Rodeo
Get started

air-recruitment.com

Senior Cyber GRC Specialist – Technical Controls

London
£120k/yr
Posted about 18 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Senior Cyber GRC Specialist – Technical Controls

London / Hybrid
Up to £120,000

Are you an experienced Cyber GRC professional with a genuinely strong understanding of cyber engineering and technical security controls?

We’re working with a major global investment management organisation looking for a Senior Cyber GRC Specialist.

This is not a purely policy, audit or compliance-focused position. To be considered, you must combine substantial Cyber GRC experience with the technical knowledge to understand and challenge controls across networks, operating systems, cloud security, IAM and Secure DevOps.

You may have started your career in cyber engineering, infrastructure security, security operations or cloud security before moving into GRC, cyber risk or controls. Alternatively, you may already be working in a technically focused Cyber GRC position within financial services or another highly regulated organisation.

This is a highly visible opportunity to help strengthen cybersecurity governance, risk management and regulatory compliance across a complex international business.

The Role

Working closely with Technology, Enterprise Risk, Legal, Compliance and Internal Audit, you will:

  • Develop and maintain comprehensive cybersecurity policies, standards and procedures
  • Ensure security policies align with regulatory requirements and recognised industry frameworks
  • Integrate effective security practices and controls across technical and non-technical departments
  • Conduct cyber risk assessments to identify vulnerabilities and emerging threats
  • Help develop, implement and monitor appropriate risk-mitigation strategies
  • Design and evaluate control metrics to assess the effectiveness of cybersecurity measures
  • Embed cyber risk within wider enterprise risk registers and board-level reporting
  • Monitor compliance with internal policies, regulatory requirements and industry standards
  • Produce clear compliance reports and updates for senior management
  • Monitor regulatory developments and create appropriate compliance roadmaps
  • Support cybersecurity awareness and training across the organisation
  • Participate in incident response and post-incident reviews
  • Help develop and implement corrective measures following security incidents
  • Provide credible cybersecurity guidance to stakeholders across the business

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

About You

You’ll need:

  • Strong professional experience across cybersecurity governance, risk and compliance
  • A solid technical cybersecurity or cyber engineering background
  • Deep knowledge of cybersecurity principles and recognised frameworks, including NIST and ISO 27001
  • Experience within financial services or another highly regulated environment
  • Knowledge of relevant financial-services regulations, ideally including FCA requirements and DORA
  • Strong understanding of network security principles and controls, including firewalls, IDS/IPS, TCP/IP, DHCP and DNS
  • Experience of security across Windows, UNIX/Linux and ideally Mac environments
  • Knowledge of operating-system access rights, secure configuration and security best practice
  • Strong understanding of cloud security across IaaS, PaaS and SaaS environments
  • Knowledge of public, private and hybrid cloud deployment models
  • A thorough understanding of IAM, SSO, MFA and role-based access control
  • Understanding of Secure DevOps and CI/CD pipeline governance
  • The ability to translate technical cyber risks into clear business and regulatory implications
  • Strong stakeholder-management skills, with the credibility to work across Technology, Risk, Legal, Compliance, Audit and senior leadership

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

A CISSP or similar recognised cybersecurity qualification would be highly beneficial.

This position would suit a Cyber GRC, Cyber Risk or Security Controls specialist who has retained strong technical knowledge—or a cybersecurity engineer who has developed substantial experience across governance, risk, controls and regulation.

If you combine strong Cyber GRC expertise with a genuine understanding of cyber engineering and technical security controls, we’d love to hear from you.

Please get in touch quoting job reference AP1203.

Please also visit www.air-recruitment.com

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Cyber GRC
Technical Security Controls
Cyber Risk Assessment
NIST
ISO 27001
Network Security
Cloud Security
IAM
Secure DevOps
FCA Regulations
DORA
Stakeholder Management
Compliance Reporting
Incident Response
CISSP
CI/CD Governance

Location

London, England, United Kingdom

Sign up to applySee more jobs like this