At a Glance
- Tasks: Advise clients on governance, risk management, and compliance in various industries.
- Company: Join a diverse and inclusive team at Sword, a leader in GRC consulting.
- Benefits: Enjoy flexible working, personalised career development, and a fantastic benefits package.
- Other info: Opportunities for growth in a supportive environment that values diversity.
- Why this job: Make a real impact by helping clients navigate complex regulatory landscapes.
- Qualifications: Experience in GRC roles and strong communication skills are essential.
The predicted salary is between 55000 - 65000 € per year.
As a GRC Consultant, you will advise and support our clients across governance, risk management and regulatory compliance. The role focuses on aligning cyber, information security, operational resilience and wider risk frameworks to UK‑specific regulatory, safety and operational requirements. You will work closely with client stakeholders to assess maturity, design and implement control frameworks, and provide pragmatic, risk‑based guidance that supports safe, secure and resilient operations.
Deliver governance, risk and compliance consulting engagements for a variety of clients and industries, including UK Oil & Gas (operators, service companies and joint ventures), CNI, Finance and Public Sector.
Responsibilities
- Lead or support GRC maturity assessments, gap analyses and audits against relevant standards and regulations.
- Interpret and apply UK specific regulatory requirements, translating them into practical, implementable controls.
- Design and implement GRC frameworks covering risk management, policy, assurance and reporting.
- Support compliance activities aligned to various regulations and assurance requirements.
- Develop and maintain risk registers, control libraries and assurance plans.
- Facilitate risk workshops, control reviews and senior stakeholder briefings.
- Support cyber and information security governance aligned to ISO 27001, NCSC guidance and sector best practice.
- Provide advisory input into operational resilience, business continuity and third party risk management.
- Produce clear, evidence based client deliverables including reports, executive summaries and remediation roadmaps.
- Support pre audit, regulatory inspection and client assurance activities.
Essential
- Good experience and background of producing high quality documentation and solution artefacts.
- Proven experience in Governance, Risk and Compliance roles within regulated or critical infrastructure environments.
- Strong understanding of the UK Oil & Gas and finance regulatory landscape.
- Working knowledge of key frameworks and standards, such as: ISO/IEC 27001, ISO 22301 (Business Continuity), UK NIS Regulations and NCSC guidance, NIST CSF, UK GDPR, Data Protection Act, DORA.
- Experience conducting risk assessments, control gap analyses and assurance activities.
- Proven ability to drive adoption, stakeholder buy-in and embedding change.
- Strong background in end‑to‑end delivery (from design to implementation and embedding).
- Ability to engage confidently with technical, operational and executive stakeholders.
- Strong written communication skills with experience producing client facing reports.
- Strong ability to translate technical and GRC concepts into clear, business-friendly language.
- Experience working in consulting or advisory environments.
Desirable / Valuable
- Knowledge of IEC 62443 for OT/ICS security.
- Operational Technology (OT) and industrial control environments.
- Familiarity with NCSC Cyber Assessment Framework (CAF) or sector‑specific assurance models.
- Experience supporting regulatory audits (HSE, NIS competent authority, client audits).
- Certifications such as ISO 27001 Lead Implementer / Lead Auditor, CISM, CRISC or CISSP, IRM or ISO risk management qualifications.
- Understanding of supply‑chain and third‑party risk in Oil & Gas, CNI and finance ecosystems.
- Familiarity with GRC tooling such as OneTrust or Archer.
- Ability to contribute to business development or service offering development.
At Sword, we offer comprehensive benefits designed to support your professional development and enhance your overall quality of life. In addition to a Competitive Salary, here's what you can expect as part of our benefits package:
- Personalised Career Development: We create a development plan customised to your goals and aspirations, with a range of learning and development opportunities within a culture that encourages growth.
- Flexible working: Flexible work arrangements to support your work-life balance.
