Назад
Company hidden
обновлено 10 часов назад

GRC Consultant (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
c1
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

GRC Consultant (Cybersecurity): Advising and supporting clients across governance, risk management, and regulatory compliance with an accent on aligning cyber and information security frameworks to UK-specific regulatory requirements. Focus on designing GRC frameworks, conducting maturity assessments, and ensuring operational resilience in critical infrastructure and finance sectors.

Location: Hybrid in Glasgow, United Kingdom

Company

hirify.global is a leading provider of business technology solutions specializing in transformational change for Energy, Public, and Finance sectors.

What you will do

  • Lead or support GRC maturity assessments, gap analyses, and audits against relevant standards and regulations.
  • Translate UK-specific regulatory requirements into practical, implementable controls.
  • Design and implement GRC frameworks covering risk management, policy, assurance, and reporting.
  • Develop and maintain risk registers, control libraries, and assurance plans.
  • Facilitate risk workshops and provide briefings to senior stakeholders.
  • Produce evidence-based client deliverables, including reports and remediation roadmaps.

Requirements

  • Proven experience in GRC roles within regulated or critical infrastructure environments.
  • Strong understanding of the UK Oil & Gas and finance regulatory landscape.
  • Working knowledge of ISO 27001, ISO 22301, UK NIS Regulations, NIST CSF, and UK GDPR.
  • Experience conducting risk assessments and control gap analyses.
  • Ability to engage confidently with technical, operational, and executive stakeholders.
  • Experience working in consulting or advisory environments.

Nice to have

  • Knowledge of IEC 62443 for OT/ICS security and industrial control environments.
  • Familiarity with NCSC Cyber Assessment Framework (CAF).
  • Certifications such as ISO 27001 Lead Implementer/Auditor, CISM, CRISC, or CISSP.
  • Experience with GRC tooling such as OneTrust or Archer.

Culture & Benefits

  • Personalized career development plans tailored to individual goals.
  • Flexible working arrangements to support work-life balance.
  • Comprehensive benefits package including generous annual leave and pension scheme.
  • Access to private health, well-being, and insurance schemes.
  • Inclusive culture focused on diversity and equal opportunities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →