GRC Consultant (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
GRC Consultant (Cybersecurity): Advising and supporting clients across governance, risk management, and regulatory compliance with an accent on aligning cyber and information security frameworks to UK-specific regulatory requirements. Focus on designing GRC frameworks, conducting maturity assessments, and ensuring operational resilience in critical infrastructure and finance sectors.
Location: Hybrid in Glasgow, United Kingdom
Company
is a leading provider of business technology solutions specializing in transformational change for Energy, Public, and Finance sectors.
What you will do
- Lead or support GRC maturity assessments, gap analyses, and audits against relevant standards and regulations.
- Translate UK-specific regulatory requirements into practical, implementable controls.
- Design and implement GRC frameworks covering risk management, policy, assurance, and reporting.
- Develop and maintain risk registers, control libraries, and assurance plans.
- Facilitate risk workshops and provide briefings to senior stakeholders.
- Produce evidence-based client deliverables, including reports and remediation roadmaps.
Requirements
- Proven experience in GRC roles within regulated or critical infrastructure environments.
- Strong understanding of the UK Oil & Gas and finance regulatory landscape.
- Working knowledge of ISO 27001, ISO 22301, UK NIS Regulations, NIST CSF, and UK GDPR.
- Experience conducting risk assessments and control gap analyses.
- Ability to engage confidently with technical, operational, and executive stakeholders.
- Experience working in consulting or advisory environments.
Nice to have
- Knowledge of IEC 62443 for OT/ICS security and industrial control environments.
- Familiarity with NCSC Cyber Assessment Framework (CAF).
- Certifications such as ISO 27001 Lead Implementer/Auditor, CISM, CRISC, or CISSP.
- Experience with GRC tooling such as OneTrust or Archer.
Culture & Benefits
- Personalized career development plans tailored to individual goals.
- Flexible working arrangements to support work-life balance.
- Comprehensive benefits package including generous annual leave and pension scheme.
- Access to private health, well-being, and insurance schemes.
- Inclusive culture focused on diversity and equal opportunities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →