Governance, Risk & Compliance Consultant in Glasgow

Governance, Risk & Compliance Consultant in Glasgow

Glasgow Full-Time 50000 - 65000 € / year (est.) Home office (partial)
Sword Group

At a Glance

  • Tasks: Advise clients on governance, risk management, and compliance in various sectors.
  • Company: Join Sword, a leader in business technology solutions with a focus on innovation.
  • Benefits: Enjoy flexible working, personalised career development, and a fantastic benefits package.
  • Other info: Diverse and inclusive workplace with opportunities for growth and development.
  • Why this job: Make a real impact by helping clients navigate complex regulatory landscapes.
  • Qualifications: Experience in Governance, Risk and Compliance roles is essential.

The predicted salary is between 50000 - 65000 € per year.

Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, dedicated to driving transformational change for our clients. We leverage proven technology, specialist teams, and extensive domain expertise to create robust technical foundations across platforms, data, and business applications. Our mission is fueled by a passion for technology as a means to solve complex business problems and achieve our clients' objectives.

About the Role:

As a GRC Consultant, you will advise and support our clients across governance, risk management and regulatory compliance. The role focuses on aligning cyber, information security, operational resilience and wider risk frameworks to UK‑specific regulatory, safety and operational requirements.

You will work closely with client stakeholders to assess maturity, design and implement control frameworks, and provide pragmatic, risk‑based guidance that supports safe, secure and resilient operations.

  • Deliver governance, risk and compliance consulting engagements for a variety of clients and industries, including UK Oil & Gas (operators, service companies and joint ventures), CNI, Finance and Public Sector.
  • Lead or support GRC maturity assessments, gap analyses and audits against relevant standards and regulations.
  • Interpret and apply UK specific regulatory requirements, translating them into practical, implementable controls.
  • Design and implement GRC frameworks covering risk management, policy, assurance and reporting.
  • Support compliance activities aligned to various regulations and assurance requirements.
  • Develop and maintain risk registers, control libraries and assurance plans.
  • Facilitate risk workshops, control reviews and senior stakeholder briefings.
  • Support cyber and information security governance aligned to ISO 27001, NCSC guidance and sector best practice.
  • Provide advisory input into operational resilience, business continuity and third party risk management.
  • Produce clear, evidence based client deliverables including reports, executive summaries and remediation roadmaps.
  • Support pre audit, regulatory inspection and client assurance activities.

Requirements

Essential

  • Good experience and background of producing high quality documentation and solution artefacts.
  • Proven experience in Governance, Risk and Compliance roles within regulated or critical infrastructure environments.
  • Strong understanding of the UK Oil & Gas and finance regulatory landscape.
  • Working knowledge of key frameworks and standards, such as: ISO/IEC 27001, ISO 22301 (Business Continuity), UK NIS Regulations and NCSC guidance, NIST CSF, UK GDPR, Data Protection Act, DORA.
  • Experience conducting risk assessments, control gap analyses and assurance activities.
  • Proven ability to drive adoption, stakeholder buy-in and embedding change.
  • Strong background in end-to-end delivery (from design to implementation and embedding).
  • Ability to engage confidently with technical, operational and executive stakeholders.
  • Strong written communication skills with experience producing client facing reports.
  • Strong ability to translate technical and GRC concepts into clear, business-friendly language.
  • Experience working in consulting or advisory environments.

Desirable / Valuable

  • Knowledge of IEC 62443 for OT/ICS security.
  • Operational Technology (OT) and industrial control environments.
  • Familiarity with NCSC Cyber Assessment Framework (CAF) or sector‑specific assurance models.
  • Experience supporting regulatory audits (HSE, NIS competent authority, client audits).
  • Certifications such as: ISO 27001 Lead Implementer / Lead Auditor, CISM, CRISC or CISSP, IRM or ISO risk management qualifications.
  • Understanding of supply‑chain and third‑party risk in Oil & Gas, CNI and finance ecosystems.
  • Familiarity with GRC tooling such as OneTrust or Archer.
  • Ability to contribute to business development or service offering development.

