GRC Lead
Listed on 2026-09-21
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Project Manager
GRC Lead Edinburgh Wordsmith
Wordsmith is building the AI-enabled command centre for in-house legal teams.
Our customers are some of the most demanding enterprise legal departments in the world, and they hold us to a high bar on security, privacy, and responsible AI.
We're looking for a senior leader to take ownership of security and compliance as we scale.
The RoleGRC Leads own security and compliance at Wordsmith end-to-end — setting the strategy for IT and infrastructure security, running our certification program across SOC 2, ISO 27001, and ISO 42001, embedding responsible-AI practices into how we build and ship product, and making sure privacy and regulatory obligations (GDPR and beyond) are handled properly as we grow.
This is a senior role that blends strategy and hands‑on execution. You'll set multi-year direction, represent Wordsmith's security posture to executives, customers, and — as we grow — the board, and build the team, tooling, and controls the company needs at the next stage, not just maintain what exists today.
What You'll Do Security Strategy & Leadership- Own Wordsmith's multi-year IT security and compliance roadmap — setting priorities, budget, and tooling decisions in partnership with Engineering and company leadership.
- Own security architecture across corporate IT and infrastructure — identity & access management, endpoint protection, and cloud/network security — and lead incident response when issues arise.
- Own SOC 2 Type II, ISO 27001/27017/27018, and ISO 42001 end-to-end — policies, controls, audit evidence, and the audits themselves.
- Run our AI governance program, including AI Impact Assessments and model/AI-vendor risk reviews, ensuring responsible, compliant AI use across the product.
- Own privacy operations end-to-end — GDPR and other regulatory obligations, DPIAs, RoPA maintenance, sub‑processor management, and Data Subject Request fulfilment.
- Assess vendors and AI tools for security, privacy, and AI risk before they're adopted, and put the right contractual safeguards in place at a program level.
- Build the people, process, and tooling the function needs as it scales — starting as the senior owner of the program today, with a mandate to build out a team as Wordsmith grows.
- Own risk and compliance reporting to leadership and, as we scale, the board — translating technical risk into business terms.
- Act as the senior voice on security for enterprise deals — security questionnaires, DPAs, and our Trust Center — partnering with Sales, Customer Success, and Legal to unblock deals without cutting corners.
- Build lean, automation-first tooling (e.g. Vanta) for evidence collection and ongoing compliance monitoring, so the program scales without scaling headcount unnecessarily.
- 8-10+ years in security, IT, or compliance roles, including a track record of owning a security or compliance function end-to-end at a fast-growing SaaS or tech company.
- Proven experience building or scaling a security/compliance program from an early stage — ideally including time as the sole or founding owner of the function.
- Deep, hands‑on expertise across SOC 2, the ISO 27000 series, and ideally ISO 42001.
- Strong grounding in core IT security fundamentals — identity & access management, endpoint/device security, and cloud or network infrastructure security.
- Practical, working knowledge of GDPR and related privacy regulation (ePrivacy or similar).
- Experience presenting security posture, risk, and roadmap to executives, boards, or investors.
- Experience building and/or…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).