Cyber GRC/IT Advisory Director

Audit & Risk Recruitment
UK
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cyber Security Information Technology

Job description

Audit & Risk Recruitment are delighted to be working as the exclusive recruitment partner on behalf of a rapidly expanding professional services and technology advisory business seeking to appoint a GRC Advisory Director! This is an opportunity to help build and shape a fast-growing GRC advisory practice at an early stage, with the backing of both a leading accountancy and advisory firm and a leading IT and cybersecurity business. You will have the scope to influence the service, build the team and develop client relationships, while being supported by the wider infrastructure, brand and client base. £75,000-£105,000 plus bonus and benefits3 days per week in their Derby, Nottingham or Birmingham officesUnfortunately this role cannot provide visa sponsorship Responsibilities Lead complex project engagements including DPIA reviews, AI Ethics and Governance Audits, Operational Resilience assessments, Tabletop Exercises and PE/M&A cyber due diligence and later when more established - ISO 27001 implementationsOwn GRC Advisory Premium and vCDO retainer accounts, including scope, deliverables, client satisfaction and commercial renewalReview all consultant outputs and maintain quality standards across the teamKeep current with relevant regulatory developments and translate changes into updated advice for clientsManage internal platforms on behalf of clients, ensuring compliance programmes are properly tracked and evidenced Team Manage a team of GRC Consultants and Senior Consultants, growing from three to around seven people over the first three yearsProvide hands-on coaching during engagements and peer review of deliverablesSupport team members through professional certifications including ISO 27001 Lead Auditor, CIPP/E and BCS Data Protection PractitionerContribute to recruitment including interview involvement and onboarding of new hires Clients and Business Development Act as senior point of contact for retainer clients at MD, Finance Director and board levelIdentify opportunities to extend the scope of existing client relationships, whether that is moving from a one-off project to a retainer or broadening the range of frameworks coveredSupport the BD Manager in qualifying opportunities and providing technical input during proposalsWork with partners across the wider firm to develop referral opportunities from their existing client baseRepresent the practice at relevant sector events and industry forums

Requirements

A solid track record of delivering GRC services implementations from scoping through to certificationHands-on experience with DPIAs, data protection health checks and policy development under UK GDPRDirect client contact at board or senior leadership level, with the ability to present clearly and handle difficult questionsExperience managing or mentoring a small team of compliance or information security professionalsWorking knowledge of at least one of: NIS2, DORA, FCA PS21/3 operational resilience, the EU AI Act, or ISO 22301 business continuityA background in professional services or consultancy, with an understanding of how to run engagements commercially Qualifications (preferable)ISO 27001 Lead Auditor or Lead Implementer from an accredited body such as BSI, LRQA or CQIBCS Certificate in Data Protection, CIPP/E or an equivalent data protection qualificationISO 22301 Lead Implementer or a recognised business continuity qualificationCyber Essentials Assessor certified by an IASME or NCSC approved bodyISO 42001 AI Management Systems, which is increasingly relevant given the EU AI Act timelineA degree in law, computer science, business, information security or a related field Audit & Risk Recruitment

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on apply4u.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

3:46 min

Core terminology and audiences for interpretable artificial intelligence

Karol Przystalski · LIVE

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

6:17 min

Understanding AI risk tiers and compliance obligations

Jaap Kersten Jaap Kersten +1 · WWC 2024

3:21 min

Automating complete quality assurance pipelines with artificial intelligence

Evelyn Haslinger · LIVE

Videos

See all

Related articles

See all