At a Glance
- Tasks: Shape AI governance and build compliance frameworks for a leading enterprise AI company.
- Company: Join WRITER, a fast-growing leader in enterprise generative AI with a collaborative culture.
- Benefits: Generous PTO, medical insurance, parental leave, wellness stipends, and competitive compensation.
- Why this job: Make a real impact on AI security and governance while working with top-tier clients.
- Qualifications: 2+ years in GRC or security compliance, strong project management, and excellent communication skills.
- Other info: Remote work options available; dynamic environment with opportunities for growth.
The predicted salary is between 36000 - 60000 ยฃ per year.
About WRITER
WRITER is where the world's leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. We are proving it is possible through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation.
About the role
This is your chance to shape AI governance from the ground up at one of the fastest-growing companies in enterprise AI. As a security specialist, GRC at WRITER, you will be building the frameworks that ensure our AI platform earns and keeps the trust of the world's most demanding enterprises. You are not just checking boxesโyou are creating the compliance infrastructure that enables WRITER to scale safely and securely while moving at the speed of innovation.
The opportunity here is extraordinary: you will work at the intersection of AI, security, and business enablement, helping define what governance looks like for enterprise AI systems that did not exist a few years ago. You will lead audit engagements for SOC 2, ISO 27001, and other critical certifications, respond to customer security assessments that directly impact major deals, and build the policies and controls that protect both our AI models and the sensitive data flowing through them.
What you will do
- Own and drive WRITER's security compliance program end-to-end including managing SOC 2 Type II audits, ISO Triad (27001/27701/42001) certification, and expanding our compliance coverage to meet emerging customer requirements in regulated industries like financial services and healthcare.
- Lead customer assurance efforts by responding to security questionnaires, DDQs, and RFPs from enterprise customers, maintaining our trust portal with up-to-date security documentation, and partnering with Sales to remove security blockers that could delay major deals.
- Build and maintain WRITER's security governance framework including creating and updating security policies, access control standards, vendor risk procedures, incident response plans, and AI-specific governance documentation that addresses model training, data handling, and responsible AI deployment.
- Conduct continuous control monitoring and evidence collection by implementing automated compliance workflows, tracking remediation activities across teams, performing control testing, and ensuring we maintain audit-ready documentation throughout the year instead of scrambling before audits.
- Drive risk assessments and third-party vendor security reviews by evaluating supplier controls, identifying and quantifying security risks across our AI platform and infrastructure, and working cross-functionally to prioritize and track remediation efforts.
- Partner with Engineering and Product teams to embed compliance into the development lifecycle by reviewing architecture decisions for security and privacy implications, ensuring secure-by-design principles are followed for new AI features, and translating regulatory requirements into technical controls that developers can actually implement.
- Serve as the primary point of contact for external auditors and assessors, coordinating evidence collection, scheduling interviews, addressing findings, and ensuring audit processes run smoothly while minimizing disruption to the broader team.
What you need
- 2+ years of hands-on experience in GRC, security compliance, or audit roles within fast-paced tech companies or startups.
- Deep working knowledge of security frameworks and certifications including SOC 2 Type II, ISO 27001, GDPR, CCPA, and familiarity with emerging AI governance requirements.
- Strong technical literacy that allows you to evaluate cloud security architectures, understand API security, review access control implementations, and have credible conversations with engineers about security controls.
- Excellent project management abilities with the skill to juggle multiple audits, customer questionnaires, policy updates, and remediation initiatives simultaneously.
- Outstanding communication skills that enable you to explain complex compliance requirements in clear, actionable language to technical and non-technical audiences alike.
- Natural curiosity about AI governance and emerging regulatory landscape including AI-specific frameworks, model risk management, data privacy implications of AI training, and responsible AI principles.
- Alignment with WRITER's values of Connect, Challenge, and Own.
Benefits & perks (UK full-time employees):
- Generous PTO, plus company holidays.
- Comprehensive medical and dental insurance.
- Paid parental leave for all parents (12 weeks).
- Fertility and family planning support.
- Early-detection cancer testing through Galleri.
- Competitive pension scheme and company contribution.
- Annual work-life stipends for wellness, learning and development.
- Company-wide off-sites and team off-sites.
- Competitive compensation and company stock options.
Security specialist, GRC (UK) in London employer: writer.com
Contact Detail:
writer.com Recruiting Team
StudySmarter Expert Advice ๐คซ
We think this is how you could land Security specialist, GRC (UK) in London
โจTip Number 1
Network like a pro! Reach out to people in the industry, especially those already working at WRITER. A friendly chat can open doors and give you insider info on what they're really looking for.
โจTip Number 2
Prepare for interviews by diving deep into WRITER's mission and values. Show us how your skills align with our vision of AI governance and security. We love candidates who are genuinely excited about what we do!
โจTip Number 3
Practice your pitch! Be ready to explain your experience in GRC and security compliance clearly and confidently. We want to hear how you've tackled challenges and driven results in past roles.
โจTip Number 4
Donโt forget to apply through our website! Itโs the best way to ensure your application gets seen by the right people. Plus, it shows us you're serious about joining the WRITER team.
We think you need these skills to ace Security specialist, GRC (UK) in London
Some tips for your application ๐ซก
Tailor Your Application: Make sure to customise your CV and cover letter for the Security Specialist role. Highlight your experience with GRC, security compliance, and any relevant certifications like SOC 2 or ISO 27001. We want to see how your skills align with our mission at WRITER!
Showcase Your Technical Know-How: Donโt shy away from discussing your technical literacy! Mention any experience you have with cloud security architectures or API security. We love candidates who can communicate effectively with both technical and non-technical teams.
Communicate Clearly: When writing your application, keep it clear and concise. Use straightforward language to explain your past experiences and how they relate to the role. Remember, weโre looking for someone who can make complex compliance requirements easy to understand!
Apply Through Our Website: We encourage you to apply directly through our website. Itโs the best way for us to receive your application and ensures youโre considered for the role. Plus, it shows youโre keen on joining our team at WRITER!
How to prepare for a job interview at writer.com
โจKnow Your Compliance Frameworks
Make sure you brush up on your knowledge of SOC 2 Type II, ISO 27001, and other relevant security frameworks. Be ready to discuss how you've applied these in past roles, as this will show your understanding of compliance and its importance in a fast-paced tech environment.
โจShowcase Your Technical Literacy
You donโt need to be a coder, but having a solid grasp of cloud security architectures and API security is crucial. Prepare to have conversations about security controls with engineers, demonstrating that you can bridge the gap between technical and non-technical teams.
โจDemonstrate Project Management Skills
Be prepared to talk about how you've managed multiple audits or compliance initiatives simultaneously. Highlight specific examples where you kept stakeholders informed and projects moving forward without constant oversightโthis will showcase your ability to juggle responsibilities effectively.
โจCommunicate Clearly and Effectively
Practice explaining complex compliance requirements in simple terms. Youโll need to convey these ideas to both technical and non-technical audiences, so think of examples where youโve successfully crafted policies or presented risk scenarios that were easily understood by all.