Information Security Business Change Partner (GRC)

Company: Computappoint
Apply for the Information Security Business Change Partner (GRC)
Location: London
Job Description:

  • Contract
  • Hybrid – Central London
  • Highly competitive day rate
Our client, a prestigious global law firm, is seeking a talented Information Security Business Change Partner to join their Information Security team in London. This is a fantastic opportunity to play a pivotal role in ensuring that transformation and business-as-usual (BAU) projects are delivered securely, in line with the firm’s Information Security policies and standards. You will act as the trusted security advisor across projects, helping protect critical legal, corporate, and fiduciary data while supporting a truly global firm with offices spanning the Americas, Europe, the Middle East, and Asia.

Job Title: Information Security Business Change Partner (GRC)
Job Type: Contract
Rate: competitive day rate
Working arrangement: Hybrid
Office Location: Central London

The Role:
  • Serve as the single point of contact for assigned projects, managing all security considerations from initiation to closure.
  • Oversee security aspects across the full project life cycle: engagement, planning & requirements, build, security assurance, project delivery, and transition – in accordance with Change Governance Framework.
  • Conduct thorough risk assessments and manage residual project risks post-closure.
  • Prepare clear, concise reports suitable for senior leadership and stakeholders.
  • Ensure projects align with the firm’s Information Security policies and standards while enabling secure business transformation.
What We’re Looking For
  • Proven experience in a similar Information Security Business Change/GRC role, ideally within professional services, legal, or financial sectors.
  • Strong understanding of project life cycles, including engagement, planning & requirements, build, security assurance, delivery, and transition.
  • Demonstrable expertise in managing security considerations, risk assessments, and producing senior-level reporting.
  • Excellent stakeholder management skills with the ability to influence and collaborate across technical and business teams.
  • A proactive, solution-focused mindset with the ability to balance security requirements with business needs.
  • Relevant professional certifications (eg, CISSP, CISM, CRISC, or equivalent GRC qualifications) would be advantageous, as would familiarity with legal or regulated environments.

Services offered by Computappoint Limited are those of an Employment Business and/or Employment Agency in relation to this vacancy.

Computappoint do not use AI to filter or assess candidates, we use experienced and dedicated recruiters, who want to match the best people to roles.

Posted: March 26th, 2026