- Company Name
- Phoenix Software
- Job Title
- Governance, Risk & Compliance Consultant
- Job Description
-
Job title: Governance, Risk & Compliance Consultant
Role Summary:
Deliver end‑to‑end GRC consulting across public and corporate sectors, including security maturing, cyber‑security strategy, ISO implementation, AI governance, third‑party risk, incident response, disaster recovery and business continuity. Engage customers through workshops, assessments, reporting and tabletop exercises.
Expectations:
- Provide tailored GRC solutions that meet client needs and regulatory requirements.
- Maintain high‑quality documentation and deliverables within agreed deadlines.
- Build trust with technical and non‑technical stakeholders to secure repeat engagements.
- Demonstrate commercial awareness and contribute to business development.
Key Responsibilities:
- Scoping and scoping‑based identification of GRC opportunities with practice leads and business developers.
- Conduct security/maturity assessments and gap analyses for ISO27001, ISO22301, ISO42001, CIS, Cyber Essentials.
- Develop and implement cyber‑security strategies and incident response plans (CSIRPs) including tabletop exercises.
- Facilitate AI governance workshops and third‑party risk management sessions.
- Prepare Business Impact Assessments, Disaster Recovery and Business Continuity Plans.
- Create executive‑level reports, findings, and implementation roadmaps.
- Support internal business functions on GRC initiatives.
Required Skills:
- Proven track record delivering GRC consultancy across diverse customers.
- Deep knowledge of ISO standards (27001, 22301, 42001), CIS Controls, Cyber Essentials.
- Experience crafting CSIRPs, incident response documentation, and conducting tabletop exercises.
- Strong written and verbal communication, translating technical content to non‑technical audiences.
- Ability to manage multiple projects, meet deadlines, and produce high‑quality documentation.
- Customer‑facing aptitude, building rapport, and delivering outstanding outcomes.
- Commercial awareness and ability to identify new GRC opportunities.
Required Education & Certifications:
- Bachelor’s degree in Information Security, Business, IT, or related field (preferred).
- Relevant industry certifications (e.g., CISSP, CISM, ISO Lead Auditor, ISO 27001 Lead Implementer) are highly desirable.
- BPSS security clearance required; additional clearance may apply.
---