GRC Consultant
Location: London/ Hybrid
Salary: Up to 85,000 DOE
We're looking for a GRC Consultant to come aboard and use your background in Governance, Risk & Compliance. You will help with the following:
Governance
Direct, oversee, design, implement, or operate within the set of multi–disciplinary structures, policies, procedures, processes, and controls implemented to manage cyber and information security at an enterprise level. Support an organisation's immediate and future regulatory, legal, risk, environmental, and operational requirements and ensure compliance with those requirements.
Policy and Procedure Management
Direct, develop, or maintain organisational cyber and information security policies, standards, and processes, using recognised standards (e.g., the ISO/IEC 27000 family, NIST CSF) where appropriate. Apply recognised cyber and information security standards and controls within an organisation, programme, project, or operation.
Risk Management
Develop cyber and information security risk management strategies and controls, considering business needs, balancing technical, physical, procedural, and personnel controls. Identify and assess information assets, threat–specific information, business impacts, business benefits, and costs to identify and assess potential vulnerabilities and risks.
Data Privacy
Direct, oversee, design, implement, contribute to, or operate within the set of multi–disciplinary structures, policies, procedures, processes, and controls to manage the protection of personal data, privacy, and human rights. Support regulatory, legal, risk, environmental, and operational requirements and ensure compliance with those requirements (e.g., GDPR, Data Protection).
Internal Controls Oversight
Establish and monitor internal controls to safeguard data and assets, conducting regular reviews and audits.
Stakeholder Engagement
Serve as a liaison, offering guidance and support to internal teams, external partners, and regulatory authorities. Provide remediation guidance and prepare management reports to track remediation activities.
Continuous Improvement
Identify opportunities for process enhancements, driving initiatives to bolster governance framework and security posture. Assess and test the effectiveness of security controls, and document compliance levels to identify risks and control gaps.
You will need to have a broad experience of security risk management and evidence of experience in a number of the following fields of expertise:
1. Strong understanding of security governance, risk, and compliance frameworks such as ISO 27001, NIST 800–53/CSF, NIS/NIS2, DORA, UK CNI/OT/IIOT compliance.
2. Hands–on experience building credibility with external stakeholders, including enterprise clients, critical system vendors, certification auditors, and regulatory bodies.
3. Proven leadership skills with the ability to guide and mentor teams, as well as influence and collaborate with senior stakeholders in a similar GRC, security, or risk management role.
4. A hands–on approach with the ability to balance strategic oversight with direct involvement in security tasks.
5. Excellent communication skills, with the ability to present complex information clearly and effectively to non–technical stakeholders.
6. The ability to explain complex topics to a diverse range of audiences.
7. Strong attention to detail and the ability to deliver high–quality work.
8. A valid right to work in the UK.
9. Eligibility to obtain UK SC clearance.
10. CISA, CRISC, CISM, or CISSP certification is advantageous.
#J-18808-Ljbffr