InfoSec GRC - 9 month FTC in London

InfoSec GRC - 9 month FTC in London

London Temporary 60750 - 74250 £ / year (est.) No working from home possible
P

At a Glance

  • Tasks: Join us to enhance cyber and information security governance while implementing Microsoft Purview Compliance Manager.
  • Company: Pantheon, a leader in private markets investing with a collaborative culture.
  • Benefits: Gain valuable experience in a dynamic environment with potential for career growth.
  • Other info: Opportunity to work with a diverse team and develop sustainable processes.
  • Why this job: Make a real impact on compliance and risk management in a cutting-edge tech setting.
  • Qualifications: Experience with Microsoft Purview and knowledge of GDPR, DORA, and ISO/IEC 27001 preferred.

The predicted salary is between 60750 - 74250 £ per year.

Pantheon has been at the forefront of private markets investing for more than 40 years, earning a reputation for an innovative approach to investing in secondaries, co-investments, and primary fund investments, as well as capital formation across commingled funds, evergreen vehicles and customized solutions.

Our specialist investment capabilities span multiple strategies across private equity, infrastructure and real assets, and private credit.

Through our collaborative and committed culture, we find new ways to solve complex problems together and deliver innovative investment opportunities across private markets.

Pantheon currently manages approximately $82.3 billion in AUM across all its strategies, serving more than 750 institutional and 638 private wealth clients worldwide

  • For further details please visit www. pantheon. com
  • Purpose of Position

This fixed-term role will provide practical delivery across Pantheon’s cyber and information-security governance, risk and compliance activities.

A major priority will be to implement and build out Microsoft Purview Compliance Manager, starting with GDPR, DORA and ISO/IEC 27001, to identify control gaps, align ownership and evidence collection, and establish a sustainable compliance operating model and governed evidence repository.

The role will also deliver core GRC activity across cyber-risk management in Resolver, supplier onboarding and assurance through Risk Ledger, third-party risk management, DDQ/ODD responses, audit and regulatory evidence, control testing, remediation tracking and management reporting.

The role is intended to increase delivery capacity, improve the quality and reuse of evidence, and leave well-documented, sustainable processes at the end of the fixed term.

Key Responsibilities

  • Implement and build out Microsoft Purview Compliance Manager, beginning with GDPR, DORA and ISO/IEC 27001 and extending to other applicable regulations, standards and internal controls.
  • Configure assessments, scope organisational boundaries and services, map common controls, assign owners, record implementation and testing status, maintain evidence, and translate gaps into prioritised improvement actions with dates and closure criteria.
  • Design and build a governed Share Point evidence repository with an agreed taxonomy, metadata, naming, versioning, access, retention, approval, review and evidence-validity model.
  • Map authoritative and reusable evidence to controls; identify missing, stale, duplicated or contradictory material; and rationalise collection for Compliance Manager, audits, regulatory requests, DDQs and ODDs.
  • Administer and develop cyber-risk records in Resolver, supporting consistent risk identification, assessment, ownership, treatment, acceptance, review, escalation and reporting, with a clear audit trail.
  • Support end-to-end third-party risk management, including supplier intake, inherent-risk triage, due diligence, Risk Ledger onboarding and administration, evidence review, findings, remediation, exceptions, periodic reassessment and offboarding.
  • Coordinate and draft accurate, consistent and client-ready responses to DDQs, ODDs, RFPs, audits and regulatory information requests, using approved sources and engaging Cyber, Risk, Privacy, Legal, Technology and business owners as required.
  • Perform control and compliance gap assessments, support control testing, maintain remediation plans, follow up overdue actions and verify evidence before closure.
  • Assess proportionate opportunities for automation, continuous monitoring and evidence reuse across Microsoft 365, Azure, Purview, security tooling and GRC platforms, while documenting activities requiring manual assessment.
  • Produce concise management information covering compliance status, material cyber risks, supplier-assurance progress, control gaps, overdue actions, evidence health, dependencies and remediation.
  • Document procedures, decisions, mappings, ownership and reporting cadences; train relevant users; and deliver a complete, usable handover so the capabilities remain sustainable after the FTC ends.
  • Knowledge & Experience Required
  • Demonstrable hands-on Microsoft Purview Compliance Manager experience, including assessments, controls, improvement actions, ownership, implementation and testing status, evidence and reporting.
  • Broad practical GRC experience encompassing cyber-risk management, control assessment, remediation tracking, policy and standards activity, regulatory assurance and audit support.
  • Working knowledge of GDPR, DORA and ISO/IEC 27001, with the ability to translate obligations into controls, test procedures, evidence requirements and proportionate remediation.
  • Experience of third-party risk management, including supplier due diligence, security evidence review, findings, remediation, exceptions and lifecycle reassessment.
  • Experience completing or coordinating DDQs, ODDs, RFPs, audit requests or regulatory evidence submissions, with strong attention to accuracy, consistency and approval.
  • Strong evidence-management skills, including control libraries, Share Point repositories, metadata, version control, access governance, review cycles, source validation and quality assurance.
  • Good working knowledge of Microsoft 365, Purview, Azure and security and compliance capabilities, with sound judgement about automation and manual assurance.
  • Clear written and verbal communication, with the ability to work effectively with Technology, Risk, Privacy, Legal, Procurement, Internal Audit, business owners and senior management.
  • Strong delivery discipline: able to manage a time-bound backlog, prioritise competing deadlines, maintain defensible records and leave complete documentation and a sustainable handover.

