Cyber GRC/IT Advisory Director
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Audit & Risk Recruitment are delighted to be working as the exclusive recruitment partner on behalf of a rapidly expanding professional services and technology advisory business seeking to appoint a GRC Advisory Director! This is an opportunity to help build and shape a fast-growing GRC advisory practice at an early stage, with the backing of both a leading accountancy and advisory firm and a leading IT and cybersecurity business. You will have the scope to influence the service, build the team and develop client relationships, while being supported by the wider infrastructure, brand and client base. £75,000-£105,000 plus bonus and benefits3 days per week in their Derby, Nottingham or Birmingham officesUnfortunately this role cannot provide visa sponsorship Responsibilities Lead complex project engagements including DPIA reviews, AI Ethics and Governance Audits, Operational Resilience assessments, Tabletop Exercises and PE/M&A cyber due diligence and later when more established - ISO 27001 implementationsOwn GRC Advisory Premium and vCDO retainer accounts, including scope, deliverables, client satisfaction and commercial renewalReview all consultant outputs and maintain quality standards across the teamKeep current with relevant regulatory developments and translate changes into updated advice for clientsManage internal platforms on behalf of clients, ensuring compliance programmes are properly tracked and evidenced Team Manage a team of GRC Consultants and Senior Consultants, growing from three to around seven people over the first three yearsProvide hands-on coaching during engagements and peer review of deliverablesSupport team members through professional certifications including ISO 27001 Lead Auditor, CIPP/E and BCS Data Protection PractitionerContribute to recruitment including interview involvement and onboarding of new hires Clients and Business Development Act as senior point of contact for retainer clients at MD, Finance Director and board levelIdentify opportunities to extend the scope of existing client relationships, whether that is moving from a one-off project to a retainer or broadening the range of frameworks coveredSupport the BD Manager in qualifying opportunities and providing technical input during proposalsWork with partners across the wider firm to develop referral opportunities from their existing client baseRepresent the practice at relevant sector events and industry forums
Requirements
A solid track record of delivering GRC services implementations from scoping through to certificationHands-on experience with DPIAs, data protection health checks and policy development under UK GDPRDirect client contact at board or senior leadership level, with the ability to present clearly and handle difficult questionsExperience managing or mentoring a small team of compliance or information security professionalsWorking knowledge of at least one of: NIS2, DORA, FCA PS21/3 operational resilience, the EU AI Act, or ISO 22301 business continuityA background in professional services or consultancy, with an understanding of how to run engagements commercially Qualifications (preferable)ISO 27001 Lead Auditor or Lead Implementer from an accredited body such as BSI, LRQA or CQIBCS Certificate in Data Protection, CIPP/E or an equivalent data protection qualificationISO 22301 Lead Implementer or a recognised business continuity qualificationCyber Essentials Assessor certified by an IASME or NCSC approved bodyISO 42001 AI Management Systems, which is increasingly relevant given the EU AI Act timelineA degree in law, computer science, business, information security or a related field Audit & Risk Recruitment
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on apply4u.co.ukGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Panel Discussion: Responsible AI in Practice - Real-World Examples and Challenges
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production
Navigating the AI Shift