06/08/2026 updated

PL
100 % available

Enterprise Security & GRC Architect | ServiceNow IRM Architect | Global Control Framework Leader

Warrington, England, United Kingdom
Worldwide
Professional Certifications: ISO27001 Lead Implementer, Lead Auditor & Internal Auditor; Certified Data Privacy Solutions Engineer (CDPSE)
Warrington, England, United Kingdom
Worldwide
Professional Certifications: ISO27001 Lead Implementer, Lead Auditor & Internal Auditor; Certified Data Privacy Solutions Engineer (CDPSE)

Profile attachments

Paul Lawson - CV - v1.21.pdf

About me

Enterprise GRC Architect, ISO 27001 Lead Consultant and ServiceNow IRM Architect with 25+ years' experience. Led the world's largest ISO 27001 programme (70+ countries, 300+ sites). Specialist in NIS2, DORA, cyber risk, governance, compliance and operational resilience.

ISO/IEC 27001Iso/iec
Enterprise Security Governance & GRC Architecture
Expertise in designing and implementing enterprise security governance frameworks, global control framework architecture, and GRC capabilities across critical infrastructure and highly regulated environments, including the world's largest ISO/IEC 27001 certification programme spanning 70+ countries and 300+ locations.

ServiceNow IRM Architecture
Deep technical expertise in ServiceNow IRM, architecting enterprise GRC data models and governance architectures including UCF-aligned common control frameworks, authority documents, compliance models, entity hierarchies, policies, issue management models, and risk models.

Regulatory Compliance & Cyber Risk Management
Extensive knowledge of international regulatory frameworks including ISO/IEC 27001:2022, NIST CSF 2.0, EU NIS2 Directive, DORA, Cyber Resilience Act, PCI-DSS, GDPR, CMMC 2.0, NERC CIP, and MLPS 2.0, enabling consistent governance and compliance assurance across global business units.

Global Common Control Framework Design
Design and implementation of a Global Common Control Framework (CCF) aligning 30+ international security, privacy, resilience, and regulatory standards, enabling standardised control validation and multi-standard compliance assessment across organisations.

Operational Resilience & Critical Infrastructure Protection
Delivery of cybersecurity governance and assurance programmes supporting critical national infrastructure, including authoring Covered Information Protection Plans under U.S. National Security Agreement requirements aligned to NIST SP 800-171 Rev. 3 and OT security controls.

ISO/IEC 27001 Audit & Certification Programmes
Certified ISO27001 Lead Implementer, Lead Auditor, and Internal Auditor with hands-on experience recovering and delivering delayed surveillance audit programmes, conducting gap analysis, internal audits, and validating compliance with ISO/IEC 27001 Clauses 4-10 and Annex A controls.

Supplier Assurance & Third-Party Cyber Risk
Establishment of Supplier Assurance Frameworks to assess and manage third-party cyber risk, including supplier security due diligence questionnaires aligned to ISO/IEC 27001 controls and leveraging SecurityScorecard for independent external security posture assessment.

Board-Level Cyber Risk Reporting & Governance Dashboards
Development of board-level cyber risk reporting including enterprise risk heatmaps, governance dashboards, compliance reporting, and executive cybersecurity dashboards for global cybersecurity leadership and C-Suite visibility.

OT Security & Identity Security
Subject matter expertise across Operational Technology (OT) security within global enterprise and critical infrastructure environments, as well as implementation of Privileged Access Management (PAM) solutions such as Thycotic to secure privileged accounts and enforce least-privilege access principles.

Data Protection & Privacy
Certified Data Protection Officer (C-DPO) and Certified Data Privacy Solutions Engineer (CDPSE) with expertise in GDPR, ISO27701 PIMS, California Consumer Privacy Act (CCPA), Japan APPI, and EU AI Act, supporting privacy governance and data protection compliance.

Languages

EnglishNative speaker

Project history

Enterprise Information Security & GRC Consultant

Hitachi Energy
Lead consultant and architect for the world's largest ISO/IEC 27001 certification programme spanning 70+ countries and 300+ locations. Designed and implemented a Global Common Control Framework (CCF) aligning multiple international standards. Architected enterprise cyber risk model in ServiceNow IRM, developed board-level cyber risk reporting, authored global information security policies and standards, and delivered cybersecurity governance supporting U.S. National Security Agreement requirements.

Field Service Engineer (Windows technologies)

IBM
Field Service Engineer specialising in Windows technologies for IBM for approximately 2 years.

Assistant IT Helpdesk Manager

Railtrack
Assistant IT Helpdesk Manager at Railtrack for approximately 1 year.

On-site IT Engineer

Computacenter c/o TSB Bank
On-site IT Engineer for Computacenter c/o TSB Bank for approximately 2 years.

IT Helpdesk Analyst

Technology plc
IT Helpdesk Analyst for Technology plc for approximately 2 years.

Trainee Computer Technician

Glaxo Wellcome Foundation
Trainee Computer Technician for the Glaxo Wellcome Foundation for approximately 2 years.

ISO27001 Consultant

Baringa
Recovered and delivered a delayed ISO/IEC 27001 surveillance audit programme by rebuilding core ISMS governance processes, conducting gap analysis and internal audits, implementing risk management and corrective action frameworks. Implemented Thycotic PAM and Alert Logic MDR. Established a Supplier Assurance Framework leveraging SecurityScorecard for third-party cyber risk management.

Director of Security

PAY.UK
Established PAY.UK's security governance and assurance capability, designing and implementing an ISO/IEC 27001-aligned ISMS supporting the UK's payments Critical National Infrastructure (CNI). Led a comprehensive security transformation programme and developed executive-level cyber risk and security governance reporting for the C-Suite.

Cyber Security Consultant

Barclays Bank
Led a 10-person security team applying NIST SP 800-53 and CIS Controls across enterprise platforms including Windows, Infoblox, and AWS, reviewing Golden Secure Builds and advising engineering teams on secure configuration standards and platform hardening.

Information Security Manager (Smart Metering)

Amey
Acted as Business CISO for a UK Smart Metering programme, designing and implementing an ISO/IEC 27001 aligned ISMS from inception through to successful certification. Implemented ISMS and GRC tooling, established security governance forums, and developed organisation-wide security awareness and training programmes.

Interim Compliance Officer

Barclays Bank
Delivered enterprise audit, risk, compliance, and control assurance reporting across Barclays technology functions. Performed control effectiveness assessments and compliance reviews. Built deep expertise in SOX, IT governance, IT service management, operational resilience, risk management, and control assurance within a highly regulated financial services environment.

Various Roles (Senior Network Security Manager, Service Delivery Manager, Senior Windows AD / Name Resolution SME)

Lloyds Banking Group
Held various roles at Lloyds Banking Group from 1999 to December 2016, including Senior Network Security Manager for 6 years, Service Delivery Manager for 2 years, and Senior Windows AD / Name Resolution SME for 11 years.

Certificates

ISO27001 Certified ISMS Lead Auditor (CIS LA)

GASQ

2023

ISO27001 Certified ISMS Lead Implementer (CIS LI)

GASQ

2023

ISO27001 Certified ISMS Internal Auditor (CIS IA)

GASQ

2023

ISO27005 Certified ISMS Risk Management (CIS RM)

GASQ

2023

PCI Implementation & Maintenance (PCI IM)

GASQ

2023

EU GDPR Foundation (GDPR F)

GASQ

2023

Certified Data Protection Officer (C-DPO)

GASQ

2023

Certified Data Privacy Solutions Engineer (CDPSE)

ISACA

2023


Contact form

Log in to get in touch

You need to be logged in to use the contact form.

Sign upLog in