Skip to Main Content
Location icon
London

Information Security Governance, Risk, and Compliance (GRC) Specialist

Janus Henderson
Office & Professional
Office & Professional
Negotiable
Company logo image
Description

Location
London

Hours
Full Time

Salary
Competitive, commensurate with experience

About the Role
A career at Janus Henderson is more than a job; it’s about investing in a brighter future together. Our mission is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service. We protect and grow our core business by amplifying our strengths and diversifying where we have the right. Our values—Clients Come First - Always, Execution Supersedes Intention, Together We Win, Diversity Improves Results, and Truth Builds Trust—are at the heart of everything we do.

As an Information Security Governance, Risk, and Compliance (GRC) Specialist, you will play a critical role in developing and maintaining cybersecurity policies and procedures aligned with industry standards and regulatory requirements. You will assist in integrating security practices across technical and non-technical departments to enhance workflows and operational processes.

Your responsibilities will include conducting regular risk assessments, collaborating on risk mitigation strategies, monitoring emerging threats, and designing control metrics to assess cybersecurity effectiveness. You will work closely with Enterprise Risk Management to embed cyber risk into broader risk registers and board-level reporting.

In compliance management, you will monitor adherence to internal policies, industry standards, and regulatory requirements, engaging with stakeholders in Technology, Legal, Compliance, and Internal Audit. You will compile and deliver detailed compliance reports to senior management and prepare compliance roadmaps for upcoming regulations.

You will support and enhance cybersecurity awareness training programs to foster a company-wide culture of security, keeping current with the latest trends and best practices. Additionally, you will actively participate in incident response, post-incident evaluations, and collaborate on corrective measures to strengthen defenses.

Effective stakeholder engagement is essential, requiring clear communication and expert guidance on cybersecurity best practices. You will work collaboratively with Technology and other departments to achieve comprehensive security objectives.

Janus Henderson is committed to an inclusive and supportive environment that values diversity and welcomes candidates from all backgrounds. We encourage applications even if you do not meet every qualification, and we support flexible working arrangements where possible.

Requirements

Experience
3 to 5 years of professional experience in information security, preferably within financial services.
Proven experience with cybersecurity principles, frameworks such as NIST and ISO/IEC 27001, and compliance standards.
Experience with financial service regulations including FCA, SEC, MAS, and DORA.
Proficient knowledge of network security principles and controls such as Firewalls, IPS/IDS, TCP/IP, DHCP, and DNS.
Extensive experience securing Operating Systems including Windows, UNIX/Linux, and Mac systems.
Knowledge of cloud service models (IaaS, PaaS, SaaS) and deployment models (public, private, hybrid, community) with experience implementing cloud security best practices.
In-depth knowledge of IAM principles and technologies, including Single Sign-On (SSO), Multi-Factor Authentication (MFA), and role-based access control (RBAC).
Understanding of Secure DevOps / CI/CD pipeline governance.

About you
Strong analytical and problem-solving skills with the ability to design and evaluate control metrics.
Excellent communication skills to engage and collaborate effectively with stakeholders at all levels.
Proactive and adaptable, keeping current with cybersecurity trends and regulatory changes.
Committed to fostering a culture of cybersecurity awareness and continuous improvement.
Ability to work independently and as part of a team in a dynamic environment.

Qualifications
Bachelor’s Degree in Information Technology, Cybersecurity, or a related field; equivalent work experience considered.
Certification such as Certified Information Systems Security Professional (CISSP) strongly preferred.
Understanding of regulatory obligations and compliance requirements applicable to the financial services industry.
Willingness to comply with Janus Henderson’s Investment Advisory Code of Ethics and related disclosure requirements.

Expiry date: 26/09/2026
Information Security Governance, Risk, and Compliance (GRC) Specialist
Company:
Janus Henderson
Job Type:
Full-time
Location:
London