Overview
In this role you will drive GWI’s security compliance strategy within the Legal team, reporting to the General Counsel. You will partner with Information Security, Product, and Technology to maintain a robust compliance posture and foster a security-minded culture. You’ll tackle governance across ISO 27001, vendor risk, and client security requirements, shaping how we work with clients and partners. This is a high-impact role at a fast-paced company that values continuous change and practical security leadership.
Pay / Benefits
- 25 days’ annual leave
- health cash plan
- 4% pension matching
- flexitime
- hybrid and remote options
- learning and leadership development
Responsibilities
- Own and maintain ISO 27001 certification and compliance across relevant security frameworks
- Develop, implement, and maintain information security policies and procedures
- Lead vendor risk management and client security assessments and onboarding
- Build and maintain security trust portal (Drata or Vanta) showcasing credentials
- Drive security awareness through training and internal communications
Key requirements
- 3–5 years in information security compliance
- Proven ability to develop and maintain security policies and procedures
- Experience conducting vendor security assessments and client onboarding requirements
- Hands-on experience with security trust portals and tools like Drata or Vanta is a plus
- Knowledge of SaaS and AI environments and cloud security best practices
- Strong communication skills to translate GRC topics internally
- strong communication
- adaptable/flexible
- comfortable in a high-tempo environment
- ISO 27001 certification expertise
- NIST framework knowledge
- security policies and procedures development
…
