GRC Specialist

EuropeFull-timePosted May 13, 2026
Back to all rolesGRC SpecialistApplyJob detailsDepartment / Human ResourcesEuropeFull-timeDepartment: SecurityFunction: Governance, Risk, and Compliance (GRC)Role SummaryShufti is hiring a Governance, Risk, and Compliance (GRC) Specialist to operate and improve the governance layer of the security programme. This role keeps the ISMS governed, risk-informed, audit-ready, and aligned to certification, customer, and regulatory obligations. The successful candidate will own the day-to-day mechanics of policy governance, risk tracking, audit coordination, document control, evidence mapping, and cross-functional follow-through.This is not a passive documentation role. The GRC Specialist is expected to convert security, audit, and compliance requirements into an operating model that teams can execute, evidence, review, and improve.What The Role Owns• ISO 27001:2022 governance and surveillance readiness• SOC 2 evidence governance and control mapping• PCI-DSS and Cyber Essentials Plus coordination• Risk-register maintenance, treatment tracking, and acceptance workflow• Policy, procedure, charter, and document-control lifecycle management• Internal audit planning, evidence collation, and CAPA follow-up• Supplier assurance coordination• KPI, monitoring, and management-review preparation• Event-driven governance for significant change, exceptions, audit findings, or privacy-impacting activityKey ResponsibilitiesISMS and Governance• Maintain the ISMS governance model, charter, scope, control framework, and recurring review cadence.• Keep the Information Security Objectives, management-review inputs, and governance records current and defensible.• Ensure the compliance obligations tracker remains current for certification cycles, surveillance activity, and major customer commitments.Policy, Procedure, and Document Control• Draft, update, coordinate review, and route approval for policies, procedures, standards, and governance notes.• Maintain document review dates, version accuracy, approval status, dissemination evidence, and archive hygiene.• Ensure critical policies and governance documents are mapped correctly in the compliance system of record.Risk Management• Maintain the live risk position across the operational register and the authoritative enterprise risk view.• Run or coordinate fortnightly operational risk reviews and ensure each material risk has an owner, treatment path, and current status.• Escalate stale actions, unmanaged residual risk, ownerless items, or governance drift into management review or CAPA.Audit, Evidence, and Corrective Action• Coordinate internal and external audit preparation, evidence collation, management responses, and closure tracking.• Maintain control-to-evidence mapping so operational teams know which artefacts are required and where they live.• Track NCR, CAPA, audit findings, and remediation evidence through to verified closure.Supplier and Cross-Functional Assurance• Coordinate supplier due diligence, annual or high-risk supplier reviews, assurance report collection, and open remediation follow-up.• Work closely with Security Operations, Infrastructure, Engineering, IAM, HR, Legal, Privacy, and leadership to keep governance records aligned to operational reality.• Trigger governance review when major technical, organisational, supplier, or regulatory changes occur.First 90 Days1. Take ownership of the current GRC operating cadence.2. Validate access and ownership across systems and evidence stores.3. Reconcile open audit findings, CAPA items, and stale treatment actions.4. Confirm the current state of the ISMS charter and governance inputs.5. Improve evidence hygiene across repositories.Required Experience• Experience in information security GRC, security compliance, ISMS operations, audit coordination, or a closely related role.• Practical working knowledge of ISO 27001.• Experience maintaining risk registers, treatment plans, corrective-action trackers, or audit evidence packs.• Experience...

Want jobs like this matched to you?

Swoopd scores fresh postings against your résumé so you only see the matches that matter.

Get started free