CGRC Lead
Cyber Governance, Risk & Compliance (GRC) Lead
Location: Hybrid – Leeds with UK travel Salary: £50,000–£60,000 + Car Allowance + Bonus + Benefits
Elevation Tech & Transformation are exclusively recruiting for a newly created Cyber Governance, Risk & Compliance (GRC) Lead on behalf of a growing UK organisation.
Reporting to the GISO, you’ll take ownership of cyber governance across the Group, working across multiple subsidiaries to strengthen security, risk and compliance practices.
This is a hands-on, relationship-led role . We’re looking for someone dynamic and pragmatic who is comfortable getting out into the business, building relationships with local teams and turning cyber frameworks into practical improvements.
Key Responsibilities
- Own and develop the Group cyber risk register.
- Develop and embed security policies, standards and governance processes.
- Apply NIST CSF and CIS Controls in a real-world environment — practical implementation experience is essential.
- Support alignment with NIST CSF, CIS Controls and ISO 27001 .
- Conduct cyber risk assessments across projects, systems and suppliers.
- Travel to subsidiaries and sites across the UK, building relationships and improving cyber maturity.
- Coordinate audits, assurance and compliance activity.
- Provide clear cyber risk and assurance reporting to senior leadership.
- Support third-party security assurance and supplier risk management.
About You
You’ll have proven experience in Cyber GRC , with demonstrable hands-on experience using NIST CSF and CIS Controls to assess, improve or implement security controls.
We’re looking for someone who is:
- Practical and commercially minded, rather than purely policy-focused.
- Confident engaging with technical, operational and senior stakeholders.
- Dynamic and relationship-driven , with the confidence to get out into subsidiaries and build trust.
- Experienced in cyber risk assessments, policies and security governance.
- Comfortable working autonomously and driving change across multiple businesses.
Experience with ISO 27001, GDPR/NIS2, Microsoft 365/Azure, GRC platforms or certifications such as CISA, CISSP or CRISC would be advantageous.
This is a fantastic opportunity to join a growing organisation where you’ll have genuine ownership and the opportunity to shape cyber governance across the Group .