At a Glance
- Tasks: Lead the development and management of governance, risk, and compliance frameworks.
- Company: Respected tech provider specialising in secure managed services for defence and public sectors.
- Benefits: Comprehensive benefits, structured career coaching, and tailored training pathways.
- Other info: Opportunity for continuous professional development and exposure to cutting-edge security solutions.
- Why this job: Make a real impact by ensuring compliance and mitigating risks in a dynamic environment.
- Qualifications: 5+ years in GRC or related fields with strong analytical and communication skills.
The predicted salary is between 63000 - 77000 Β£ per year.
The GRC Manager will take ownership of developing, implementing, and maintaining the organisation's governance, risk management, and compliance frameworks. You will ensure operational activities align with legal requirements, regulatory standards, and internal policies, while proactively identifying and mitigating enterprise risks.
About the Client: Our client is a highly respected technology and secure managed services provider, specialising in delivering resilient, high-assurance IT infrastructure and security solutions to defence and public sector partners. They pride themselves on fostering continuous professional development through structured career coaching, tailored training pathways, and comprehensive benefit packages.
Key Responsibilities:
- Develop, implement, and manage the overarching GRC strategy, policies, and procedural frameworks.
- Conduct enterprise risk assessments and maintain the organisation's central risk register.
- Monitor operational, regulatory, cybersecurity, financial, and third-party risks.
- Ensure full compliance with relevant statutory regulations, legal standards, and framework requirements.
- Coordinate internal and external audit activities, managing the swift remediation of findings.
- Establish compliance monitoring mechanisms and present regular reporting to senior leadership.
- Collaborate with internal business units to design and embed effective risk mitigation controls.
- Monitor regulatory developments and assess their potential operational impact.
- Support business continuity, disaster recovery, and information security governance initiatives.
- Oversee third-party/vendor risk evaluations and perform required due diligence.
- Lead organisation-wide training programmes to promote a strong security and compliance culture.
Required Skills and Experience:
- Essential Experience: Minimum of 5 years demonstrable experience within GRC, Information Security, Audit, or Risk disciplines.
- Core Knowledge: Thorough understanding of enterprise risk management frameworks and internal audit processes.
- Data Protection: Proven hands-on experience with GDPR compliance (including ROPA, LIA, and DPIA requirements).
- Communication: Excellent analytical, problem-solving, and senior stakeholder management abilities.
- Technical Aptitude: Experience utilising modern GRC software platforms and risk mapping tools.
- Desirable: Exposure to Defence Cyber Certification (DCC), Cyber Essentials (CE), or Cyber Essentials Plus (CE+).
- Familiarity with Secure by Design (SbD) principles and JSP 453 assurance activities.
- Understanding of vendor risk management, SOC2, or NIS2 directives.
- Previous experience performing duties as a Crypto Custodian or Alternate Custodian.
- Relevant industry certifications such as CISA, CRISC, CISM, or CISSP.
Governance and Compliance Manager employer: Resourcing Group
Join a dynamic and innovative Cyber Security company that prioritises employee growth and collaboration in a fully remote environment. With a strong focus on hands-on engineering and customer engagement, you'll have the opportunity to make a significant impact while enjoying a competitive salary and the flexibility of working from anywhere in the UK. The company fosters a culture of continuous learning and support, ensuring you thrive in your role as a Customer Platform Architect.