GRC Officer: OT & IT Risk, Compliance & Governance

GRC Officer: OT & IT Risk, Compliance & Governance

Full-Time 55000 - 65000 £ / year (est.) No working from home possible
Edward Mann

At a Glance

  • Tasks: Identify and manage security risks while ensuring compliance with industry standards.
  • Company: Dynamic tech firm in London focused on governance and risk management.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Other info: Collaborative environment with excellent career advancement potential.
  • Why this job: Join a key role in shaping risk management practices and making a real impact.
  • Qualifications: Experience in IT risk management and strong communication skills required.

The predicted salary is between 55000 - 65000 £ per year.

We are recruiting for a client in London for a GRC Officer (with OT and IT experience) reporting into the Head of IT and Security. The role ensures that security/operational risks are effectively identified, assessed and monitored, and that the organisation maintains compliance with relevant legislation, industry standards and internal policies.

This position operates as a key member of the second line of defence, working closely with business units, technical teams and senior stakeholders to embed robust governance and risk practices.

  • Demonstrable experience in governance, risk management or compliance within an IT/technology, operational, regulated or critical services environment.
  • Strong understanding of risk management methodologies and compliance frameworks (e.g., ISO 27001, NIST CSF, NIS, CAF).
  • Excellent written and verbal communication skills with proven stakeholder engagement capability.
  • Ability to interpret and translate regulatory requirements into practical processes and controls.
  • Strong organisational skills with the ability to manage multiple workstreams effectively.
  • Experience working in regulated sectors (e.g., transport, utilities, financial services, health, government, technology).
  • Exposure to OT or industrial control systems (ICS) risk and compliance.
  • Experience in developing policies, standards and governance reporting.
  • Relevant certifications such as ISO 27001 Lead Implementer/Lead Auditor, CISMP, CRISC, CISM, or similar.

Areas of focus:

  • Implement and maintain the organisation’s risk management framework, including risk identification, assessment, treatment planning and monitoring.
  • Facilitate risk assessments across business units and support the development of risk mitigation strategies.
  • Monitor and report on risk trends, control effectiveness and emerging threats.

Compliance:

  • Support the organisation’s compliance programme, ensuring adherence to relevant laws, regulations and standards (e.g., ISO 27001, NIS Regulations, GDPR, sector‑specific obligations).
  • Maintain compliance registers, audit evidence repositories and documentation to demonstrate ongoing compliance.
  • Monitor changes in regulatory and industry requirements and assess their impact on the organisation.
  • Coordinate internal and external audits, including evidence collection and management of findings.

Governance & Policy Support:

  • Contribute to the development, review and implementation of policies, standards and governance processes.
  • Produce clear, accurate reports for senior leadership, committees and governance bodies.
  • Support the establishment and continuous improvement of governance controls and assurance mechanisms.
  • Hold accountability across all technology departments for the governance and assurance of change management, including oversight of changes to systems, data pipelines, AI models, prompts, and configurations, ensuring that appropriate approval, risk assessment, testing, documentation, and audit evidence are maintained prior to implementation.

Awareness & Engagement:

  • Assist in the design and delivery of awareness, engagement and training activities related to security, compliance and risk.
  • Communicate complex requirements to both technical and non-technical stakeholders in a practical and business relevant manner.

Qualifications:

  • Degree in Information Security, Risk Management, Business, Law or a related discipline; or equivalent professional experience.
  • Professional qualifications in information security, risk or compliance are beneficial but not essential.

Personal Attributes:

  • Detail‑oriented and methodical, with strong analytical skills.
  • Proactive and able to work independently while engaging collaboratively across teams.
  • Able to simplify complex subjects into accessible and actionable guidance.
  • Confident engaging with stakeholders at all levels, including senior leaders.

GRC Officer: OT & IT Risk, Compliance & Governance employer: Edward Mann

Join a forward-thinking organisation in London that prioritises employee development and fosters a collaborative work culture. As a GRC Officer, you will benefit from comprehensive training opportunities, a supportive environment for professional growth, and the chance to make a meaningful impact on governance and risk management practices. With a focus on compliance and innovation, this role offers a unique opportunity to engage with diverse stakeholders while contributing to the organisation's success in a regulated sector.

Edward Mann

Contact Details:

Edward Mann Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land GRC Officer: OT & IT Risk, Compliance & Governance

Network Like a Pro

Get out there and connect with people in the industry! Attend events, webinars, or even local meetups. The more you engage with professionals in GRC, the better your chances of landing that dream job.

Show Off Your Skills

When you get the chance to chat with potential employers, make sure to highlight your experience with risk management frameworks like ISO 27001 or NIST CSF. Share specific examples of how you've tackled compliance challenges in the past!

Tailor Your Approach

Every company is different, so do your homework! Understand their specific needs and challenges in governance and compliance. This way, you can tailor your conversations to show how you can add value to their team.

Apply Through Us!

Don’t forget to check out our website for the latest GRC Officer openings. Applying through us not only gives you access to exclusive roles but also helps us support you throughout the process!

We think you need these skills to ace GRC Officer: OT & IT Risk, Compliance & Governance

Governance
Risk Management
Compliance
ISO 27001
NIST CSF
NIS Regulations
GDPR

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the GRC Officer role. Highlight your experience in governance, risk management, and compliance, especially within IT and operational environments. We want to see how your skills align with the job description!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're the perfect fit for this role. Mention specific experiences that demonstrate your understanding of risk management methodologies and compliance frameworks. Let us know why you’re excited about joining our team!

Showcase Your Communication Skills:Since excellent written and verbal communication skills are key for this role, make sure your application reflects that. Use clear and concise language, and don’t shy away from showcasing your ability to engage with stakeholders at all levels. We love a good communicator!

Apply Through Our Website:We encourage you to apply through our website for a smoother process. It helps us keep track of applications and ensures you get the best experience possible. Plus, it shows us you’re keen on joining StudySmarter!

How to prepare for a job interview at Edward Mann

Know Your Frameworks

Make sure you brush up on key compliance frameworks like ISO 27001 and NIST CSF. Be ready to discuss how you've applied these in past roles, especially in risk management or compliance settings.

Showcase Your Stakeholder Skills

Prepare examples of how you've engaged with various stakeholders, from technical teams to senior leadership. Highlight your communication skills and how you’ve simplified complex regulatory requirements for different audiences.

Demonstrate Your Analytical Mindset

Be ready to talk about how you identify and assess risks. Use specific examples from your experience where you’ve developed risk mitigation strategies or monitored control effectiveness.

Stay Updated on Regulations

Research recent changes in relevant laws and regulations that could impact the organisation. Show that you’re proactive by discussing how you would keep the compliance programme aligned with these changes.