GRC Principal in London

GRC Principal in London

London Full-Time 60000 - 70000 £ / year (est.) Home office (partial)
OVO

At a Glance

  • Tasks: Lead the GRC function, ensuring compliance and risk management while driving continuous improvement.
  • Company: Join OVO, a mission-driven company tackling the climate crisis with innovative solutions.
  • Benefits: Hybrid work model, competitive salary, and opportunities for professional growth.
  • Other info: Collaborative culture focused on diversity and teamwork for the planet.
  • Why this job: Make a real impact on enterprise security and help shape a sustainable future.
  • Qualifications: Proven leadership in GRC, strong communication skills, and resilience in complex environments.

The predicted salary is between 60000 - 70000 £ per year.

Team: Enterprise Security, Governance, Risk & Compliance (GRC)

Location: Hub Based - Hybrid for all

Experience: Expert

Working pattern: Full-Time

Reporting to: Chief Information Security Officer

Sponsorship: Unfortunately we are unable to offer sponsorship for this role.

This role in 3 words: Engaging. Visionary. Enabler.

Top 3 qualities for this role: Leadership. Communication. Resilience.

Where you’ll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You’ll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life.

Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us.

Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you’ll be joining plays a gigantic role in making that happen. Here’s how: Reporting to the CISO this role is part of the Enterprise Security management team where you’ll deliver risk-led security focused on what matters most to the business.

We are hiring innovators, people with the vision to cut through complexity, to streamline, and deliver simplicity. We encourage collaboration, and want to instil a sense of ownership and pride in our Enterprise Security and GRC teams, as well as the stakeholders they engage with. This role is about leading change, reducing risk, and continuous improvement.

This role in a nutshell: OVO is seeking an experienced GRC Principal to provide leadership, compliance continuity, and strategic assurance. Reporting to the CISO you will balance day-to-day compliance and assurance stability, with continuous improvement of our risk levels and risk management practices.

As an Operator of Essential Services under NIS regulations, OVO requires a seasoned GRC professional capable of managing a complex regulatory landscape while providing hands-on guidance to a newly formed security GRC team.

You will:

  • Provide day-to-day leadership to the security GRC function, ensuring clear direction and role clarity.
  • Develop and manage strong stakeholder relationships (business) and reporting.
  • Be a thought leader connecting security teams to wider issues of risk.
  • Deliver GRC vision and people management.
  • Manage and track security risks within the corporate GRC framework.
  • Manage a complex regulatory environment.
  • Provide continuity and continuous improvement for our Information Security Management System (ISMS), streamlining and simplifying existing processes.
  • Focus is on the now, but consider the horizon: navigating shifting external risks and a complex regulatory landscape.
  • Lead solution design and delivery of enterprise compliance initiatives collaborating with Security Architecture and Assurance and the broader Security teams (ISO 27001 certification and Cybersecurity Assessment Framework).
  • Collaborate with GRC Security Architecture and Assurance to enable and track risk-reduction, focused security control improvement through automation and assurance.
  • Lead the preparation for board level risk updates, translating technical risk into executive-level insights.
  • Review the 'Three Lines of Defence' model to ensure clear delineation between 1st-line operations and 2nd-line oversight.
  • Collaborate and consult with risk management, compliance and DPO functions to ensure alignment.
  • Act as: Compliance, controls and audit partner to business; Legal and regulatory partner to business.

Your team will collaborate with business, Tech and security to deliver:

  • Policies and standards (top level/ISMS).
  • Communications and engagement.
  • Third party risk management (compliance/legal/contractual).
  • Security assurance and audit-readiness against controls.
  • Horizon scanning legal, regulatory and compliance.

Your key outcomes will be:

  • Unified governance: ownership of a living, breathing ISMS that satisfies multiple regulatory requirements without redundant effort.
  • Strategic reporting: delivering clear risk reporting to leadership that enables fast, informed business decisions.
  • Cultural transformation: engaged stakeholders and a measurable reduction in 'human-factor' risk, moving beyond 'tick-box' training to a high-engagement security awareness program.
  • Cross-functional partnerships: seamless collaboration with other teams such as Risk, Business Continuity, and Fraud to ensure a straightforward experience for OVO regarding compliance.

Systems:

  • GRC Platforms: for centralising the risk register and Common Control Framework (CCF).
  • Learning Management Systems (LMS): to drive and track the awareness program.
  • Collaboration and Workflow: management and task tracking.
  • Reporting Tools: to visualise KRIs and compliance health tracking.

You’ll be successful in this role if you …

  • Can think strategically as well as pragmatically.
  • Can communicate effectively across different levels and areas of a business (business, risk, Tech, security).

GRC Principal in London employer: OVO

At OVO, we pride ourselves on being an excellent employer that values flexibility and collaboration. Our dynamic work culture fosters growth and innovation, providing employees with opportunities to enhance their skills while contributing to a meaningful mission of delivering exceptional customer service. With competitive salaries, bonuses, and a variety of flexible benefits, OVO is committed to supporting our team members both personally and professionally in a vibrant office environment.

OVO

Contact Details:

OVO Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land GRC Principal in London

Join Compliance Communities

Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!

Attend Industry Conferences

Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.

Leverage Your University Career Services

If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.

Showcase Your Knowledge Online

Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like OVO looking for candidates who are engaged and informed.

We think you need these skills to ace GRC Principal in London

Leadership
Communication Skills
Resilience
Risk Management
Regulatory Compliance
Stakeholder Management
Information Security Management System (ISMS)

Some tips for your application 🫡

Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!

Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.

Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!

Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at OVO. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!

How to prepare for a job interview at OVO

Master the Regulations

Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!

Show Your Analytical Skills

Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!

Know Your Tools

Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!

Align with Company Culture

Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with OVO’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!