Benefits

At Sword, our core values and culture are based on caring about our people, investing in training and career development, and building inclusive teams where we are all encouraged to contribute to achieve success. We offer comprehensive benefits designed to support your professional development and enhance your overall quality of life. In addition to a Competitive Salary, here's what you can expect as part of our benefits package:

  • Personalised Career Development: We create a development plan customised to your goals and aspirations, with a range of learning and development opportunities within a culture that encourages growth.
  • Flexible working: Flexible work arrangements to support your work-life balance.
  • A Fantastic Benefits Package: This includes generous annual leave allowance, enhanced family friendly benefits, pension scheme, access to private health, well-being, and insurance schemes.

At Sword we are dedicated to fostering a diverse and inclusive workplace and are proud to be an equal opportunities employer, ensuring that all applicants receive fair and equal consideration for employment, regardless of whether they meet every requirement. If you don’t tick all the boxes but feel you have some of the relevant skills and experience we’re looking for, please do consider applying and highlight your transferable skills and experience. We embrace diversity in all its forms, valuing individuals regardless of age, disability, gender identity or reassignment, marital or civil partner status, pregnancy or maternity status, race, colour, nationality, ethnic or national origin, religion or belief, sex, or sexual orientation. Your perspective and potential are important to us. If we can do anything to help make the hiring process more accessible, please let our talent acquisition team know when you apply so we can support any adjustments.

Governance, Risk & Compliance Consultant in Glasgow employer: Sword Group

At Sword, we pride ourselves on being an exceptional employer, offering a vibrant work culture that prioritises employee growth and well-being. Our commitment to personalised career development, flexible working arrangements, and a comprehensive benefits package ensures that our team members thrive both professionally and personally. Join us in a dynamic environment where your contributions are valued, and diversity is celebrated, particularly within the exciting sectors of Energy, Public, and Finance.

Sword Group

Contact Detail:

Sword Group Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Governance, Risk & Compliance Consultant in Glasgow

Tip Number 1

Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their values and how they align with your own. This will help you tailor your responses and show that you're genuinely interested in being part of their team.

Tip Number 3

Practice makes perfect! Conduct mock interviews with friends or use online platforms. This will help you get comfortable with common questions and refine your answers, making you more confident when it counts.

Tip Number 4

Don’t forget to follow up after interviews! A simple thank-you email can leave a lasting impression and keep you top of mind. Plus, it shows your enthusiasm for the role and appreciation for the opportunity.

We think you need these skills to ace Governance, Risk & Compliance Consultant in Glasgow

Governance, Risk and Compliance (GRC)
UK Oil & Gas Regulatory Knowledge
ISO/IEC 27001
ISO 22301
UK NIS Regulations
NIST CSF
UK GDPR

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter for the GRC Consultant role. Highlight your experience in governance, risk management, and compliance, especially within regulated environments like Oil & Gas or finance. We want to see how your skills align with our mission!

Showcase Your Documentation Skills:Since strong written communication is key for this role, include examples of high-quality documentation you've produced in the past. Whether it's reports, executive summaries, or remediation roadmaps, let us know how you can translate complex concepts into clear, business-friendly language.

Be Specific About Your Experience:When detailing your background, be specific about the frameworks and standards you're familiar with, like ISO 27001 or UK GDPR. This will help us understand your expertise and how it fits into our consulting engagements.

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates. Plus, we love seeing applications come in through our own platform!

How to prepare for a job interview at Sword Group

Know Your Regulations

Familiarise yourself with UK-specific regulatory requirements relevant to the role. Brush up on frameworks like ISO 27001 and UK GDPR, as being able to discuss these confidently will show your expertise and readiness to tackle compliance challenges.

Prepare Real-World Examples

Think of specific instances where you've successfully implemented GRC frameworks or conducted risk assessments. Being able to share these experiences will demonstrate your practical knowledge and problem-solving skills, making you a more compelling candidate.

Engage Stakeholders Effectively

Practice how you would communicate complex GRC concepts to various stakeholders. Use clear, business-friendly language to explain technical details, as this will highlight your ability to bridge the gap between technical and operational teams.

Showcase Your Documentation Skills

Since producing high-quality documentation is essential for this role, prepare samples of reports or deliverables you've created in the past. This will not only showcase your writing skills but also your attention to detail and commitment to quality.