Senior InfoSec GRC Specialist in London

Senior InfoSec GRC Specialist in London

London Full-Time 43200 - 72000 £ / year (est.) No home office possible
Go Premium
C

At a Glance

  • Tasks: Lead security compliance efforts and optimise customer engagement processes.
  • Company: Dynamic tech firm focused on information security and compliance.
  • Benefits: Competitive salary, flexible working, and opportunities for professional growth.
  • Why this job: Make a real impact in security while collaborating with diverse teams.
  • Qualifications: 7+ years in InfoSec, strong communication skills, and knowledge of SOC2/ISO27001.
  • Other info: Join a diverse team committed to inclusivity and innovation.

The predicted salary is between 43200 - 72000 £ per year.

The Senior InfoSec GRC Specialist plays a pivotal role across multiple dimensions. They are instrumental in crafting responses to security inquiries within "request for proposals" (RFPs) and ensuring their prompt delivery. As the initial point of contact for addressing customer security concerns, they actively seek avenues to optimize the efficiency of the security customer engagement process. Moreover, they utilize structured methods and protocols to identify and assess risk, implement pertinent controls, formalize agreements, and diligently follow through on necessary procedures. Effective communication is at the core of their responsibilities, encompassing the dissemination of strategies, standards, policies, procedures, and awareness campaigns to all business partners. They take purposeful actions to guarantee global business units' compliance with relevant frameworks and conduct comprehensive reviews of proposed vendor engagement terms and conditions. Additionally, they apply the company's risk profile, offer pertinent feedback, and meticulously document any deviations from the established processes.

Responsibilities:
  • Assists in the production of response to security questions in "request for proposals" (RFP's) or customer assessments (Due Diligence Questionnaires).
  • Acts as first point of escalation for security/compliance questions for current and prospective customers.
  • Review third party vendors for security and compliance controls; assesses risk based on a given risk assessment framework (Third Party Risk Management/Vendor Assessment).
  • Assists and/or takes the lead in managing/overseeing annual SOC2 & ISO27001 audits.
  • Contributes in annual InfoSec Policies review/edits/updates and provides considered input.
  • Review proposed client engagement terms and conditions and apply the company risk profile, providing the appropriate feedback as to any changes needed and documenting exceptions to the process.
  • Assists in the collation of Enterprise Risk, control and mitigation updates, along with KRIs.
  • Identifies efficiency improvements in the security customer engagement process.
  • Communicates strategies, standards, policies, procedures, communications, and awareness efforts with all business partners.
  • Takes actions as directed to ensure compliance of global business units in actions necessary to ensure compliance with applicable frameworks.
  • Keeps up to date with evolving regulations and legislation related to privacy and security as they pertain to Clearwater.
  • Ability to manage time effectively by hitting assigned deadlines and milestones.
  • Requires minimum supervision to work on daily tickets and tasks, can use documentation and team resources to complete most tasks.
  • Capably resolves all but the most complex operational issues without the need for escalation.
  • Willingness and ability to maintain a positive, quality-oriented, reliable and flexible attitude.
  • Actively seeks opportunities for improving key processes and systems without requiring daily direction.
  • Demonstrates the ability to take on an assignment, project, or problem and lead, define, and implement a solution to completion.
Requirements:
  • Knowledge of SOC2 and ISO 27001 control frameworks.
  • Knowledge of risk frameworks and risk management processes.
  • Ability to work effectively in a team environment and across all organizational levels, where flexibility, collaboration, and adaptability are important.
  • Excellent attention to detail and strong documentation skills.
  • Excellent verbal, written and interpersonal communication skills.
  • Experienced in Atlassian (JIRA) and proficient in Microsoft Office.
Experience:
  • 7+ years of role-specific experience, preferred.
  • Demonstrated experience in owning, managing and responding to Client/Prospect Security Assessments (DDQs, RFPs etc.).
  • Experience working with Third Party Risk Management/Vendor Assessment tasks.
  • Demonstrated experience with SOC 1, SOC 2, and/or ISO 27001 audits and monitoring control activities.
  • Experience in owning/editing/contributing to Information Security Policies.
  • Experience performing or undergoing internal and external audits.
  • Experience with compliance, audit, or operations including development of internal controls, policies, and procedures.
  • Experience assisting in risk management processes, control frameworks, KRIs.
  • Experience communicating technical controls and processes with customers and stakeholders.
  • Demonstrated professional application of information security, compliance, assurance and/or other security practices and principles.

