- Significant experience in information security governance, risk, and compliance leadership roles.
- Proven experience implementing and maintaining ISO/IEC 27001 and PCI DSS compliance programmes.
- Strong understanding of security and risk frameworks, including NIST, SCF and ISF.
- Experience leading third-party / supplier security risk management programmes.
- Experience designing and operating security awareness and human risk management initiatives.
- Experience producing executive level risk, KRI, and KPI reporting for governance forums.
- Proven people leadership experience managing multi disciplinary teams.
- Strong leadership and stakeholder management capability.
- Relevant professional certifications, such as: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor
- Experience implementing or using GRC tooling and automation platforms.
- Experience applying AI or automation to risk assessments, control testing, or awareness programmes.
Benefits
At Ageas we offer a wide range of benefits to support you and your family inside and outside of work, which helped us achieve, Top Employer status in the UK.
Here are some of the benefits you can enjoy at Ageas:
- Flexible Working- Smart Working @ Ageas gives employees flexibility around location (as long as it’s within the UK) and, for many of our roles, flexibility within the working day to manage other commitments, such as school drop offs etc. We also offer all our vacancies part-time/job-shares. We also offer a minimum of 35 days holiday (inc. bank holidays) and you can buy and sell days.
- Supporting your Health- Dental Insurance Health Cash Plan, Health Screening, Will Writing, Voluntary Critical Illness, Mental Health First Aiders, Well Being Activities – Mindfulness.
- Supporting your Wealth- 50% off esure and Sheilas' Wheels motor and home insurance, Annual Bonus Schemes, Annual Salary Reviews, Competitive Pension, Employee Savings, Employee Loans.
- Supporting you at Work- Well-being activities, mindfulness sessions, Sports and Social Club events and more.
- Supporting you and your Family- Maternity/pregnant parent/primary adopter entitlement of 16 weeks at full pay and paternity/non-pregnant parent/co-adopter at 8 weeks’ full pay.
- Benefits for Them- Partner Life Assurance and Critical Illness cover.
- Get some Tech- Deals on various gadgets including Wearables, Tablets and Laptops.
- Getting around- Car Salary Exchange, Cycle Scheme, Vehicle Breakdown Cover.
- Supporting you back to work- Return to work programme after maternity leave.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
About Ageas
We are one of the largest car and home insurers in the UK. Our People help Ageas to be a thriving, creative and innovative place to work. We show this in the service we provide to over four million customers.
As an inclusive employer, we encourage anyone to apply. We’re a signatory of the Race at Work Charter and Women in Finance Charter, member of iCAN and GAIN. As a Disability Confident Leader, we are committed to ensuring our recruitment processes are fully inclusive. That means if you are applying for a job with us, you will have fair access to support and adjustments throughout your recruitment experience. If the list does not cover the support you need, please contact our Recruitment Team to discuss how they can help. We also guarantee an interview for applicants with a disability who meet the minimum criteria for the role. For more information, please see Ageas Everyone.
We have a zero-tolerance approach towards any form of harassment during the recruitment process, ensuring that everyone is treated with respect and professionalism.
Our aim is to have great people everywhere in our business and we’re always looking for outstanding people to join us. Most roles across Ageas allow a proportion of your time to be spent working from home and we’re open to discussing flexible working, including full-time, part-time or job share arrangements. To find out more about Ageas, see About Us.
Want to be part of a Winning Team? Come and join Ageas.
Click on the ‘Apply button’ to be considered.
Important Notice – Recruitment Scam Alert
We are aware of fraudulent activity whereby individuals are being contacted with fake job offers claiming to be from Ageas, often for remote roles such as Administrative Assistants. These scams may include offers of high hourly pay and requests for upfront payments or deposits. Please be aware that Ageas will never ask for money at any stage of the recruitment process. Ageas will always ask you to make an application via our Company Websites and all legitimate Ageas job opportunities are listed on our official careers pages within. Communication will only come from verified Ageas email addresses and if you are unsure about the legitimacy of a job offer or communications you are receiving, please contact recruitment@ageas.co.uk with the subject FRAUD.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills