GRC Specialist

Open 19d

Department: Security

Function: Governance, Risk, and Compliance (GRC)

Role Summary

Shufti is hiring a Governance, Risk, and Compliance (GRC) Specialist to operate and improve the governance layer of the security programme. This role keeps the ISMS governed, risk-informed, audit-ready, and aligned to certification, customer, and regulatory obligations. The successful candidate will own the day-to-day mechanics of policy governance, risk tracking, audit coordination, document control, evidence mapping, and cross-functional follow-through.

This is not a passive documentation role. The GRC Specialist is expected to convert security, audit, and compliance requirements into an operating model that teams can execute, evidence, review, and improve.

What The Role Owns

• ISO 27001:2022 governance and surveillance readiness

• SOC 2 evidence governance and control mapping

• PCI-DSS and Cyber Essentials Plus coordination

• Risk-register maintenance, treatment tracking, and acceptance workflow

• Policy, procedure, charter, and document-control lifecycle management

• Internal audit planning, evidence collation, and CAPA follow-up

• Supplier assurance coordination

• KPI, monitoring, and management-review preparation

• Event-driven governance for significant change, exceptions, audit findings, or privacy-impacting activity

Key Responsibilities

ISMS and Governance

• Maintain the ISMS governance model, charter, scope, control framework, and recurring review cadence.

• Keep the Information Security Objectives, management-review inputs, and governance records current and defensible.

• Ensure the compliance obligations tracker remains current for certification cycles, surveillance activity, and major customer commitments.

Policy, Procedure, and Document Control

• Draft, update, coordinate review, and route approval for policies, procedures, standards, and governance notes.

• Maintain document review dates, version accuracy, approval status, dissemination evidence, and archive hygiene.

• Ensure critical policies and governance documents are mapped correctly in the compliance system of record.

Risk Management

• Maintain the live risk position across the operational register and the authoritative enterprise risk view.

• Run or coordinate fortnightly operational risk reviews and ensure each material risk has an owner, treatment path, and current status.

• Escalate stale actions, unmanaged residual risk, ownerless items, or governance drift into management review or CAPA.

Audit, Evidence, and Corrective Action

• Coordinate internal and external audit preparation, evidence collation, management responses, and closure tracking.

• Maintain control-to-evidence mapping so operational teams know which artefacts are required and where they live.

• Track NCR, CAPA, audit findings, and remediation evidence through to verified closure.

Supplier and Cross-Functional Assurance

• Coordinate supplier due diligence, annual or high-risk supplier reviews, assurance report collection, and open remediation follow-up.

• Work closely with Security Operations, Infrastructure, Engineering, IAM, HR, Legal, Privacy, and leadership to keep governance records aligned to operational reality.

• Trigger governance review when major technical, organisational, supplier, or regulatory changes occur.

First 90 Days

1. Take ownership of the current GRC operating cadence.

2. Validate access and ownership across systems and evidence stores.

3. Reconcile open audit findings, CAPA items, and stale treatment actions.

4. Confirm the current state of the ISMS charter and governance inputs.

5. Improve evidence hygiene across repositories.

Required Experience

• Experience in information security GRC, security compliance, ISMS operations, audit coordination, or a closely related role.

• Practical working knowledge of ISO 27001.

• Experience maintaining risk registers, treatment plans, corrective-action trackers, or audit evidence packs.

• Experience managing policy or document-control workflows.

• Ability to work across technical and non-technical teams.

• Strong written communication and record-quality discipline.

Preferred Experience

• Experience with SOC 2 evidence management or multi-framework control mapping.

• Experience with certification surveillance cycles or auditor coordination.

• Experience with supplier due diligence and assurance reviews.

• Familiarity with privacy-support processes.

• Experience using compliance or workflow tooling such as Vanta, ClickUp, or Jira.

Core Competencies

• Structured thinking and strong follow-through

• Ability to distinguish policy intent from operational evidence

• Confidence in chasing owners, due dates, and unresolved actions

• Good judgment on escalation

• Accuracy with versioning, evidence linkage, and controlled records

• Comfort working with auditors, leadership, and operational teams

Success Profile

• Keep governance records current without waiting for audit pressure

• Maintain clean linkage between risks, controls, evidence, and remediation

• Ensure management reviews and recurring governance tasks happen on time

• Reduce confusion in shared repositories

• Make the compliance and audit posture easier to operate