- A Fantastic Benefits Package: This includes generous annual leave allowance, enhanced family friendly benefits, pension scheme, access to private health, well-being, and insurance schemes.
At Sword we are dedicated to fostering a diverse and inclusive workplace and are proud to be an equal opportunities employer, ensuring that all applicants receive fair and equal consideration for employment, regardless of whether they meet every requirement. If you don’t tick all the boxes but feel you have some of the relevant skills and experience we’re looking for, please do consider applying and highlight your transferable skills and experience. We embrace diversity in all its forms, valuing individuals regardless of age, disability, gender identity or reassignment, marital or civil partner status, pregnancy or maternity status, race, colour, nationality, ethnic or national origin, religion or belief, sex, or sexual orientation. Your perspective and potential are important to us. If we can do anything to help make the hiring process more accessible, please let our talent acquisition team know when you apply so we can support any adjustments.
Governance, Risk & Compliance Consultant in Glasgow employer: Cyber Fraud Centre
At Sword, we pride ourselves on being an exceptional employer, offering a supportive and inclusive work culture that prioritises your professional growth. With personalised career development plans, flexible working arrangements, and a comprehensive benefits package, including generous annual leave and enhanced family-friendly benefits, we ensure our employees thrive both personally and professionally in the dynamic field of Governance, Risk & Compliance consulting.
StudySmarter Expert Advice🤫
We think this is how you could land Governance, Risk & Compliance Consultant in Glasgow
✨Tip Number 1
Network like a pro! Reach out to your connections in the GRC field and let them know you're on the lookout for opportunities. Attend industry events or webinars to meet potential employers and get your name out there.
✨Tip Number 2
Prepare for interviews by brushing up on your knowledge of UK-specific regulations and frameworks. Be ready to discuss how you've applied these in past roles, and don’t forget to have some questions prepared to show your interest in the company!
✨Tip Number 3
Showcase your expertise! Create a portfolio of your previous work, including reports and frameworks you've developed. This will help you stand out and demonstrate your ability to deliver high-quality documentation.
✨Tip Number 4
Don’t just apply through job boards; head over to our website and submit your application directly! This way, you can ensure your application gets the attention it deserves and shows your enthusiasm for joining our team.
We think you need these skills to ace Governance, Risk & Compliance Consultant in Glasgow
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in governance, risk management, and compliance. We want to see how your skills align with the specific requirements of the GRC Consultant role.
Showcase Your Documentation Skills:Since strong written communication is key for this role, include examples of high-quality documentation you've produced in the past. This could be reports, executive summaries, or any client-facing materials that demonstrate your ability to convey complex information clearly.
Highlight Relevant Experience:Don’t forget to mention your experience with UK-specific regulations and frameworks like ISO 27001 or NIS Regulations. We’re looking for candidates who can translate these into practical controls, so make it clear how you’ve done this in previous roles.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it gives you a chance to explore more about what we do at StudySmarter!
How to prepare for a job interview at Cyber Fraud Centre
✨Know Your Regulations
Make sure you brush up on UK-specific regulatory requirements relevant to the role. Familiarise yourself with frameworks like ISO 27001 and UK GDPR, as well as the Oil & Gas sector regulations. This will help you demonstrate your understanding of the compliance landscape during the interview.
✨Showcase Your Documentation Skills
Since producing high-quality documentation is key in this role, prepare examples of reports or artefacts you've created in previous positions. Be ready to discuss how you ensure clarity and effectiveness in your written communication, especially when translating technical concepts into business-friendly language.
✨Engage with Stakeholders
Highlight your experience in engaging with various stakeholders, from technical teams to executive management. Prepare anecdotes that showcase your ability to drive adoption and stakeholder buy-in, as this is crucial for implementing GRC frameworks successfully.
✨Prepare for Practical Scenarios
Expect to be asked about real-world scenarios related to risk assessments and control gap analyses. Think through some challenges you've faced and how you approached them, as well as the outcomes. This will show your practical experience and problem-solving skills in action.