At a Glance
- Tasks: Advise clients on governance, risk, and compliance while implementing cutting-edge GRC technology.
- Company: Join Lex Dinamica, a forward-thinking consulting firm focused on privacy and AI compliance.
- Benefits: Enjoy 26 days of annual leave, hybrid working, and optional private health insurance.
- Other info: Work with global clients and enjoy excellent career growth opportunities.
- Why this job: Shape the future of privacy and compliance in a dynamic, collaborative environment.
- Qualifications: Experience in GRC frameworks and a passion for privacy and technology are essential.
The predicted salary is between 50000 - 65000 £ per year.
We are growing. Privacy and AI compliance has moved from a back office concern to a board level priority, and our clients are asking more of us because of it. Every week brings a new regulation, a new enforcement decision, or a new product launch that needs a privacy lens before it ships. This demand is an opportunity for us. We are building Lex Dinamica for what comes next in this work, and we are looking for the people who want to build it with us.
This role is how we build out our GRC capability and bring our clients a broader view of risk, controls and compliance technology.
Lex Dinamica is a consulting firm that provides Privacy, AI and Risk solutions. Our advisory, technology and DPO services help clients address regulatory challenges worldwide and deliver compliance-driven value. Our clients range from FTSE 100 companies and global multinationals to government contractors and high growth scale ups, and they come to us for advisory work, DPO support delivered as a service, AI governance, and privacy technology programmes including OneTrust, where we are a certified implementation partner.
The GRC Consultant role is how we extend that work into governance, risk and compliance more broadly. You will help clients design, run and improve the frameworks that hold their compliance programmes together, and bring an integrated view to organisations increasingly asked to manage privacy, security, AI and operational risk as one.
The Role
- Advise clients across governance, risk and compliance, including framework design, controls, and assurance.
- Support implementation of GRC technology platforms, with a focus on OneTrust and adjacent tools.
- Bring a broad GRC lens to engagements that touch privacy, security, AI and operational risk.
- Work directly with clients across our global portfolio, including German or French speaking accounts if your languages allow.
In practice, that means working alongside our consultants and senior leadership to deliver GRC programmes from scoping through go live and into operations. You will advise clients on the frameworks that hold their compliance programmes together. Risk taxonomies, control libraries, policy structures, assurance approaches, and the operating models that bring them to life. You will help clients move from fragmented, function specific compliance toward something integrated.
You will support the implementation and configuration of GRC technology. OneTrust is a focus for us, alongside the wider landscape of GRC platforms our clients use. You do not need to be a OneTrust expert today. You do need to be ready to build that expertise quickly with our support and certification.
You will bring an integrated view across risk domains. Privacy, information security, AI governance, operational resilience, third party risk, and the regulatory landscape that connects them. Our clients increasingly want one partner who can see across all of it. You will help us be that partner.
You will work directly with clients across our global portfolio. If you happen to speak German or French, you will also be the natural point of contact for clients who prefer to work in that language, which is something we are increasingly asked for.
You will contribute to how we work. Our GRC service line is growing, and the people who join now will help shape the methodologies, templates, and ways of working that we take to every future client.
Who we're looking for
Must haves
- A solid grounding in governance, risk and compliance, with practical experience designing or operating GRC frameworks, controls, or assurance programmes in a client or in house setting.
- Willingness to learn OneTrust and broader GRC platforms quickly, supported by our internal training and certification.
- A genuine interest in privacy, AI governance, and the wider compliance technology space. You enjoy the intersection of regulation, risk and technology and want to build a career there.
- Strong analytical and problem solving instincts. GRC work is detail heavy, and small framework choices have real downstream consequences.
- Strong written and verbal communication in English. You can explain a complex risk concept to a non technical client without losing them or oversimplifying.
- A right to work in the UK or the EU.
- Fluency in German. With German, you will become a natural point of contact for our DACH region clients and work directly in their language where that adds value.
- Fluency in French. With French, you will become a natural point of contact for our French speaking clients across France, Belgium, Luxembourg and Swiss Romande.
- Fluency in any other language. We work across more than fifty jurisdictions, and additional language capability extends the range of clients you can serve.
- Hands on experience with one or more GRC technology platforms (OneTrust, ServiceNow GRC, Archer, MetricStream, or similar).
- Familiarity with widely used GRC frameworks and standards (ISO 27001, ISO 27701, SOC 2, NIST CSF, COSO, or similar).
- Working knowledge of GDPR, the EU AI Act, and the wider regulatory landscape across the UK and EU.
- Exposure to specific regimes such as DORA, NIS2, or sectoral compliance requirements.
- Consulting experience, whether at a professional services firm, a Big Four, or a privacy or risk specialist firm.
- A recognised credential such as CIPP/E, CIPM, CRISC, CISA, ISO 27001 Lead Auditor or Implementer, or equivalent.
- A relevant degree in a field such as Business, Law, Economics, Computer Science, Information Security, or similar.
About Lex Dinamica
Lex Dinamica was built from day one to solve the problems that organisations face when data, regulation, technology and trust all have to hold together at once. That focus is what we are, and it is what we lead with from the first client conversation to the final deliverable. Headquartered in London and supported by delivery centres across the EU, US and India, we partner with clients from FTSE 100 companies and global multinationals to government contractors and high growth scale ups. Our work spans more than fifty jurisdictions and over one hundred and fifty delivered projects. Our founders came out of Big Four consulting. The firm they built deliberately keeps what works about that model, the rigour, the breadth, the client discipline, and strips out what does not, the layers, the politics, the pace.
We are a firm of curious people, fast learners, and genuine team players. We are selective about who we hire, because the people already here are worth working alongside.
Working With Us
You will be based in our London office with hybrid working, spending two days a week in the office and the rest of your week wherever you work best. The specific rhythm will flex around client commitments, team moments, and how you do your best work. At Lex Dinamica, we understand that a career is one part of a wider life, and we build our working patterns around that reality. Our hybrid model is designed to give you the face to face time that builds relationships, accelerates learning, and makes a small firm feel like one, alongside the focus time that consulting work genuinely needs.
What we offer
- 26 days of annual leave, with the option to accrue additional days over time.
- Hybrid working as standard.
- Optional private health insurance.
- A work from anywhere policy that lets you work abroad for defined periods each year.
JOIN THE TEAM
Ready to shape the future of privacy? For more opportunities, follow us on LinkedIn.
The data you provide us with will be processed exclusively for recruitment purposes and assessing your application against our requirements. You may withdraw your application at any time by getting in touch with a member of our team, via LinkedIn or the contact details found on our website. You may ask us to keep your information on file for any future opportunities.
Lex Dinamica is proud to be an equal opportunity employer, which means we are committed to creating and celebrating diverse thoughts, cultures, and backgrounds throughout our organisation. Employment at Lex Dinamica is based on substantive ability, objective qualifications, and work ethic, not an individual's background, religion, sex or gender, gender identity or expression, sexual orientation, national origin or ancestry, alienage or citizenship status, physical or mental disability, pregnancy, age, genetic information, veteran status, marital status, status as a victim of domestic violence or sex offenses, reproductive health decision, or any other characteristics protected by applicable law.
GRC Consultant employer: Lex Dinamica Ltd
At Lex Dinamica, we pride ourselves on being an exceptional employer that fosters a collaborative and innovative work culture. Our London office offers a dynamic environment where you can thrive professionally while enjoying the benefits of hybrid working. With a strong focus on employee growth and development, we provide ample opportunities for you to enhance your skills and advance your career in the rapidly evolving field of data protection and privacy.
StudySmarter Expert Advice🤫
We think this is how you could land GRC Consultant
✨Join Compliance Communities
Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!
✨Attend Industry Conferences
Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.
✨Leverage Your University Career Services
If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.
✨Showcase Your Knowledge Online
Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Lex Dinamica Ltd looking for candidates who are engaged and informed.
We think you need these skills to ace GRC Consultant
Some tips for your application 🫡
Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!
Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.
Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!
Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Lex Dinamica Ltd. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!
How to prepare for a job interview at Lex Dinamica Ltd
✨Master the Regulations
Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!
✨Show Your Analytical Skills
Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!
✨Know Your Tools
Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!
✨Align with Company Culture
Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Lex Dinamica Ltd’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!