Information Security Governance, Risk and Compliance Specialist

Summary

The Information Security GRC Specialist will manage ISO 27001 certification, oversee vendor risk assessments, and maintain security policies within a SaaS and AI-focused environment. The role involves collaborating with internal teams to drive security awareness and managing the company's security trust portal.

Salary: £71,000 - 82,000 per year

Requirements:
  • We are looking for someone with in-depth, practical experience obtaining and maintaining ISO 27001 certification, with solid knowledge of frameworks such as NIST.
  • We typically expect 3–5 years in an information security compliance role, though we will consider other experience levels.
  • We need proven ability to develop and maintain security policies and procedures aligned with industry best practice.
  • We are looking for experience conducting vendor security assessments and managing client security onboarding requirements while balancing risk against commercial objectives.
  • We value hands-on experience building or maintaining a security trust portal, with familiarity with tools such as Drata or Vanta as a plus.
  • We are looking for knowledge of SaaS and AI environments, including experience implementing and managing cloud security best practices.
  • We need strong communication skills with the ability to translate complex GRC topics into clear internal guidance.
Responsibilities:
  • We own and maintain our ISO 27001 certification and compliance across relevant security frameworks.
  • We develop, implement, and maintain information security policies and procedures aligned with industry best practices.
  • We lead vendor risk management and client security assessments, including responding to client security questionnaires and onboarding requirements.
  • We build and maintain our security trust portal, showcasing our credentials to clients and stakeholders using tools such as Drata or Vanta.
  • We drive security awareness across the business through training programmes and internal communications that promote a strong GRC culture.
  • We work closely with our Legal, Information Security, Product, and Technology teams to strengthen our compliance posture and security-conscious culture.
Technologies:
  • AI
  • Cloud
  • Support
  • Security

More:

We are GWI, and we are looking for an Information Security GRC Specialist to join our Legal team in London. This is a permanent, mid-senior role with a hybrid working pattern of 2 days per week in the office. We offer meaningful work, visible impact, and a culture that empowers you to do your best. Our benefits include 25 days annual leave plus holiday office closures, health and wellbeing support, competitive salary, 4% pension matching, flexitime, early Friday finishes, hybrid and remote options, a work-from-home budget, accredited learning, leadership development, global career mobility, and a range of community and impact initiatives. We are a company that values thinking big, asking why, and showing respect, and we are committed to diversity, equity, inclusion, and belonging across our workplace.

last updated 34 week of 2026

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available