At a Glance
- Tasks: Manage security and compliance documentation, support audits, and ensure data protection regulations are met.
- Company: Join a trusted tech company focused on security and compliance for major clients.
- Benefits: Remote work, generous personal development budget, health care, and wellness perks.
- Why this job: Advance your career in a growing field with opportunities to specialise and make an impact.
- Qualifications: Experience in GRC or information security, ISO 27001 certification preferred.
- Other info: Dynamic role with potential for international compliance projects and professional growth.
The predicted salary is between 36000 - 60000 £ per year.
We’re proud to be trusted by some of the largest companies in the world to handle their Salesforce DevOps. Underpinning that trust is a commitment to protect their data through our modern approach to security and compliance, and this is only getting more important as we grow our customer base in increasingly regulated sectors. This is a fantastic opportunity to progress your career in security and compliance within the tech sector. This role will provide you with exposure to several key areas including information security, data protection, general compliance, audits and relevant project work. There’ll be lots of opportunity to progress within the role and specialise within a certain area of the business in the future.
What’s the opportunity at Gearset?
- Own our security and compliance documentation accurate and up to date, such as policies, procedures, and support documentation across our information security and compliance programs.
- Support our commercial teams in complex information security and compliance negotiations, while making sure we respond accurately and within given timescales.
- Take ownership of maintaining our current ISO 27001 compliance and certification through continuous improvement activities, as well as supporting preparation for internal and external audits.
- Own our internal Data Protection compliance program and make sure we comply with various regulations globally including UK GDPR, EU GDPR, and CCPA.
- Gain experience in the implementation and ownership of additional compliance based projects as we increase the international regulation and standards we comply with.
- Help us work efficiently by identifying common deal blockers and standardising documentation and processes.
What you’ll achieve
- You’ll build on your prior experience from a GRC or an information security role, within a technology company, to support our ambitious company growth plans.
- You’ll become a technical expert on the company and our products to streamline customer onboarding, and security and compliance reviews.
- You’ll own reviewing and responding to our complex customer security and compliance requests.
- You’ll have ownership of compliance and reporting to the international information security standard ISO 27001, to ensure Gearset retains our certification and continues to provide the highest level of protection to our customers’ data.
- You’ll manage our third party supplier risk program.
- You’ll work as part of the compliance project team when implementing new regulations or standards such as NIST, fedRAMP etc.
- You’ll have the opportunity to get certified to international standards on Information Security, Compliance, Risk, Data Protection or Cyber Security.
About you
- Have been in an information security or GRC role, within a technology company and hold either a ISO 27001 Lead Implementer or Lead Auditor certificate.
- Have in-depth knowledge of ISO 27001 standards & proven experience in implementing ISO 27001 and maintaining the certification.
- Along with knowledge of general compliance requirements such as Modern Slavery, AML, Bribery etc.
- Have a track record of owning internal compliance with global data protection laws including GDPR and CCPA.
- Have an understanding of AWS Cloud infrastructure, and application security.
- Possess a technical predisposition, the desire to learn and ability to react to the needs of a rapidly growing company eg comfortable working in an ever changing environment.
- Are an excellent communicator, with attention to detail and a passion for always delivering a great customer experience.
Great to haves
- A degree in Computer Science, Information Security, Cybersecurity, or a closely related discipline such as Data Protection, Information Governance or Risk.
- A recognised Information Security qualification such as CISSP, CompTIA Security+ etc.
- Past exposure to other regulations or frameworks such as NIST, HIPAA, fedRAMP, DORA.
- Knowledge of DevOps and DevSecOps.
Benefits (the stuff you’d expect!)
- This is a full time opportunity, working Monday to Friday remotely within the UK.
- Opportunity to join our Long Term Incentive scheme.
- Generous personal development budget for courses, conferences, or whatever is useful to your professional development in the role of up to £1500 per year.
- Top end hardware provided.
- Free lunch any day you are in the office.
- BUPA health care.
- Life Insurance & critical illness cover.
- Discounted gym membership, as well as a range of health and wellness benefits.
GRC Manager in Cambridge employer: Gearset
Contact Detail:
Gearset Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land GRC Manager in Cambridge
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend webinars, and join relevant groups. The more connections we make, the better our chances of landing that GRC Manager role.
✨Tip Number 2
Prepare for interviews by researching the company and its compliance practices. We should be ready to discuss how our experience aligns with their needs, especially around ISO 27001 and data protection.
✨Tip Number 3
Showcase our skills through real-life examples. When discussing past roles, let’s highlight specific projects where we improved compliance or security processes. This will make us stand out!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure our application gets noticed. Plus, it shows we’re genuinely interested in being part of the team at Gearset.
We think you need these skills to ace GRC Manager in Cambridge
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the GRC Manager role. Highlight your experience in information security and compliance, especially with ISO 27001. We want to see how your skills align with what we’re looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about security and compliance in tech. Share specific examples of your past achievements that relate to the role, and let us know why you want to join StudySmarter.
Showcase Your Technical Skills: Don’t forget to mention your technical expertise! If you’ve got experience with AWS Cloud infrastructure or any relevant certifications, make sure these stand out. We love seeing candidates who are eager to learn and adapt in a fast-paced environment.
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to submit all your documents in one go. Plus, it helps us keep track of your application!
How to prepare for a job interview at Gearset
✨Know Your Standards
Make sure you brush up on ISO 27001 standards and any other relevant compliance regulations. Being able to discuss these in detail will show that you’re not just familiar with them, but that you can apply them in real-world scenarios.
✨Showcase Your Experience
Prepare specific examples from your past roles where you've successfully managed compliance projects or handled security audits. This will help demonstrate your hands-on experience and how it aligns with the responsibilities of the GRC Manager role.
✨Communicate Clearly
As an excellent communicator, practice articulating complex information security concepts in a straightforward manner. This is crucial, especially when discussing compliance negotiations with commercial teams or responding to customer requests.
✨Stay Current with Trends
Keep yourself updated on the latest trends in information security and compliance, especially regarding GDPR and CCPA. Showing that you’re proactive about learning will impress interviewers and highlight your commitment to the field.