Jobs
My ads
My job alerts
Sign in
Find a job Career Tips Companies
Find

Information security specialist grc

Slough
UK National Audit Office
Information security specialist
Posted: 12h ago
Offer description

Role: Information Security Specialist: GRC

Type of contract: Full Time, permanent

Location: Hybrid working. On-site, London or Newcastle, minimum 2 days pw

Salary: London c£68,000 Newcastle c£59,000 plus Civil Service employer pension contribution of 28.9%


Selection Process


1. Application


Candidates are required to submit their CV and covering letter on the essential criteria above by 11.59 pm 26th October 2025.


2. Screening


An initial screening will be conducted to check the eligibility of candidates & based on the role. Only candidates who meet these criteria will proceed to the next stage.


3. Assessment


Were looking to hold two assessments- Phone interviews and Final interviews. Phone interviews will be held on the 3rd and 4th November and final stage interviews will be held at our offices in Victoria on the 10th and 11th of November.


To be considered under the Disability Confident scheme should confirm this when submitting their application. Under this scheme we guarantee an interview to an applicant with a disability who meets the minimum requirements for the role. You should also let our HR team know if you wish us to consider any Reasonable Adjustments at any stage of the process (HR Service Desk (HRServiceDesk@nao.org.uk).


Applicants will not be discriminated against on the grounds of any protected characteristic or any other extraneous factor.


Nationality Requirement:

• UK Nationals

• Nationals of Commonwealth countries who have the right to work in the UK

• Nationals from the EU, EEA or Switzerland with (or eligible for) status under the European Union Settlement Scheme (EUSS)


Please note, we are not able to sponsor work visas or accept temporary visas as we are looking to hire on a permanent basis. Please contact the HR Service desk (hrservicedesk@nao.org.uk) should you have any questions on your nationality eligibility.


In a nutshell - Who are we looking for

As a GRC Specialist at the NAO, you’ll play a critical role in delivering and maintaining effective governance, risk, and compliance activities. This is a hands-on role for someone who takes initiative, communicates with confidence, and works seamlessly across technical and non-technical teams.


The successful candidate will be able to work both independently but will also contribute within team environments and will support the shared goals of the team both within technical and procedural control areas, and input into the continued development of this critical function.


Context and main purpose of the job:

Secure the Future. Shape the Cloud. Drive Innovation.

In a world where cyber challenges and opportunities are constantly evolving, we are committed to staying ahead of the curve. With new investments aimed at enhancing the NAO’s security maturity, our Information Security team is expanding. This is your chance to join a dynamic organization with clear strategic objectives and help advance our data use and embrace new technologies securely.


We’re not just growing—we’re evolving. As part of a forward-thinking organisation with a strong mandate to harness data and embrace cutting-edge technologies, our InfoSec team is central to enabling and securing the NAO’s digital future.


We’re on the lookout for passionate, curious, and collaborative security professionals across a wide range of specialisms. Whether your expertise lies in governance, engineering, threat detection, or cloud security, you’ll find real scope to make an impact—both within InfoSec and across the wider organisation.

•Be part of a diverse and expanding team that thrives on challenge and innovation.

•Work in a complex, data-rich environment where your insights will shape national-level outcomes.

•Help embed security into every layer of our digital transformation—from strategy to code.


This is more than a job. It’s a chance to help define the future of security at the NAO and be part of a high performing, collaborative, and innovative team.


Relationships:

Reporting to: Head of Information Security / Information Security Manager: GRC

Internal: Close working relationships with Infosec peers, Digital Services, Internal Communications, Procurement, development teams and the broader organisation.

External: NAO suppliers, vendors, and peers in similar organisations.

Resources Managed: None


The Role:

Governance

•Maintain and update security policies, procedures, and guidelines to ensure alignment with regulatory and business requirements.

•Report on risk and compliance status to relevant stakeholders.

•Support the development and management of a network of Security Champions to promote awareness and embed best practices.

