At a Glance
- Tasks: Lead the development and management of governance, risk, and compliance frameworks.
- Company: Respected tech provider specialising in secure IT infrastructure for defence and public sectors.
- Benefits: Comprehensive benefits, tailored training, and structured career coaching for professional growth.
- Other info: Opportunity to work with cutting-edge technology and enhance your career in a supportive culture.
- Why this job: Make a real impact by ensuring compliance and mitigating risks in a dynamic environment.
- Qualifications: 5+ years in GRC or related fields with strong analytical and communication skills.
The predicted salary is between 63000 - 77000 Β£ per year.
The GRC Manager will take ownership of developing, implementing, and maintaining the organisation's governance, risk management, and compliance frameworks. You will ensure operational activities align with legal requirements, regulatory standards, and internal policies, while proactively identifying and mitigating enterprise risks.
Key Responsibilities:
- Develop, implement, and manage the overarching GRC strategy, policies, and procedural frameworks.
- Conduct enterprise risk assessments and maintain the organisation's central risk register.
- Monitor operational, regulatory, cybersecurity, financial, and third-party risks.
- Ensure full compliance with relevant statutory regulations, legal standards, and framework requirements.
- Coordinate internal and external audit activities, managing the swift remediation of findings.
- Establish compliance monitoring mechanisms and present regular reporting to senior leadership.
- Collaborate with internal business units to design and embed effective risk mitigation controls.
- Monitor regulatory developments and assess their potential operational impact.
- Support business continuity, disaster recovery, and information security governance initiatives.
- Oversee third-party/vendor risk evaluations and perform required due diligence.
- Lead organisation-wide training programmes to promote a strong security and compliance culture.
Required Skills and Experience:
- Minimum of 5 years demonstrable experience within GRC, Information Security, Audit, or Risk disciplines.
- Thorough understanding of enterprise risk management frameworks and internal audit processes.
- Proven hands-on experience with GDPR compliance (including ROPA, LIA, and DPIA requirements).
- Excellent analytical, problem-solving, and senior stakeholder management abilities.
- Experience utilising modern GRC software platforms and risk mapping tools.
- Desirable: Exposure to Defence Cyber Certification (DCC), Cyber Essentials (CE), or Cyber Essentials Plus (CE+).
- Familiarity with Secure by Design (SbD) principles and JSP 453 assurance activities.
- Understanding of vendor risk management, SOC2, or NIS2 directives.
- Previous experience performing duties as a Crypto Custodian or Alternate Custodian.
- Relevant industry certifications such as CISA, CRISC, CISM, or CISSP.
Governance and Compliance Manager employer: Bulb Resourcing
Join a leading technology provider as an Infrastructure Engineer, where you will thrive in a collaborative and innovative environment that prioritises continuous improvement and data security. With a strong focus on employee development, this role offers the chance to work with cutting-edge technologies while contributing to high-performance infrastructure solutions for a diverse clientele. Enjoy the benefits of a dynamic workplace that champions automation and robust security principles, ensuring your career growth is both meaningful and rewarding.