Studies have shown that women and people of colour are less likely to apply to jobs unless they meet every single qualification. We are dedicated to building a diverse, inclusive and authentic workplace, so if you're excited about this role but your past experience doesn't align perfectly with the job description, we encourage you to still apply! You may be just what we're looking for.

Senior InfoSec GRC Specialist in London employer: Clearwater Analytics, Ltd

As a Senior InfoSec GRC Specialist in our London office, you will thrive in a dynamic and inclusive work culture that prioritises employee growth and development. We offer competitive benefits, a collaborative environment, and opportunities to engage with cutting-edge security frameworks, ensuring that your contributions are valued and impactful. Join us to be part of a forward-thinking team dedicated to excellence in information security and compliance.
C

Contact Detail:

Clearwater Analytics, Ltd Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior InfoSec GRC Specialist in London

✨Tip Number 1

Network like a pro! Reach out to your connections in the InfoSec world, especially those who might know someone at our company. A friendly chat can open doors that a CV just can't.

✨Tip Number 2

Prepare for the interview by brushing up on your knowledge of SOC2 and ISO 27001 frameworks. We love candidates who can speak confidently about their experience and how it relates to our needs.

✨Tip Number 3

Show us your problem-solving skills! Be ready to discuss specific examples where you've identified risks and implemented controls. We want to see how you think on your feet.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take that extra step.

We think you need these skills to ace Senior InfoSec GRC Specialist in London

Knowledge of SOC2 and ISO 27001 control frameworks
Risk Management Processes
Third Party Risk Management
Client/Prospect Security Assessments
Excellent Attention to Detail
Strong Documentation Skills
Verbal Communication Skills
Written Communication Skills
Interpersonal Communication Skills
Experience with Atlassian (JIRA)
Proficient in Microsoft Office
Ability to Work in a Team Environment
Flexibility and Adaptability
Problem-Solving Skills
Experience with Compliance and Audit Processes

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with SOC2, ISO 27001, and risk management. We want to see how your skills align with the role of Senior InfoSec GRC Specialist!

Showcase Your Communication Skills: Since effective communication is key in this role, don’t shy away from demonstrating your verbal and written skills. Use clear, concise language in your application to reflect your ability to convey complex information simply.

Highlight Relevant Experience: Be sure to emphasise your experience with client security assessments and vendor management. We’re looking for someone who can hit the ground running, so make it easy for us to see how you fit the bill!

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates during the process!

How to prepare for a job interview at Clearwater Analytics, Ltd

✨Know Your Frameworks

Make sure you brush up on SOC2 and ISO 27001 control frameworks before the interview. Being able to discuss these in detail will show that you understand the core of the role and can hit the ground running.

✨Prepare for RFP Questions

Since you'll be crafting responses to security inquiries in RFPs, practice articulating your past experiences with client assessments. Think of specific examples where you successfully managed or responded to security questions.

✨Showcase Your Communication Skills

Effective communication is key in this role. Be ready to demonstrate how you've communicated strategies and policies in previous positions. Use clear examples that highlight your ability to convey complex information simply.

✨Highlight Your Problem-Solving Abilities

The job requires identifying efficiency improvements and resolving operational issues. Prepare to discuss instances where you've led a project or solved a complex problem, showcasing your initiative and leadership skills.

Senior InfoSec GRC Specialist in London
Clearwater Analytics, Ltd
Location: London
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

C
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>