Overview
As a GRC Consultant, you will ensure security controls are designed, implemented, and operating effectively to enable business goals safely. You will drive governance, risk and compliance across policy and standard frameworks, collaborating with cross-functional teams to manage cyber risk. The role focuses on continuous assessment, evidence-based reporting, and improving security controls to support scalable, secure IT services. You will contribute to a culture of responsible innovation and security excellence within a global organization.
Responsibilities
- Provide security expertise across standards and accreditations and maintain the Information Security Management System (ISMS)
- Develop Information Security Management Plans incorporating Regulatory, Legal and Compliance requirements
- Identify and analyze risks and emerging cyber threats to drive risk mitigation
- Ensure partner and supplier adherence to standards, policies, and security KPIs
- Collaborate with 1st/2nd/3rd lines of defence on cyber security, data privacy, and regulatory considerations
- Lead development and enhancement of governance, risk and compliance aligned to policy and industry best practices
- Produce and report useful risk-based metrics for informed decision making
- Challenge and improve processes to ensure security risk mitigation responsibilities are understood
- Maintain documentation relating to security controls and processes
- Develop and maintain ISM practices to achieve required industry standards (e.g., ISO 27001)
- Propose, sponsor, and implement policy/procedure changes to safeguard IT services and assets
- Perform focused information risk assessments for existing/new services with Operational/Service Management and SMEs
- Include third-party supplier security assessments during onboarding and lifecycle
- Coordinate audits, ITHC and risk assurance to evidence regulatory compliance and remediation actions
- Maintain strong relationships across in-scope services and suppliers
- Chairs/coordinates the Security Working Group (SWG) and participates in governance forums
- Contribute to data protection risk analysis and incident response activities
Key requirements
- Track record delivering security solutions for large-scale infrastructure, transformation, or integration programmes
- Practical knowledge of security frameworks such as NIST CSF, NIST 800-53, NCSC CAF
- Knowledge of networking (switching, routing, firewalls)
- Deep understanding of modern security concepts, attack vectors, malware, threat intelligence
- Experience with security testing and vulnerability management (e.g., pen testing/ITHC, CVSS/CVE)
- Experience with ISO 27001/27002/27017/27108 or equivalent standards
- Desirable experience with Cloud platforms (AWS/Azure) and cloud security practices
- Certifications like CISSP, CISM, CCSP, CRISC or equivalent
- Knowledge across AD, Cryptography, IAM, PKI, Server hardening, SIEM/SOAR, virtualization
- Familiarity with MITRE ATT&CK and ITIL
- Stakeholder management
- Analytical mindset
- Collaborative problem solving
- NIST CSF
- NIST 800-53
- NCSC CAF
…
