GRC Consultant
$65,000–$90,000 year
HybridLondon, England, United Kingdom
Job Summary
Advise clients on cybersecurity governance, risk management, and compliance frameworks including ISO 27001, NIST, GDPR, DORA, and PCI DSS. Conduct risk assessments, control gap analyses, and audits while developing information security policies, procedures, and risk registers. Lead engagements for regulatory compliance and support third-party vendor risk assessments and due diligence. Prepare reports and recommendations for CISO, board, and audit committee presentations, and collaborate with technical teams to align risk controls with business strategy. Contribute to certification readiness and internal audit programs. This role supports clients across multiple sectors to improve risk posture through robust information security governance.
Required Qualifications
- In-depth knowledge of ISO 27001, NIST CSF, GDPR, and risk management frameworks
- Experience performing security risk assessments, internal audits, and compliance reviews
- Strong understanding of cybersecurity controls, regulatory mandates, and business risk alignment
- Excellent client communication, stakeholder management, and reporting skills
- Familiarity with GRC platforms (e.g., RSA Archer, ServiceNow GRC, LogicGate)
Desired Qualifications
- Certifications such as CISM, CRISC, ISO 27001 Lead Auditor, or similar
- Experience working with financial services, healthcare, or SaaS industries
- Understanding of emerging regulations (e.g., DORA, NIS2, AI Act)
- Cloud compliance knowledge (e.g., CSA CCM, AWS/Azure/GCP compliance)
- Familiarity with SOC 2, PCI DSS, HIPAA frameworks
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.