GRC Consultant
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
GRC Consultant (Governance, Risk & Compliance): Building a scalable compliance function for a growing software business with an accent on PCI DSS, GDPR, security governance, and audit readiness. Focus on designing practical policies and risk frameworks, closing compliance gaps, and coordinating enterprise security assessments.
Location: Hybrid or remote from the UK, with the role listed in London. Initial commitment is approximately three days per week.
Salary: £500–£600 per day.
Company
A digital recruitment and consultancy firm partnering with growing software businesses.
What you will do
- Review the existing compliance landscape, identify gaps, and create a practical roadmap.
- Build governance, risk, and compliance frameworks, including policies, procedures, documentation, and risk registers.
- Lead PCI DSS initiatives and improve GDPR processes and documentation.
- Support ISO 27001, SOC 2, and Cyber Essentials readiness, including audit preparation and evidence tracking.
- Manage client security questionnaires, compliance requests, renewals, and ongoing requirements.
- Coordinate external security assessments and penetration testing while advising leadership on regulatory requirements.
Requirements
- Proven experience building and managing GRC functions in growing technology or SaaS businesses.
- Hands-on knowledge of GRC, PCI DSS, GDPR, and security governance.
- Experience with ISO 27001, SOC 2, and/or Cyber Essentials.
- Background in policy creation, compliance documentation, risk management frameworks, and audit preparation.
- Ability to work independently and collaborate with multiple senior stakeholders.
- Availability for an initial three-month contract at approximately three days per week.
Nice to have
- Experience with Point of Sale compliance.
- Knowledge of French compliance or regulatory requirements.
- Experience supporting businesses operating across multiple European markets.
Culture & Benefits
- Opportunity to build a compliance function from the ground up and make a visible business impact.
- Embedded collaboration with senior stakeholders rather than working as an external consultancy.
- Initial three-month engagement with potential for ongoing retained work.
- Hybrid or remote working arrangement.
- Start as soon as possible.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →