Information Security Governance, Risk and Compliance Specialist in London

Information Security Governance, Risk and Compliance Specialist in London

London Full-Time 31500 - 38500 £ / year (est.) Home office (partial)
G

At a Glance

  • Tasks: Shape security compliance and build a culture of awareness at GWI.
  • Company: Join GWI, a dynamic tech company making an extraordinary impact.
  • Benefits: Enjoy 25 days leave, health benefits, flexible work options, and career growth.
  • Other info: Diverse and inclusive workplace with opportunities for personal and professional growth.
  • Why this job: Make a real difference in information security while working with innovative teams.
  • Qualifications: Experience in ISO 27001 certification and strong communication skills are essential.

The predicted salary is between 31500 - 38500 £ per year.

Location: London, UKWeekly office requirement: Hybrid – 2 days per week Employment type: Permanent Seniority level: Mid-Senior At GWI we're always looking for extraordinary people who thrive on making an extraordinary impact.

Right now we're looking for an Information Security GRC Specialist to play a key role in our Legal team in London.

If that's you, and making a difference gets you out of bed in the morning, keep reading.

It could be the start of something, well, extraordinary.

Sounds great, what will I be doing? ðAs our Information Security GRC Specialist you'll play a pivotal role in shaping the future of security compliance at GWI.

Reporting into our General Counsel and working closely with our Information Security, Product, and Technology teams, you'll own our compliance posture across security frameworks, vendor risk, and client-facing security requirements — while building a security-conscious culture across the business.

A few things you'll be responsible for:ð Own and maintain GWI's ISO 27001 certification and compliance across relevant security frameworks, keeping our posture sharp as the threat landscape evolves.ð Develop, implement, and maintain information security policies and procedures aligned with industry best practices.ð Lead vendor risk management and client security assessments — including responding to client security questionnaires and onboarding requirements.ð Build and maintain GWI's security trust portal, showcasing our credentials to clients and stakeholders using tools such as Drata or Vanta.ð Drive security awareness across the business through training programmes and internal communications that promote a strong GRC culture.

It's also fun; shaking things up is what working for GWI is all about.

You'll need to be flexible, comfortable with continuous change, and working in a high-tempo environment.

What do I need to bring with me? ð§³You'll need to be able to demonstrate the core skills this role requires.

You don't have to tick all the boxes right away; the important thing is that you're willing to learn.

Here's what the team will be looking for in you:ð In-depth, practical experience obtaining and maintaining ISO 27001 certification, with solid knowledge of frameworks such as NIST — typically 3–5 years in an information security compliance role, though other experience levels will be considered.ð Proven ability to develop and maintain security policies and procedures that align with industry best practice.ð Experience conducting vendor security assessments and managing client security onboarding requirements, balancing risk against commercial objectives.ð Hands-on experience building or maintaining a security trust portal; familiarity with tools such as Drata or Vanta is a plus.ð Knowledge of Saa S and AI environments, with experience implementing and managing cloud security best practices.ð Strong communication skills — able to translate complex GRC topics into clear internal guidance and keep the wider business informed and engaged on security matters.

Equally important is attitude.

We want people who think big (to make an impact), ask why (to find a better way), and show respect (to everyone, at every level, all the time).

Those are our values, and they're a big part of what we're looking for in you.

What We Offer ð§At GWI, you’ll find meaningful work, visible impact, and a culture that empowers you to do your best.

Our package includes: Time to recharge – 25 days’ annual leave, plus office closures over the holidays.

Health & wellbeing – Health cash plan, enhanced family benefits, carer days, and mental health support.

Financial benefits – Competitive salary, 4% pension matching, and recognition programs that celebrate success.

Flexibility & balance – Flexitime, early Friday finishes, hybrid and remote options, plus a “work from home” budget.

Career growth – Accredited learning, leadership development, and global career mobility.

Community & impact – DE&I initiatives, volunteering opportunities, donation matching, and payroll giving.

Put all that together and GWI is the friendliest, most fulfilling place any of us has ever worked.

Diversity, Equity & Inclusion ð«¶Diversity is fundamental to who we are—both as a data company and as a workplace.

Our data reflects global realities, and so must our teams.

We strive to ensure our workforce is as diverse and inclusive as the insights we provide to our clients.

As a Disability Confident employer, we welcome applications from disabled candidates and are committed to providing all necessary adjustments during the hiring process.

We also actively encourage applications from underrepresented and marginalized communities.

At GWI, you will find a place where you can contribute meaningfully, grow professionally, and belong fully.#li-hybrid#LI-NIKOSSS1

Information Security Governance, Risk and Compliance Specialist in London employer: Global Web Index

At GWI, we pride ourselves on being an exceptional employer, offering a vibrant work culture that fosters collaboration and innovation. With a strong focus on employee growth, we provide extensive learning opportunities, flexible working arrangements, and a commitment to diversity and inclusion, ensuring that every team member can thrive both personally and professionally. Located in a dynamic environment, our hybrid work model allows for a balanced lifestyle while contributing to meaningful projects that have a visible impact.

G

Contact Details:

Global Web Index Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Governance, Risk and Compliance Specialist in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Global Web Index, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Global Web Index

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Global Web Index. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Information Security Governance, Risk and Compliance Specialist in London

ISO 27001 Certification
Information Security Policies
Vendor Risk Management
Client Security Assessments
Security Trust Portal Management
Drata
Vanta

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Global Web Index insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Global Web Index that you’re committed to staying ahead in the game.

How to prepare for a job interview at Global Web Index

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Global Web Index to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Global Web Index.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.