I’m working with a high-growth B2B SaaS business that is building out its security and compliance function as it continues to scale into more demanding enterprise markets.
They’re looking for a Security GRC Manager to take ownership of the security compliance programme end to end, while also playing a key role in enterprise customer trust and security reviews.
This is a hands-on role rather than one focused purely on coordinating audits. You’ll own the operating rhythm across frameworks including ISO 27001, SOC 1, SOC 2 and HIPAA, keeping controls running, evidence organised, policies current, risks visible and audits moving throughout the year.
You’ll also work directly with enterprise customers across security reviews, questionnaires, procurement, RFPs and diligence, helping turn security and compliance into a commercial asset rather than a blocker.
This would suit someone who enjoys owning the detail as well as the bigger picture, can operate across multiple teams and is comfortable being hands‑on with controls, evidence and customer conversations.
What you’ll be doing
- Own the security compliance programme across ISO 27001, SOC 1, SOC 2, HIPAA and future frameworks
- Run audit cycles throughout the year and coordinate external auditors and internal control owners
- Own controls, evidence, policies, risk registers, access reviews, vendor reviews and business continuity processes
- Lead customer‑facing security reviews, questionnaires, RFPs and enterprise diligence
- Build and maintain trust collateral, security portals and reusable questionnaire answer libraries
- Work closely with Product and Engineering to translate compliance requirements into practical controls
- Use AI to improve and automate areas such as policy drafting, evidence management and questionnaire responses
- Help improve the maturity of security, privacy, risk and customer trust as the business moves further upmarket
- Apply strong risk judgement and focus teams on meaningful security improvements rather than compliance theatre
What they’re looking for
- 4+ years’ experience across GRC, security compliance, trust, audit, information security, privacy operations or a related area
- Hands‑on experience with frameworks such as SOC 2, ISO 27001, SOC 1, HIPAA or GDPR
- Experience supporting enterprise sales, procurement, RFPs or customer security reviews
- Confidence leading customer conversations around security, privacy and risk
- Experience using AI to improve GRC workflows, such as policy drafting, questionnaire responses or vendor reviews
- Strong written communication and attention to detail
- Good understanding of modern B2B SaaS environments, including cloud infrastructure, access management, vendors, product development and customer data
- Strong risk judgement and the ability to prioritise what genuinely matters
- Experience building or owning a trust centre, customer‑facing security portal or security questionnaire library
- Comfortable working autonomously in a high‑growth environment where processes are still evolving
London | Monday to Thursday in the office
Market-leading compensation + share options + private healthcare + 25 days holiday + enhanced parental leave + L&D budget
#J-18808-Ljbffr
Risk Management Officer employer: Propel
Join a dynamic and innovative team as a Project Management Office (PMO) Officer, where your expertise in vendor and contract management will be valued in a collaborative and high-performing environment. With a focus on employee growth and development, we offer flexible working arrangements, including remote work with occasional days in London, ensuring a healthy work-life balance. Our commitment to fostering a culture of excellence and continuous improvement makes us an exceptional employer for those seeking meaningful and rewarding opportunities in the finance and IT sectors.