Himalayas logo
JM
Open to opportunities

Jason Moseley

@jasonmoseley

Information security and risk professional specialising in ISO27001, TPRM, and IT audit assurance.

United Kingdom
Message

What I'm looking for

I seek senior GRC or information security roles where I can lead ISO27001 programmes, mature TPRM, influence stakeholders, and drive measurable risk reduction.

I am an information security and cyber risk professional with extensive experience across 2nd and 3rd line assurance, IT audit, ISO27001 implementation, third-party risk management, and control testing. I have led certification efforts, designed GRC frameworks, scoped and delivered TPRM programmes, and advised senior stakeholders to strengthen security posture.

My background includes roles delivering enterprise risk registers, executing supplier audits, and acting as lead auditor for ISO27001/9001 programmes. I combine technical assessment skills (including control testing and gap analysis) with strong stakeholder engagement to achieve measurable reductions in vendor and organisational risk.

Experience

Work history, roles, and key accomplishments

NB

ISO 27001 & 9001 Auditor

NQA Certification Body

Oct 2024 - Jul 2025 (9 months)

Conducted independent audits of organisations' ISMS against ISO 27001 and assessed documentation, controls, and operational practices to determine certification readiness and continued compliance.

FI

Cyber Security Risk Manager

Flutter International

Jan 2022 - Apr 2022 (3 months)

Managed IT risk registers, chaired the Top Risk Working Group, conducted gap analyses and risk treatment planning, and closed outstanding audit actions to prepare for ISO27001 recertification.

AI

IT & Information Security Risk Manager

Allianz Insurance

Apr 2020 - Jan 2022 (1 year 9 months)

Led IT and information security risk activities including RCSAs, CBEST remediation, control testing (COBIT 5), and management of risk registers to align cybersecurity controls with business objectives and NIS2 obligations.

GR

Internal Audit & Systems Manager

Grundon

Jun 2015 - Mar 2016 (9 months)

Maintained ISO9001, ISO27001, ISO14001 and OHSAS/18001 standards across the business and managed internal audit and systems compliance activities.

BSI Group logoBG

Certified Lead Auditor

Apr 2014 - Jul 2015 (1 year 3 months)

Performed audits against ISO27001 and ISO9001 standards as a certified lead auditor, evaluating organisational compliance and recommending improvements.

Education

Degrees, certifications, and relevant coursework

Jason hasn't added their education

Don't worry, there are 90k+ talented remote workers on Himalayas

Tech stack

Software and tools used professionally

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan
Jason Moseley - GRC Specialist - SEFE Gas Distribution Company | Himalayas