As an Information Security Risk Manager with deep expertise in developing effective GRC capabilities, I help senior leaders enhance decision-making and control by focusing on integrating culture, process, and technology. I work across industries - from start-ups to multinational corporations - helping organisations manage risks in a way that strengthens operational resilience, compliance, and profitability.My approach goes beyond technology and third-party risk management; it encompasses the full spectrum of operational and enterprise risks, providing practical, measurable strategies and controls that influence insider and third-party behaviours. By focusing on clear, data-driven methods, I support senior management in aligning risk management with broader business objectives, ensuring that risk management decisions are always in line with the company's strategic direction.I have extensive experience across all business sizes, from start-ups to multi-national listed companies, in sectors including financial services, critical national infrastructure, third-sector, healthcare and academia. I have helped organisations comply with regulations and frameworks such as GDPR, CCPA and the ISO27k and 31k suite, all while driving operational efficiency and reducing risk exposure. My aim is not just to manage risk but to simplify and demystify risk management, empowering businesses to make informed decisions that support long-term success.I support organisations throughout the GRC journey, including:• Advocating and advising for building out a GRC capability or function, including creating a business case for funding;• Creating a strategy and roadmap;• Writing policies and standards;• Training and socialisation;• Interviewing job applicants;• Implementing and integrating GRC software;• Reviewing and delivering positive change in existing functions;• Building risk quantification capabilities;• Interim leadership roles;• ISO27k preparedness.Let's connect if you're looking for an independent and experienced risk consultant who can develop scalable, adaptable risk solutions tailored to your organisation's unique challenges.
Listed skills include Financial Risk, Financial Advisory, Financial Services, Personnel Management, and 31 others.