•Foster a security-aware culture through effective communication and engagement strategies.


Risk Management

•Conduct risk assessments across systems, processes, and new and existing third parties, ensuring alignment with Infosec policies and frameworks.

•Maintain the risk register, ensuring risks are owned, have treatment plans, and are actioned in a timely manner.

•Improve and maintain risk dashboards to enhance visibility and reporting.

•Supporting the wider organisation with its treatment of Information Security risks across all change and BC/DR plans.


Compliance

•Drive continuous improvement of security awareness training and compliance initiatives.

•Support the management and maintenance of ISO/IEC 27001 certification and related compliance frameworks.

Product Assurance

•Deliver security-focused product assurance, ensuring standardised best practices and non-functional requirements are embedded in tools and services.

•Ensure projects are risk-assessed, have defined security requirements, and track mitigation activities.

•Conduct information asset inventory assessments to verify security controls and compliance alignment.


Supplier Assurance

•Manage and deliver on going cyclical supplier assurance schedules ensuring assessments are conducted in line with risk profile.

•Monitor supplier security posture and recommend appropriate technical and organisational controls to mitigate risk.

•Collaborate with business units and Procurement to advise on supplier risk, support onboarding, and manage remediation efforts.


Key skills/competencies required:

Essential:

•Minimum 3 years’ experience in a governance, risk and compliance role, or similar information security role.

•SME in risk management, confident in providing guidance on the identification, assessment, and mitigation of information security risks across systems, processes, and third-party engagements.

•Experience with and strong knowledge of ISO/IEC 27001, NIST CSF 2.0, or Cyber Essentials/Plus, with up-to-date understanding of security best practices.

•Demonstrate a solid understanding of Governance, Risk, and Compliance (GRC) processes, including policy development, risk assessments, control monitoring, and regulatory compliance frameworks.

•Able to confidently communicate complex technical concepts in a clear, business-friendly manner, and collaborate effectively with both technical and non-technical stakeholders across the organisation.

•Self-motivated and curious, with a proactive mindset and a strong commitment to driving good security practices, continuous improvement, and meaningful organisational change.

•Strong team player who upholds team culture and values and collaborates effectively across multidisciplinary teams including both InfoSec, tech and non-technical functions.

•Current SC Security Clearance, or able to achieve SC clearance.


Desirable

•Familiarity with GRC platforms such as OneTrust, ServiceNow GRC, LogicGate, with experience supporting risk, compliance, and data privacy workflows.

•Understanding of GDPR and data protection principles.

•Ability to identify, suggest, and drive improvements in GRC and information security processes.

•Holding a relevant degree or professional certification, such as, CISSP, CISM, CISA, CRISC, CIA.

•Familiarity with Microsoft security stack is advantageous.

•Experience in or with public sector, big four audit firms or similar is advantageous.


To view the full JD and apply please click on the link that will bring up the application page.

Apply
Create E-mail Alert
Job alert activated
Saved
Save
Similar job
Cybersecurity information security specialist
Watford
Permanent
Skanska
Information security specialist
€60,000 a year
Similar job
Senior cybersecurity & information security specialist
Watford
Permanent
Skanska
Information security specialist
€60,000 a year
See more jobs
Similar jobs
It jobs in Slough
jobs Slough
jobs Berkshire
jobs England
Home > Jobs > It jobs > Information security specialist jobs > Information security specialist jobs in Slough > Information Security Specialist GRC

About Jobijoba

  • Career Advice
  • Company Reviews

Search for jobs

  • Jobs by Job Title
  • Jobs by Industry
  • Jobs by Company
  • Jobs by Location
  • Jobs by Keywords

Contact / Partnership

  • Contact
  • Publish your job offers on Jobijoba

Legal notice - Terms of Service - Privacy Policy - Manage my cookies - Accessibility: Not compliant

© 2025 Jobijoba - All Rights Reserved

Apply
Create E-mail Alert
Job alert activated
Saved
Save