Overview
In this Principal GRC role, you will lead SCC’s growing GRC advisory practice, shaping offerings and guiding client engagements. You’ll translate regulatory complexity into pragmatic roadmaps, from scoping to board-ready outputs, influencing how the team works and grows. You’ll operate across board-level risk discussions and hands-on control design to deliver practical, risk-based recommendations. This position offers high impact in a dynamic, cross-functional environment with a strong focus on transformation and governance.
Pay / Benefits
- hybrid working
- 2 paid volunteering days per year
- broad flexible benefits scheme
- career development
- life-long learning opportunities
- competitive salary package
Responsibilities
- Help define and shape SCC’s GRC go-to-market strategy, including future service offerings and delivery approach
- Lead GRC consulting engagements across sectors with high-quality outcomes and actionable recommendations
- Act as a subject matter expert on ISO 27001, NIST, NCSC CAF and Defence Cyber Certification requirements
- Design and implement governance frameworks, policies, processes and controls
- Lead cyber risk assessments, maturity reviews and gap analyses with clear improvement roadmaps
- Support compliance programmes, audit readiness and certification preparation
- Contribute to bids, proposals, client presentations and solution design
- Help define future growth and hiring strategy for the GRC capability, including mentoring
- Engage with senior stakeholders to explain cyber risk and compliance clearly and practically
Key requirements
- Strong experience in Governance, Risk and Compliance within cyber security or technology risk
- Knowledge of ISO 27001, NIST, NCSC CAF, Cyber Essentials and related assurance schemes
- Experience leading risk assessments, control reviews, audits or security maturity assessments
- Ability to translate regulatory requirements into practical business actions for executives
- Previous consulting, advisory or client-facing delivery experience
- Excellent written and verbal communication with ability to produce executive-level reports
- Confidence operating from strategic to detailed control planning levels
- SC (Security Clearance) or willingness to undergo process for SC Clearance
- Qualifications such as CISSP, CISM, ISO 27001 Lead Implementer, CISSP-ISSAP or NCSC Practitioner preferred or pursued
- excellent communication
- stakeholder engagement
- ability to simplify complex concepts
- ISO 27001
- NIST
- NCSC CAF
…
