- Company Name
- Techary
- Job Title
- GRC Officer
- Job Description
-
Job title: GRC Officer
Role Summary:
Proactively strengthen the organization’s Information Security posture by managing, improving, and maintaining governance, risk, and compliance (GRC) processes. Lead the lifecycle of certifications, policy development, internal and external audits, and provide compliance support to customers.
Expectations:
- Own end‑to‑end GRC deliverables, ensuring timely completion, evidence management, and continuous improvement.
- Serve as the subject matter expert for cyber security standards and certification frameworks.
Key Responsibilities:
- Maintain and mature existing certifications (Cyber Essentials, Cyber Essentials Plus, ISO27001:2022) and pursue future accreditations (ISO9001, ISO42001, etc.).
- Draft, review, update, and version‑control internal policies, procedures, standards, and documentation.
- Schedule, track, and document operational compliance tasks: restoration tests, internal audits, risk reviews, access reviews, training audits.
- Manage risk registers, compliance metrics, evidence repositories, and audit workflows.
- Coordinate and prepare for internal and external audits, including evidence collection and remediation tracking.
- Monitor regulatory and industry changes to keep controls aligned with evolving standards.
- Consult customers on compliance implementation, policy creation, gap assessments, readiness planning, and best‑practice guidance.
- Support the Information Security team in risk identification, monitoring, and reporting.
- Assist vendor risk assessments and third‑party due diligence.
- Track corrective actions, deviations, and continuous improvements.
Required Skills:
- Proven experience in GRC, Information Security, Compliance, or Audit.
- In‑depth knowledge of Cyber Essentials, Cyber Essentials Plus, ISO27001, and familiarity with ISO9001 or other industry standards.
- Strong governance documentation skills (policies, processes, standards, evidence).
- Excellent organisational, prioritisation, and cross‑departmental coordination abilities.
- Clear communication skills for both technical and non‑technical stakeholders.
- Detail‑oriented with high organisational competence.
Required Education & Certifications:
- Minimum of a bachelor’s degree in Information Security, Risk Management, Business, or related field.
- Relevant certifications preferred: ISO27001 Lead Implementer/Auditor, CompTIA Security+, GRC‑specific certifications, or equivalent.
Orpington, United kingdom
Hybrid
01-01-2026