Information Security GRC Specialist

Gwi
London, UK
3 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Part-time (≤ 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Software as a Service Cloud Computing Security Cyber Security

Job description

As our Information Security GRC Specialist you’ll play a pivotal role in shaping the future of security compliance at GWI. Reporting into our General Counsel and working closely with our Information Security, Product, and Technology teams, you’ll own our compliance posture across security frameworks, vendor risk, and client-facing security requirements - while building a security-conscious culture across the business.

A few things you’ll be responsible for:

Own and maintain GWI’s ISO 27001 certification and compliance across relevant security frameworks, keeping our posture sharp as the threat landscape evolves.

Develop, implement, and maintain information security policies and procedures aligned with industry best practices.

Lead vendor risk management and client security assessments - including responding to client security questionnaires and onboarding requirements.

Build and maintain GWI’s security trust portal, showcasing our credentials to clients and stakeholders using tools such as Drata or Vanta.

Drive security awareness across the business through training programmes and internal communications that promote a strong GRC culture.

It’s also fun; shaking things up is what working for GWI is all about. You’ll need to be flexible, comfortable with continuous change, and working in a high-tempo environment., Diversity is fundamental to who we are-both as a data company and as a workplace. Our data reflects global realities, and so must our teams. We strive to ensure our workforce is as diverse and inclusive as the insights we provide to our clients.

As a Disability Confident employer, we welcome applications from disabled candidates and are committed to providing all necessary adjustments during the hiring process. We also actively encourage applications from underrepresented and marginalized communities.

At GWI, you will find a place where you can contribute meaningfully, grow professionally, and belong fully.

Requirements

You’ll need to be able to demonstrate the core skills this role requires. You don’t have to tick all the boxes right away; the important thing is that you’re willing to learn. Here’s what the team will be looking for in you:

In-depth, practical experience obtaining and maintaining ISO 27001 certification, with solid knowledge of frameworks such as NIST - typically 3-5 years in an information security compliance role, though other experience levels will be considered.

Proven ability to develop and maintain security policies and procedures that align with industry best practice.

Experience conducting vendor security assessments and managing client security onboarding requirements, balancing risk against commercial objectives.

Hands-on experience building or maintaining a security trust portal; familiarity with tools such as Drata or Vanta is a plus.

Knowledge of SaaS and AI environments, with experience implementing and managing cloud security best practices.

Strong communication skills - able to translate complex GRC topics into clear internal guidance and keep the wider business informed and engaged on security matters.

Equally important is attitude. We want people who think big (to make an impact), ask why (to find a better way), and show respect (to everyone, at every level, all the time). Those are our values, and they’re a big part of what we’re looking for in you.

Benefits & conditions

At GWI, you’ll find meaningful work, visible impact, and a culture that empowers you to do your best. Our package includes:

  • Time to recharge - 25 days’ annual leave, plus office closures over the holidays.
  • Health & wellbeing - Health cash plan, enhanced family benefits, carer days, and mental health support.
  • Financial benefits - Competitive salary, 4% pension matching, and recognition programs that celebrate success.
  • Flexibility & balance - Flexitime, early Friday finishes, hybrid and remote options, plus a “work from home” budget.
  • Career growth - Accredited learning, leadership development, and global career mobility.
  • Community & impact - DE&I initiatives, volunteering opportunities, donation matching, and payroll giving.

Put all that together and GWI is the friendliest, most fulfilling place any of us has ever worked.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:24 min

Managing environmental components via Terraform core architecture

Talia Nassi · LIVE

3:46 min

Core terminology and audiences for interpretable artificial intelligence

Karol Przystalski · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all