> Markdown version of [/jobs/ext/348298-grc-specialist](https://www.wearedevelopers.com/jobs/ext/348298-grc-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Specialist - **Company:** Grc - **Location:** UK - **Salary:** £80,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cyber Security - **Published:** June 19, 2026 - **Apply:** https://www.nemoresourcing.co.uk/grc ## About the Role + Experience in Governance, Risk & Compliance, Information Security, Audit or Risk Management + Experience of conducting audits, compliance reviews, governance assessments + Good knowledge of Cyber Essentials/Plus, GDPR, Data Protection + Experience presenting to senior stakeholders + Excellent communication skills + Strong commercial awareness, with the potential to progress into a leadership role + A passion for helping organisations with their governance, security and resilience. If you have any of the following, that would be a bonus: - + ISO 27001 Lead Auditor or Lead Implementer + CISSP, CRISC, CISM, CISMP or equivalent + Experience of delivering vCISO services + Knowledge of NIST CSF, CAF, DSPT + Knowledge of Microsoft 365 security and compliance tools + Experience in an MSP environment ## Description Currently, this role is effectively undertaken by the CEO, CTO and Head of Sales. The first twelve months in the role will focus on assuming an increasing amount of responsibility for GRC consulting activities from these three. This will be a very supportive process, engaging mainly with long-standing clients and ensuring that the positioning of GRC services, or delivery of GRC assignments, is well aligned to the company's established ways of working and dovetails well with existing relationships., + Client Compliance & Governance engagements including Compliance as a Service + Conduct governance reviews, maturity assessments, compliance audits + Develop & maintain client risk registers, remediation plans, governance frameworks + Produce governance roadmaps + Lead compliance workshops + Virtual CISO services + Develop client cyber security & governance strategies + Board-level security & risk reporting + Risk Management, Supplier Assurance & third-party risk assessment & mitigation + Lead client Operational Resilience, Business Continuity and Disaster Recovery programmes + Provide expert advice on compliance frameworks & regulatory issues + Develop and advise on AI governance frameworks + Work closely with internal technical team to align compliance requirements with security controls + Work closely with the sales team to support the sale of CaaS service to new and existing clients + Take lead role in supporting internal governance. Ultimately, as incoming Head of GRC, the following responsibilities will be added: - + Establish GRC practice including fully implemented governance and compliance roadmap + Grow Compliance revenue in line with agreed targets + Increase CaaS adoption amongst client base + Increase compliance maturity among client base + Maintain and improve certification levels + Develop new governance and compliance services + Develop and deliver relevant GRC thought-leadership content + Develop multi-year roadmap for GRC business + Own the performance, development and direction of the GRC practice + Support the recruitment of required resources as the practice expands GRC Specialist - moving to Head of GRC - requirements The fundamental requirements are as follows. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Fake or News: Translating Dog Barks, Notepad Gets an Upgrade and Michelin-Star Robots - Paul Tregoing](https://www.wearedevelopers.com/videos/1802-fake-or-news-translating-dog-barks-notepad-gets-an-upgrade-and-michelin-star-robots-paul-tregoing) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [How Lufthansa Industry Solutions is preparing for the Quantum Age! ](https://www.wearedevelopers.com/videos/1443-how-lufthansa-industry-solutions-is-preparing-for-the-quantum-age) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)