Senior InfoSec GRC Specialist in London

Senior InfoSec GRC Specialist in London

London Full-Time 48000 - 72000 £ / year (est.) No home office possible
Go Premium
C

At a Glance

  • Tasks: Lead security inquiries and optimise customer engagement processes in InfoSec.
  • Company: Dynamic company focused on information security and compliance.
  • Benefits: Competitive salary, flexible work options, and opportunities for professional growth.
  • Why this job: Make a real impact in security while collaborating with diverse teams.
  • Qualifications: 7+ years in InfoSec, strong communication skills, and knowledge of SOC2 and ISO 27001.
  • Other info: Join a forward-thinking team dedicated to innovation and compliance.

The predicted salary is between 48000 - 72000 £ per year.

The Senior InfoSec GRC Specialist plays a pivotal role across multiple dimensions. They are instrumental in crafting responses to security inquiries within "request for proposals" (RFPs) and ensuring their prompt delivery. As the initial point of contact for addressing customer security concerns, they actively seek avenues to optimize the efficiency of the security customer engagement process. Moreover, they utilize structured methods and protocols to identify and assess risk, implement pertinent controls, formalize agreements, and diligently follow through on necessary procedures. Effective communication is at the core of their responsibilities, encompassing the dissemination of strategies, standards, policies, procedures, and awareness campaigns to all business partners. They take purposeful actions to guarantee global business units' compliance with relevant frameworks and conduct comprehensive reviews of proposed vendor engagement terms and conditions. Additionally, they apply the company's risk profile, offer pertinent feedback, and meticulously document any deviations from the established processes.

Responsibilities:

  • Assists in the production of response to security questions in "request for proposals" (RFP's) or customer assessments (Due Diligence Questionnaires).
  • Acts as first point of escalation for security/compliance questions for current and prospective customers.
  • Review third party vendors for security and compliance controls; assesses risk based on a given risk assessment framework (Third Party Risk Management/Vendor Assessment).
  • Assists and/or takes the lead in managing/overseeing annual SOC2 & ISO27001 audits.
  • Contributes in annual InfoSec Policies review/edits/updates and provides considered input.
  • Review proposed client engagement terms and conditions and apply the company risk profile, providing the appropriate feedback as to any changes needed and documenting exceptions to the process.
  • Assists in the collation of Enterprise Risk, control and mitigation updates, along with KRIs.
  • Identifies efficiency improvements in the security customer engagement process.
  • Communicates strategies, standards, policies, procedures, communications, and awareness efforts with all business partners.
  • Takes actions as directed to ensure compliance of global business units in actions necessary to ensure compliance with applicable frameworks.
  • Keeps up to date with evolving regulations and legislation related to privacy and security as they pertain to Clearwater.
  • Ability to manage time effectively by hitting assigned deadlines and milestones.
  • Requires minimum supervision to work on daily tickets and tasks, can use documentation and team resources to complete most tasks.
  • Capably resolves all but the most complex operational issues without the need for escalation.
  • Willingness and ability to maintain a positive, quality-oriented, reliable and flexible attitude.
  • Actively seeks opportunities for improving key processes and systems without requiring daily direction.
  • Demonstrates the ability to take on an assignment, project, or problem and lead, define, and implement a solution to completion.

Requirements:

  • Knowledge of SOC2 and ISO 27001 control frameworks.
  • Knowledge of risk frameworks and risk management processes.
  • Ability to work effectively in a team environment and across all organizational levels, where flexibility, collaboration, and adaptability are important.
  • Excellent attention to detail and strong documentation skills.
  • Excellent verbal, written and interpersonal communication skills.
  • Experienced in Atlassian (JIRA) and proficient in Microsoft Office.

Experience:

  • 7+ years of role-specific experience, preferred.
  • Demonstrated experience in owning, managing and responding to Client/Prospect Security Assessments (DDQs, RFPs etc.).
  • Experience working with Third Party Risk Management/Vendor Assessment tasks.
  • Demonstrated experience with SOC 1, SOC 2, and/or ISO 27001 audits and monitoring control activities.
  • Experience in owning/editing/contributing to Information Security Policies.
  • Experience performing or undergoing internal and external audits.
  • Experience with compliance, audit, or operations including development of internal controls, policies, and procedures.
  • Experience assisting in risk management processes, control frameworks, KRIs.
  • Experience communicating technical controls and processes with customers and stakeholders.
  • Demonstrated professional application of information security, compliance, assurance and/or other security practices and principles.

Senior InfoSec GRC Specialist in London employer: Clearwater Analytics (CWAN)

As a Senior InfoSec GRC Specialist at our company, you will thrive in a dynamic work environment that prioritises collaboration and innovation. We offer competitive benefits, a strong commitment to employee development, and a culture that values open communication and continuous improvement. Located in a vibrant area, our workplace fosters a sense of community and provides unique opportunities for professional growth in the ever-evolving field of information security.
C

Contact Detail:

Clearwater Analytics (CWAN) Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior InfoSec GRC Specialist in London

✨Tip Number 1

Network like a pro! Get out there and connect with folks in the InfoSec community. Attend meetups, webinars, or conferences where you can chat with potential employers and other professionals. Remember, it’s all about who you know!

✨Tip Number 2

Prepare for those interviews by practising common questions related to GRC and risk management. We recommend doing mock interviews with friends or using online platforms. The more you rehearse, the more confident you'll feel when it’s showtime!

✨Tip Number 3

Showcase your expertise! Create a portfolio that highlights your experience with SOC2, ISO 27001, and any relevant projects. This will give you an edge and demonstrate your hands-on skills to potential employers.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who are proactive and engaged in their job search.

We think you need these skills to ace Senior InfoSec GRC Specialist in London

Risk Assessment
Security Compliance
Third Party Risk Management
Vendor Assessment
SOC 2 Audits
ISO 27001 Audits
Information Security Policies
Documentation Skills
Communication Skills
Attention to Detail
Project Management
Regulatory Knowledge
Team Collaboration
Process Improvement
Technical Communication

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter for the Senior InfoSec GRC Specialist role. Highlight your experience with SOC2, ISO 27001, and risk management processes. We want to see how your skills align with our needs!

Showcase Your Communication Skills: Since effective communication is key in this role, don’t shy away from demonstrating your verbal and written skills. Use clear, concise language in your application to reflect how you would communicate strategies and policies with our business partners.

Highlight Relevant Experience: Be sure to emphasise your experience with security assessments, vendor management, and compliance audits. We’re looking for someone who can hit the ground running, so make it easy for us to see your relevant background!

Apply Through Our Website: We encourage you to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super straightforward!

How to prepare for a job interview at Clearwater Analytics (CWAN)

✨Know Your Frameworks

Make sure you brush up on SOC2 and ISO 27001 control frameworks before the interview. Being able to discuss these in detail will show that you’re not just familiar with them, but that you can apply them effectively in real-world scenarios.

✨Prepare for RFP Questions

Since you'll be crafting responses to security inquiries in RFPs, practice answering common security questions. Think about how you would articulate your experience with client assessments and vendor evaluations, as this will likely come up during the interview.

✨Showcase Your Communication Skills

Effective communication is key in this role. Be ready to demonstrate how you've successfully communicated strategies and policies in previous positions. Use specific examples to illustrate your ability to convey complex information clearly to various stakeholders.

✨Highlight Process Improvements

Think of instances where you've identified efficiency improvements in security processes. Be prepared to discuss these examples in detail, as they will showcase your proactive approach and problem-solving skills, which are crucial for this position.

Senior InfoSec GRC Specialist in London
Clearwater Analytics (CWAN)
Location: London
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>