Desirable

  • Hands-on experience of Risk Ledger, Resolver or comparable GRC and third-party risk platforms.
  • Experience in regulated financial services, including DORA implementation, regulatory engagement, external assurance or ISO/IEC 27001 certification activity.
  • Experience migrating existing controls, risks, assessments and evidence, and creating custom assessment content where standard templates do not meet business needs.
  • Experience using Power Platform, Microsoft Graph, APIs or other appropriate methods to streamline evidence collection, workflow and reporting.
  • Fixed term deliverables
  • First 30 days: confirm the prioritised GRC backlog, stakeholders and RACI; validate Compliance Manager licensing, templates and scope; establish a pilot assessment and evidence-repository design; and review current Resolver, Risk Ledger, TPRM and DDQ/ODD processes and outstanding work.
  • By 60 days: populate the agreed GDPR, DORA and ISO/IEC 27001 assessments; map common controls and available evidence; triage priority gaps; improve evidence quality; and deliver agreed cyber-risk, supplier-assurance and due-diligence actions.
  • By 90 days: operate control testing and review cycles; establish reporting and remediation governance; demonstrate improved Resolver and Risk Ledger data quality and workflow; and embed a repeatable, approved DDQ/ODD evidence process.
  • By the end of the FTC: deliver a functioning and governed Compliance Manager capability and evidence repository, demonstrable improvements across the wider GRC remit, trained owners and a complete handover pack.

This job description is not to be construed as an exhaustive statement of duties, responsibilities, or requirements.

You may be required to perform other job-related duties as reasonably requested by your manager.

Pantheon is an Equal Opportunities employer, we are committed to building a diverse and inclusive workforce so if you're excited about this role but your past experience doesn't perfectly align we'd still encourage you to apply.

InfoSec GRC - 9 month FTC in London employer: Pantheon Ventures Careers

Pantheon is an exceptional employer, offering a collaborative and innovative work culture that empowers employees to tackle complex challenges in the private markets sector. With a strong commitment to professional development, employees benefit from hands-on experience with cutting-edge tools like Microsoft Purview Compliance Manager, while also enjoying a diverse and inclusive environment that values every individual's contribution. Located in a vibrant area, Pantheon provides unique opportunities for growth and meaningful engagement in the rapidly evolving field of cyber and information security.

P

Contact Details:

Pantheon Ventures Careers Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land InfoSec GRC - 9 month FTC in London

✨Get Engaged in Cybersecurity Communities

Dive into online forums or local meetups, like OWASP events or Cybersecurity conferences. These spaces are packed with pros who can share insights and might even know about temporary roles at places like Pantheon Ventures Careers.

✨Showcase Your Skills Publicly

Link your GitHub or create a series of blogs sharing your knowledge on cybersecurity topics. It’s a great way to demonstrate your expertise and attract attention from hiring managers, especially when they see your passion in action.

✨Stay On Top of Temp Opportunities

Keep an eye on platforms that list temporary positions specifically in tech. Websites focusing on contract roles in cybersecurity can lead straight to employers like Pantheon Ventures Careers.

✨Make Contact with Recruiters Specialising in Cybersecurity

Reach out to recruitment agencies that focus on cybersecurity roles. They often have insights into temporary roles before they’re advertised and can put your name forward to companies like Pantheon Ventures Careers.

We think you need these skills to ace InfoSec GRC - 9 month FTC in London

Microsoft Purview Compliance Manager
GDPR
DORA
ISO/IEC 27001
Cyber-risk management
Control assessment
Remediation tracking

Some tips for your application 🫡

Show Off Your Technical Skills:In cybersecurity, it's vital to highlight your skills with relevant tools and technologies. Make sure your CV showcases your experience with firewalls, intrusion detection systems, and any cybersecurity frameworks you've worked with. This gives Pantheon Ventures Careers a clear view of your capabilities right off the bat.

Certifications Matter:If you’ve got any cybersecurity certifications, like CompTIA Security+ or CISSP, flaunt them! These not only validate your skills but also show that you’re committed to the field. Add a section to your CV specifically for this, because in a temporary role like this, those credentials can really set you apart.

Tailor Your Cover Letter to the Role:For a temporary position, we want to see your willingness to learn and adapt quickly. Make your cover letter specific to the role at Pantheon Ventures Careers; mention why you’re excited about the opportunity and how it fits your career goals. A personal touch can make a big difference!

Don’t Forget the Soft Skills:In cybersecurity, technical skills are crucial, but so are soft skills like teamwork and communication. Make sure to weave examples of how you've collaborated with teams or communicated complex ideas into your application. This shows that you're not just a tech whizz but also a great team player, perfect for a temporary role at Pantheon Ventures Careers.

How to prepare for a job interview at Pantheon Ventures Careers

✨Brush Up on Technical Skills

Make sure you’re familiar with the latest cybersecurity tools and techniques, like firewalls, intrusion detection systems, and malware analysis. During the interview with Pantheon Ventures Careers for the InfoSec GRC - 9 month FTC, be prepared to discuss specific scenarios where you tackled security threats or vulnerabilities.

✨Show Your Problem-Solving Prowess

Cybersecurity is all about thinking on your feet. Expect technical questions that require you to demonstrate your problem-solving abilities. You might be presented with a mock security breach scenario, so practising your responses to potential threats can be a game changer!

✨Demonstrate Your Adaptability

As this is a temporary role, showing that you're adaptable and quick to learn is crucial. Talk about times you've picked up new skills or reacted to changing situations quickly. Employers want to know you can hit the ground running and keep things secure during your short stay at Pantheon Ventures Careers.

✨Bring Relevant Certifications

If you have any relevant cybersecurity certifications, like CompTIA Security+ or CEH, be sure to mention them. This can really help you stand out during a temporary hiring process, as it showcases your commitment to the field and your readiness to take on the InfoSec GRC - 9 month FTC role at Pantheon Ventures Careers.