×
Register Here to Apply for Jobs or Post Jobs. X

GRC Lead

Job in City of Edinburgh, Edinburgh, City of Edinburgh Area, EH1, Scotland, UK
Listing for: Wordsmith
Full Time position
Listed on 2026-09-21
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Project Manager
Salary/Wage Range or Industry Benchmark: 95000 - 140000 GBP Yearly GBP 95000.00 140000.00 YEAR
Job Description & How to Apply Below
Location: City of Edinburgh

GRC Lead Edinburgh Wordsmith

Wordsmith is building the AI-enabled command centre for in-house legal teams.

Our customers are some of the most demanding enterprise legal departments in the world, and they hold us to a high bar on security, privacy, and responsible AI.

We're looking for a senior leader to take ownership of security and compliance as we scale.

The Role

GRC Leads own security and compliance at Wordsmith end-to-end — setting the strategy for IT and infrastructure security, running our certification program across SOC 2, ISO 27001, and ISO 42001, embedding responsible-AI practices into how we build and ship product, and making sure privacy and regulatory obligations (GDPR and beyond) are handled properly as we grow.

This is a senior role that blends strategy and hands‑on execution. You'll set multi-year direction, represent Wordsmith's security posture to executives, customers, and — as we grow — the board, and build the team, tooling, and controls the company needs at the next stage, not just maintain what exists today.

What You'll Do Security Strategy & Leadership
  • Own Wordsmith's multi-year IT security and compliance roadmap — setting priorities, budget, and tooling decisions in partnership with Engineering and company leadership.
IT & Infrastructure Security
  • Own security architecture across corporate IT and infrastructure — identity & access management, endpoint protection, and cloud/network security — and lead incident response when issues arise.
Compliance & Certification
  • Own SOC 2 Type II, ISO 27001/27017/27018, and ISO 42001 end-to-end — policies, controls, audit evidence, and the audits themselves.
AI Governance
  • Run our AI governance program, including AI Impact Assessments and model/AI-vendor risk reviews, ensuring responsible, compliant AI use across the product.
Privacy Operations
  • Own privacy operations end-to-end — GDPR and other regulatory obligations, DPIAs, RoPA maintenance, sub‑processor management, and Data Subject Request fulfilment.
Third-Party & Vendor Risk
  • Assess vendors and AI tools for security, privacy, and AI risk before they're adopted, and put the right contractual safeguards in place at a program level.
Team & Function Building
  • Build the people, process, and tooling the function needs as it scales — starting as the senior owner of the program today, with a mandate to build out a team as Wordsmith grows.
Executive & Board Reporting
  • Own risk and compliance reporting to leadership and, as we scale, the board — translating technical risk into business terms.
Customer & Deal Support
  • Act as the senior voice on security for enterprise deals — security questionnaires, DPAs, and our Trust Center — partnering with Sales, Customer Success, and Legal to unblock deals without cutting corners.
Automation & Tooling
  • Build lean, automation-first tooling (e.g. Vanta) for evidence collection and ongoing compliance monitoring, so the program scales without scaling headcount unnecessarily.
What we're looking for Essential
  • 8-10+ years in security, IT, or compliance roles, including a track record of owning a security or compliance function end-to-end at a fast-growing SaaS or tech company.
  • Proven experience building or scaling a security/compliance program from an early stage — ideally including time as the sole or founding owner of the function.
  • Deep, hands‑on expertise across SOC 2, the ISO 27000 series, and ideally ISO 42001.
  • Strong grounding in core IT security fundamentals — identity & access management, endpoint/device security, and cloud or network infrastructure security.
  • Practical, working knowledge of GDPR and related privacy regulation (ePrivacy or similar).
  • Experience presenting security posture, risk, and roadmap to executives, boards, or investors.
  • Experience building and/or…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary