×
Register Here to Apply for Jobs or Post Jobs. X

Principal GRC Consultant

Remote / Online - Candidates ideally in
Birmingham, West Midlands, B1, England, UK
Listing for: SCC
Remote/Work from Home position
Listed on 2026-09-04
Job specializations:
  • IT/Tech
    Cybersecurity, IT Consultant, IT Business Analyst
Job Description & How to Apply Below
About

The Role We are actively building diverse teams and welcome applications from everyone.

Role:
Principal GRC Consultant

Location:

Birmingham (SCC operate hybrid working, which comprises of a mix of office and home working)
Contract Type:
Permanent

Salary Package:

Competitive plus large company benefits, a broad flexible benefits scheme, and 2 paid-for volunteering days a year

Hours:

9.00 am – 5.30 pm Monday – Friday Interview Process: 2-stage process

Why SCC?

An inclusive workplace

Excellent package: solid basic and company benefits

Hybrid working & core hours in line with role requirements

Career development and life-long learning opportunities

Opportunity to join Europe's largest privately-owned IT Company Role purpose:

SCC is building a serious GRC consulting capability not a bolt-on, but a practice designed to last. We want someone who can shape it from the inside: influence how we work, who we hire, and what we stand for in the market.

The challenge is real. Clients are navigating rapidly evolving regulatory environments, boards that need cyber risk explained in business terms, and a threat landscape that AI is making harder to predict. Frameworks and controls matter but what clients actually need is someone who can think clearly under complexity and lead others to better decisions.

This is a principal-level role in the truest sense. The work is advisory, often ambiguous, and always consequential.

You will lead GRC engagements with clients across sectors — from initial scoping through to board-ready outputs. That means running risk assessments and maturity reviews, designing governance frameworks and control environments, supporting compliance programmes, and translating regulatory complexity into practical roadmaps.

You will also work alongside SCC's sales and architecture teams to shape opportunities and strengthen proposals. Over time, you will help define the practice itself: its methods, its talent, and how it grows.

The day-to-day will move between board-level risk discussions and detailed control planning. You need to be equally comfortable in both.

Key responsibilities:

1.
Help define and shape SCC’s GRC go-to-market strategy, including future service offerings, client propositions and delivery approach
2.
Lead GRC consulting engagements for clients across a range of sectors, ensuring high-quality outcomes and practical recommendations
3.
Act as a subject matter expert across recognised frameworks and standards such as ISO 27001, NIST, NCSC CAF and Defence Cyber Certification requirements
4.
Design and implement governance frameworks, policies, processes and controls that help clients manage cyber risk effectively
5.
Lead cyber risk assessments, maturity reviews and gap analyses, translating findings into clear improvement plans and business-aligned roadmaps
6.
Support compliance programmes, audit readiness activity and certification preparation for clients
7.
Provide expert input into bids, proposals, client presentations and solution design
8.
Help define the future growth and hiring strategy for the GRC capability, including mentoring and supporting future consultants
9.
Engage confidently with senior stakeholders, explaining cyber risk and compliance issues clearly, with relevance and actionable

Skills and experience:

1.
Strong experience in Governance, Risk and Compliance, ideally within cyber security, information security or technology risk
2.
Good working knowledge of recognised frameworks and standards such as ISO 27001, NIST, NCSC CAF, Cyber Essentials and related assurance or certification schemes
3.
Experience leading risk assessments, control reviews, audit preparation, compliance programmes or security maturity assessments
4.
Ability to advise senior stakeholders and translate technical or regulatory requirements into practical business actions
5.
Previous consulting, advisory or client-facing delivery experience would be highly beneficial
6.
Strong written and verbal communication skills, including the ability to produce clear reports, recommendations and executive-level briefings
7.
Confidence working at both strategic and practical levels, from board-level risk discussions through to detailed…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary