- Company Name
- McFall Recruitment Limited
- Job Title
- Head of Cyber Risk, Governance & Compliance GRC
- Job Description
-
**Job title**
Head of Cyber Risk, Governance & Compliance (GRC)
**Role summary**
Lead a global GRC team of six to strengthen and harmonise the organisation’s cyber risk management framework. Directly report to the CISO and drive consistency, compliance, and maturity across worldwide operations, ensuring alignment with regulatory standards and executive expectations.
**Expactations**
- Deliver strategic direction for cyber governance, risk, and compliance.
- Translate technical risk insights into clear, board‑level reporting.
- Manage cross‑functional collaboration with Operational Resilience, Engineering, and Cyber Operations teams.
- Maintain regulatory compliance and audit readiness across US, UK, EU, Japan, and other jurisdictions.
**Key responsibilities**
- Head and develop the global GRC team, setting performance and development standards.
- Design, maintain, and update policies, standards, and documentation to satisfy regulatory and audit requirements.
- Oversee vendor and third‑party due diligence, supplier notifications, and control assurance processes.
- Utilize tools such as SecurityScorecard, RiskConnect, and SharePoint for risk monitoring, reporting, and evidence management.
- Produce concise risk reports for senior stakeholders and the board, ensuring clarity and actionable insights.
- Collaborate with internal teams (Operational Resilience, Engineering, Cyber Ops) to integrate risk controls into operational processes.
- Monitor emerging regulations and frameworks (NIST, ISO 27001, CPMI‑IOSCO, CRI Cyber Risk Profile) and advise on necessary adjustments.
- Lead audit preparation and liaise with external auditors to ensure compliance and timely closure of findings.
**Required skills**
- Proven leadership of cyber risk and compliance functions in financial services or similarly regulated sectors.
- Deep knowledge of cyber risk frameworks (NIST, ISO 27001, CPMI‑IOSCO, CRI).
- Ability to synthesize complex technical risk into executive‑friendly communication.
- Strong organizational, documentation, and detail orientation.
- Proficiency with risk management platforms (SecurityScorecard, RiskConnect, SharePoint).
- Cross‑functional collaboration and stakeholder engagement skills.
**Required education & certifications**
- CISM – mandatory.
- CRISC, ISO 27001 Lead Implementer/Auditor, CISSP or CGEIT – advantageous.
- DORA or NIST CSF training – desirable.
- Bachelor’s degree in Information Security, Risk Management, or related field (or equivalent professional experience).
Edinburgh, United kingdom
Hybrid
06-11-2025