GRC Consultant
Listed on 2026-08-08
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst
GRC Consultant (Governance, Risk & Compliance)
Contract | 3 Months | Remote | 3 Days per Week | £500–£600 per day
Build a compliance function from the ground up.
We're partnering with an ambitious software business that's experiencing significant growth and preparing to onboard several major enterprise clients. With that growth comes increasing scrutiny around governance, security and compliance and they're looking for an experienced GRC Consultant to build a scalable compliance framework that will support the business for years to come.
This isn't a box-ticking exercise.
You'll be embedded within the team, working closely with senior stakeholders to understand the business, identify gaps, implement best practices, and create a pragmatic compliance function that actually works.
Following the initial engagement, there's a strong opportunity to continue supporting the business on a retained, long‑term basis.
What you'll be doingYou'll take ownership of the company's Governance, Risk & Compliance capability, including:
- Reviewing the current compliance landscape and identifying gaps
- Building a practical compliance framework across the business
- Leading PCI DSS compliance initiatives
- Developing and improving GDPR processes and documentation
- Supporting security standards such as ISO 27001, SOC 2 and/or Cyber Essentials
- Creating policies, procedures and governance documentation
- Building and maintaining risk registers
- Preparing the business for future audits and assessments
- Managing client security questionnaires and compliance requests
- Tracking ongoing compliance requirements, renewals and evidence
- Coordinating external security assessments and penetration testing where required
- Advising leadership on evolving compliance and regulatory requirements
We're looking for someone who has genuinely done this before.
You'll be comfortable coming into a growing technology business, understanding what exists today and creating a practical roadmap to get everything where it needs to be.
Ideally you'll have experience with:- Governance, Risk & Compliance (GRC)
- PCI DSS
- GDPR
- ISO 27001, SOC 2 and/or Cyber Essentials
- Security governance and audit preparation
- Policy creation and documentation
- Risk management frameworks
- Working independently with multiple stakeholders
- Supporting SaaS or technology businesses
- Experience with Point of Sale (POS) compliance
- Knowledge of French compliance or regulatory requirements
- Experience supporting businesses operating across multiple European markets
This client could engage a consultancy.
Instead, they want an experienced independent consultant who'll become part of the team, build relationships with stakeholders and leave behind a compliance framework that scales with the business.
If you enjoy taking ownership, solving problems and making a visible impact, this is the kind of engagement where you'll genuinely shape how a company approaches governance and compliance.
The DetailsContract:
Initial 3-month engagement
Commitment:
Approximately 3 days per week
Rate: £500–£600 per day
Location:
Hybrid/Remote
Start: ASAP
Potential for ongoing retained work following the initial project
If you're an experienced GRC Consultant looking for a contract where you can make a genuine impact - not simply maintain existing processes - we'd love to hear from you.
#J-18808-LjbffrTo Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: