TL;DR
GRC Specialist: Responsible for the day-to-day execution of governance, risk, and compliance (GRC) activities, including audit preparation, evidence collection, and security questionnaires, with an accent on addressing audit requests and client inquiries promptly and consistently. Focus on ensuring risks, exceptions, and remediation actions are logged and tracked to completion to provide a strong operational foundation for the Risk & Compliance program.
Location: Hybrid, Edinburgh, GB
Company
hirify.global is a global leader in analytics, insights, and proprietary data across the energy and natural resources landscape, guiding decisions for influential energy producers, utilities, financial institutions, and governments.
What you will do
- Execute day-to-day governance, risk, and compliance (GRC) activities.
- Prepare for SOC2 and other internal audits, collecting and organizing evidence.
- Track remediation items from audits and ensure timely closure with responsible teams.
- Coordinate responses to customer and third-party security questionnaires.
- Update and maintain the cyber risk register, recording new risks and tracking progress.
- Contribute data for quarterly risk and compliance dashboards and highlight overdue items.
Requirements
- Experience in IT audit, compliance, or GRC operations.
- Familiarity with audit frameworks such as SOC2, ISO 27001, and GDPR.
- Strong organizational skills for evidence collection and tracking.
- Ability to manage multiple concurrent requests and deadlines.
- Clear written communication for client questionnaires and reports.
- Experience in SaaS, data analytics, or regulated industries.
- Exposure to vendor/supplier risk assessments.
- Experience using GRC platforms (e.g., ServiceNow GRC, Archer).
Culture & Benefits
- Inclusive, Trusting, Customer committed, Future Focused, and Curious values.
- Committed to equal opportunities regardless of race, colour, religion, age, sex, national origin, disability or protected veteran status.
- Support for applicants with physical or mental disabilities through the hiring process.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →