At a Glance
- Tasks: Lead governance, risk management, and compliance projects for diverse clients.
- Company: Join Mishcon de Reya, a rapidly growing independent law firm with a global presence.
- Benefits: Enjoy competitive salary, flexible working, and opportunities for professional growth.
- Other info: Dynamic environment with a commitment to diversity and inclusion.
- Why this job: Make a real impact by enhancing GRC processes and advising senior stakeholders.
- Qualifications: 5+ years in GRC or risk management, with strong analytical and communication skills.
The predicted salary is between 70000 - 90000 £ per year.
We are seeking an experienced Senior GRC Consultant to join our consulting practice. The successful candidate will operate as a client-facing consultant across a portfolio of concurrent engagements, delivering governance, risk management, and compliance advisory services to multiple clients with the autonomy and rigour expected of a senior consulting professional. The Senior GRC Consultant will manage a diverse client book, with the firm itself representing a principal, but not exclusive engagement.
Across all assignments, the Senior GRC Consultant will be expected to maintain a consistently high standard of delivery, context-switching effectively between engagements and adapting to the specific regulatory, operational, and strategic requirements of each client environment. Working closely with senior stakeholders across client organisations, the Senior GRC Consultant will drive the maturation of GRC processes, ensure alignment with regulatory requirements and industry best practices, and provide expert advisory guidance on risk-related matters.
A key focus across engagements will be to assess, enhance, and uplift baseline GRC capabilities and processes, embedding sustainable improvements that raise the overall maturity of each client's GRC function. The Senior GRC Consultant will also be expected to define and track meaningful metrics and key performance indicators (KPIs) to measure the effectiveness of GRC activities and demonstrate progress against maturity objectives. The Senior GRC Consultant will be supported by a Cyber GRC Analyst in the delivery of day-to-day GRC activities. In addition, the Senior GRC Consultant will be responsible for guiding, mentoring, and developing the analyst, fostering their professional growth and ensuring effective knowledge transfer across the GRC function.
Key Responsibilities
- Governance: Assess, develop, and uplift governance frameworks, policies, and procedures across the firm and external client environments. Ensure that governance structures are robust, clearly documented, and aligned with strategic objectives. Facilitate governance forums and committees, preparing board-level and executive reporting as required.
- Risk Management: Deliver enterprise-wide cyber risk assessments across the firm and client environments, including identification, analysis, evaluation, and treatment of key risks. Maintain and enhance risk registers, ensuring risks accurately captured, rated, and escalated in accordance with the applicable risk appetite framework. Assess and uplift risk management methodologies, tools, and reporting mechanisms across stakeholder groups. Provide subject-matter expertise and advisory guidance on emerging risks, threat landscapes, and risk mitigation strategies.
- Compliance: Monitor and assess compliance posture against applicable laws, regulations, standards, and contractual obligations (e.g. GDPR, ISO 27001, SOC 2, PCI DSS, NIS2) across the firm and external client engagements. Design and execute compliance assessment programmes, internal audits, and gap analyses. Advise on and manage relationships with external auditors, regulators, and certification bodies. Track regulatory developments and deliver clear, actionable guidance on the impact of new or amended requirements.
- Stakeholder Engagement & Advisory: Act as a trusted adviser to senior leadership across the firm and client environments on GRC matters, translating complex risk and compliance topics into clear, actionable insights. Collaborate with IT, Information Security, Legal, Data Protection, and operational teams to embed GRC principles into day-to-day operations and client delivery. Deliver GRC awareness training and education programmes to promote a risk-aware culture across the firm and within client organisations.
- Reporting & Metrics: Develop and maintain GRC dashboards, key risk indicators (KRIs), and key performance indicators (KPIs) to provide visibility of risk and compliance status across the firm and client engagements. Define and track meaningful metrics to measure the effectiveness of GRC activities and demonstrate progress against maturity objectives. Prepare regular reports for senior management, audit committees, and the board as required.
Qualifications
- A minimum of five (5) years' experience in a GRC, risk management, information security, or compliance role, with demonstrable experience operating at a senior or lead level within a consulting or advisory capacity.
- Strong working knowledge of governance and risk management frameworks (e.g. ISO 27001, ISO 31000, NIST CSF, COBIT).
- Proven experience conducting risk assessments, compliance audits, and gap analyses.
- Experience engaging with regulators, external auditors, and certification bodies.
- Excellent understanding of relevant regulatory landscapes (e.g. GDPR, NIS2, PCI DSS, FCA regulations, or sector-specific requirements).
- Demonstrated ability to deliver GRC advisory services with the autonomy and rigour expected of a senior consulting professional.
Desirable Qualifications & Certifications:
- Professional certifications such as CRISC, CISA, CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent.
- Experience with GRC tooling platforms (e.g. ServiceNow GRC, OneTrust, Archer, or similar).
- Prior experience in financial services, legal, defence, or other highly regulated sectors.
- Familiarity with third-party risk management and supply chain assurance programmes.
- Experience delivering GRC services to multiple clients simultaneously, managing competing priorities and maintaining consistent quality of delivery across engagements.
Skills
- Exceptional analytical and critical-thinking skills with the ability to assess complex risk scenarios.
- Outstanding written and verbal communication skills, with the ability to present to executive and board-level audiences.
- Strong client relationship management skills, with the ability to build trust and credibility across diverse stakeholder groups.
- Proven ability to context-switch effectively across multiple concurrent engagements without compromising quality of delivery.
- Strong stakeholder management and influencing skills.
- Self‑motivated and able to work independently, managing multiple priorities within a fast‑paced consulting environment.
- High attention to detail and a commitment to delivering quality outcomes.
Please note that this job profile is not an exhaustive list of duties but merely an outline of the key components of the role. You may be required by your line manager to take on additional responsibilities when requested.
About Mishcon de Reya LLP
Mishcon de Reya is an independent law firm, which now employs over 1400 people with more than 650 lawyers offering a wide range of legal services to companies and individuals. The firm has grown rapidly in recent years, showing more than 40% revenue growth in the past five years alone.
With presence in London, Oxford, Cambridge, Singapore, Hong Kong and UAE, the firm services an international community of clients and provides advice in situations where the constraints of geography often do not apply. The work the firm undertakes is cross-border, multi‑jurisdictional and complex, centred around three increasingly entwined and connected sectors: the Innovation Economy, Private Wealth and Capital, and Real Estate. The firm is known as a disputes powerhouse with a formidable capacity firmwide for dispute resolution.
We strive to create a fully diverse and inclusive workplace where all our people are empowered to fulfil their potential. We are proud of our agile working culture and are always happy to talk flexible working.
Senior GRC Consultant in London employer: Mishcon de Reya LLP
As a leading law firm, we pride ourselves on fostering a dynamic and inclusive work culture that empowers our employees to excel. Our Senior Project Manager - Tech role offers the opportunity to lead transformative technology initiatives in a collaborative environment, with access to ongoing professional development and a commitment to work-life balance. Located in a vibrant city, we provide a supportive atmosphere where innovation thrives, ensuring that our team members can make a meaningful impact while advancing their careers.
StudySmarter Expert Advice🤫
We think this is how you could land Senior GRC Consultant in London
✨Join Compliance Communities
Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!
✨Attend Industry Conferences
Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.
✨Leverage Your University Career Services
If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.
✨Showcase Your Knowledge Online
Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Mishcon de Reya LLP looking for candidates who are engaged and informed.
We think you need these skills to ace Senior GRC Consultant in London
Some tips for your application 🫡
Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!
Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.
Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!
Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Mishcon de Reya LLP. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!
How to prepare for a job interview at Mishcon de Reya LLP
✨Master the Regulations
Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!
✨Show Your Analytical Skills
Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!
✨Know Your Tools
Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!
✨Align with Company Culture
Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Mishcon de Reya LLP’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!