Information Security Governance, Risk and Compliance Specialist
Summary
The Information Security GRC Specialist will manage ISO 27001 certification, oversee vendor risk assessments, and maintain security policies within a SaaS and AI-focused environment. The role involves collaborating with internal teams to drive security awareness and managing the company's security trust portal.
Salary: £71,000 - 82,000 per year
Requirements:- We are looking for someone with in-depth, practical experience obtaining and maintaining ISO 27001 certification, with solid knowledge of frameworks such as NIST.
- We typically expect 3–5 years in an information security compliance role, though we will consider other experience levels.
- We need proven ability to develop and maintain security policies and procedures aligned with industry best practice.
- We are looking for experience conducting vendor security assessments and managing client security onboarding requirements while balancing risk against commercial objectives.
- We value hands-on experience building or maintaining a security trust portal, with familiarity with tools such as Drata or Vanta as a plus.
- We are looking for knowledge of SaaS and AI environments, including experience implementing and managing cloud security best practices.
- We need strong communication skills with the ability to translate complex GRC topics into clear internal guidance.
- We own and maintain our ISO 27001 certification and compliance across relevant security frameworks.
- We develop, implement, and maintain information security policies and procedures aligned with industry best practices.
- We lead vendor risk management and client security assessments, including responding to client security questionnaires and onboarding requirements.
- We build and maintain our security trust portal, showcasing our credentials to clients and stakeholders using tools such as Drata or Vanta.
- We drive security awareness across the business through training programmes and internal communications that promote a strong GRC culture.
- We work closely with our Legal, Information Security, Product, and Technology teams to strengthen our compliance posture and security-conscious culture.
- AI
- Cloud
- Support
- Security
More:
We are GWI, and we are looking for an Information Security GRC Specialist to join our Legal team in London. This is a permanent, mid-senior role with a hybrid working pattern of 2 days per week in the office. We offer meaningful work, visible impact, and a culture that empowers you to do your best. Our benefits include 25 days annual leave plus holiday office closures, health and wellbeing support, competitive salary, 4% pension matching, flexitime, early Friday finishes, hybrid and remote options, a work-from-home budget, accredited learning, leadership development, global career mobility, and a range of community and impact initiatives. We are a company that values thinking big, asking why, and showing respect, and we are committed to diversity, equity, inclusion, and belonging across our workplace.
last updated 34 week of 2026