Salary – From £76,400 + annual bonus & benefits
Work Level - WL2
Location – Edinburgh, Reigate, Glasgow, Newcastle. Permanent.
Office Attendance - Our roles are hybrid; however, you should be able to travel to our office 1-3 days per week for this position.
Closing Date - Applications close on 6th August at 5pm
We’re looking for a Lead Security Engineering (GRC) Manager to join our Insurance, Money and Services team.
This is a senior security leadership role that will define and operate the IMS GRC engineering strategy, moving governance, risk and compliance from manual, point-in-time assurance towards engineering-led, automated and continuous assurance. You’ll lead across control engineering, compliance automation, security assurance and regulatory readiness, ensuring security requirements are embedded into platforms, products and services by design.
You’ll work closely with the CISO, senior technology leaders, engineering teams, risk, audit and suppliers to shape how IMS demonstrates security control effectiveness at scale. The role is pivotal in building a modern GRC engineering capability, introducing compliance-as-code, automated evidence collection, continuous controls monitoring and intelligent risk analytics across a complex regulated environment.
What you’ll be doing
• Own and evolve the IMS GRC engineering strategy and roadmap, including continuous controls monitoring, compliance automation, risk intelligence and assurance transformation.
• Translate security policies, standards and regulatory requirements into practical, technical and automatable controls across cloud platforms, CI/CD pipelines, engineering workflows and service operating models.
• Design and maintain automated control validation, evidence collection, compliance metrics and dashboards to provide real-time visibility of security posture and control effectiveness.
• Configure, extend and integrate GRC and assurance tooling with cloud, security, engineering and business platforms using APIs, JSON, scripting and automation workflows.
• Act as a trusted security advisor to engineering and platform teams, promoting secure-by-design, shift-left and reusable control patterns that reduce friction while maintaining strong assurance.
• Support audit, regulatory, supplier and incident response activity where control operation, evidence, ownership or compliance posture is impacted, and lead/develop GRC engineering capability as demand grows.
We need you to have (minimum experience)
• Strong experience in information security, GRC engineering, security assurance or compliance roles in regulated or complex environments.
• Proven ability to translate compliance, risk and regulatory requirements into technical, operational and automatable controls.
• Hands-on experience with security control frameworks, risk management, ISMS operation, audit support, control testing, GRC platforms and automated evidence collection.
• Technical proficiency in automation, APIs, JSON and at least one scripting or programming language, with a solid understanding of cloud, CI/CD, identity, infrastructure and application security fundamentals.
And if you have any of these, even better
• Experience designing continuous compliance or compliance-as-code solutions in AWS, Azure or hybrid environments.
• Experience leading, coaching and developing security, assurance or GRC engineering professionals.
• Familiarity with AI-assisted tooling and intelligent risk analytics to improve assurance, documentation and engineering efficiency.
• Professional certifications such as CISSP, ISO 27001 Lead Implementer/Lead Auditor, AWS/Azure certifications, cloud security specialisations, Infrastructure-as-Code or CI/CD tooling certifications.
We don’t expect you to tick every box, and if you feel you hit most of the brief, it’s worth exploring to further develop your career here with us.
What’s in it for you
• Prepare for your retirement with our colleague pension scheme.
• Virtual GP Service for you and your family 365 days a year.
• Performance related annual bonus.
• Indulge in a generous holiday allowance with a minimum of 7.2 weeks, with the opportunity to buy more.
• Embrace the benefits of our Colleague Clubcard, enjoy a 10% discount that increase to 15% every payday. As an added perk, we’ll give you a second card to share with someone else.
• Benefit from our family-oriented initiatives, encompassing enhanced maternity leave pay, a shared parental leave policy, and a generous 8-week paid paternity leave.
• A place to get on - take advantage of our ongoing learning opportunities and award-winning training, to help you achieve the job and career you want.
• Take part in our Buy as you Earn and Save as your Earn share schemes.
Everyone’s welcome
We want all our colleagues to always feel welcome and be themselves. We’re committed to building a more inclusive workplace and celebrating everything that makes colleagues unique, and value the richness and diversity this brings to our business. A more diverse business helps us deliver on our purpose to serve our customers, communities, and planet a little better every day.
Interviews
We know the importance of balancing work with life’s other commitments. Please talk to us at interview about the flexibility you need, as we’re committed to exploring part time and flexible working opportunities, at every level of the organisation.
Interviews are expected to be held shortly after closing date.