Governance, Risk & Compliance Consultant

Cyber Fraud Centre

Glasgow

On-site

GBP 50,000 - 75,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Personalised Career Development
Flexible working arrangements
Generous annual leave allowance
Private health insurance

Job summary

Cyber Fraud Centre is seeking a GRC Consultant to advise clients on governance, risk management, and regulatory compliance with a focus on UK-specific requirements. Responsibilities include leading GRC assessments, designing frameworks, and supporting compliance activities across various sectors. Applicants should possess strong experience in GRC roles, particularly within the UK Oil & Gas and financial sectors, and relevant certifications such as ISO 27001. Offered benefits include career development, flexible working arrangements, and a comprehensive package covering health and well-being.

Qualifications

  • Proven experience in Governance, Risk and Compliance roles within regulated environments.
  • Strong understanding of the UK Oil & Gas regulatory landscape.
  • Experience conducting risk assessments and assurance activities.

Responsibilities

  • Lead or support GRC maturity assessments, gap analyses and audits.
  • Design and implement GRC frameworks across risk management and governance.
  • Develop and maintain risk registers, control libraries and assurance plans.

Skills

Governance, Risk and Compliance experience
ISO/IEC 27001 knowledge
Strong written communication skills
Stakeholder engagement

Education

ISO 27001 Lead Implementer / Lead Auditor certification
CISM, CRISC or CISSP certification

Tools

OneTrust
Archer

Job description

As a GRC Consultant, you will advise and support our clients across governance, risk management and regulatory compliance. The role focuses on aligning cyber, information security, operational resilience and wider risk frameworks to UK‑specific regulatory, safety and operational requirements.

You will work closely with client stakeholders to assess maturity, design and implement control frameworks, and provide pragmatic, risk‑based guidance that supports safe, secure and resilient operations.

Deliver governance, risk and compliance consulting engagements for a variety of clients and industries, including UK Oil & Gas (operators, service companies and joint ventures). CNI, Finance and Public Sector

Responsibilities
  • Lead or support GRC maturity assessments, gap analyses and audits against relevant standards and regulations
  • Interpret and apply UK specific regulatory requirements, translating them into practical, implementable controls
  • Design and implement GRC frameworks covering risk management, policy, assurance and reporting
  • Support compliance activities aligned to various regulations and assurance requirements
  • Develop and maintain risk registers, control libraries and assurance plans
  • Facilitate risk workshops, control reviews and senior stakeholder briefings
  • Support cyber and information security governance aligned to ISO 27001, NCSC guidance and sector best practice
  • Provide advisory input into operational resilience, business continuity and third party risk management
  • Produce clear, evidence based client deliverables including reports, executive summaries and remediation roadmaps
  • Support pre audit, regulatory inspection and client assurance activities
Essential
  • Good experience and background of producing high quality documentation and solution artefacts
  • Proven experience in Governance, Risk and Compliance roles within regulated or critical infrastructure environments
  • Strong understanding of the UK Oil & Gas and finance regulatory landscape
  • Working knowledge of key frameworks and standards, such as:
    • ISO/IEC 27001
    • ISO 22301 (Business Continuity)
    • UK NIS Regulations and NCSC guidance
    • NIST CSF
    • UK GDPR
    • Data Protection Act
    • DORA
  • Experience conducting risk assessments, control gap analyses and assurance activities
  • Proven ability to drive adoption, stakeholder buy-in and embedding change
  • Strong background in end‑end to delivery (from design to implementation and embedding)
  • Ability to engage confidently with technical, operational and executive stakeholders
  • Strong written communication skills with experience producing client facing reports
  • Strong ability to translate technical and GRC concepts into clear, business-friendly language
  • Experience working in consulting or advisory environments
Desirable / Valuable
  • Knowledge of:
    • IEC 62443 for OT/ICS security
    • Operational Technology (OT) and industrial control environments
  • Familiarity with NCSC Cyber Assessment Framework (CAF) or sector‑specific assurance models
  • Experience supporting regulatory audits (HSE, NIS competent authority, client audits)
Certifications such as
  • ISO 27001 Lead Implementer / Lead Auditor
  • CISM, CRISC or CISSP
  • IRM or ISO risk management qualifications
  • Understanding of supply‑chain and third‑party risk in Oil & Gas, CNI and finance ecosystems
  • Familiarity with GRC tooling such as OneTrust or Archer
  • Ability to contribute to business development or service offering development

At Sword, we offer comprehensive benefits designed to support your professional development and enhance your overall quality of life. In addition to a Competitive Salary, here's what you can expect as part of our benefits package:

  • Personalised Career Development: We create a development plan customised to your goals and aspirations, with a range of learning and development opportunities within a culture that encourages growth.
  • Flexible working: Flexible work arrangements to support your work-life balance. We can’t promise to always be able to meet every request, however, are keen to discuss your individual preferences to make it work where we can.
  • A Fantastic Benefits Package: This includes generous annual leave allowance, enhanced family friendly benefits, pension scheme, access to private health, well-being, and insurance schemes.

At Sword we are dedicated to fostering a diverse and inclusive workplace and are proud to be an equal opportunities employer, ensuring that all applicants receive fair and equal consideration for employment, regardless of whether they meet every requirement. If you don’t tick all the boxes but feel you have some of the relevant skills and experience we’re looking for, please do consider applying and highlight your transferable skills and experience. We embrace diversity in all its forms, valuing individuals regardless of age, disability, gender identity or reassignment, marital or civil partner status, pregnancy or maternity status, race, colour, nationality, ethnic or national origin, religion or belief, sex, or sexual orientation. Your perspective and potential are important to us.

If we can do anything to help make the hiring process more accessible, please let our talent acquisition team know when you apply so we can support any adjustments.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst (Security Governance & Configuration)
GRC Analyst (Security Governance & Configuration)

Sword Group • Aberdeen City

On-site
GBP 40,000 - 60,000
Personalised Career Development
Flexible working arrangements
Generous annual leave allowance
Principal GRC Consultant
Principal GRC Consultant

SCC • Birmingham

On-site
GBP 85,000 - 120,000
Hybrid working
2 volunteering days a year
Career development
GRC Consultant: Risk, Compliance & Cyber for UK Regs
GRC Consultant: Risk, Compliance & Cyber for UK Regs

Cyber Fraud Centre • Glasgow

On-site
GBP 50,000 - 75,000
Personalised Career Development
Flexible working arrangements
Generous annual leave allowance
+1
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
Information Technology Governance Manager
Information Technology Governance Manager

Electus Recruitment Solutions • Shrivenham

On-site
GBP 80,000 - 110,000
Governance Risk and Compliance (GRC) Analyst
Governance Risk and Compliance (GRC) Analyst

Assured Data Protection Inc. • Leeds

Hybrid
GBP 50,000 - 65,000
Hybrid working options
Regular team-building events
Dynamic, inclusive work environment
+1
Information Security & Data Governance Lead (UK)
Information Security & Data Governance Lead (UK)

SES Energy • Aberdeen City

On-site
GBP 90,000 - 120,000
Senior GRC / Security Assurance Officer
Senior GRC / Security Assurance Officer

Rowden • West of England

Hybrid
GBP 60,000 - 80,000
GRC Manager
GRC Manager

Hamilton Barnes ? • Swindon

On-site
GBP 45,000 - 48,000
Cyber Governance Specialist - Ref 2863 UK Aberdeen
Cyber Governance Specialist - Ref 2863 UK Aberdeen

Prosource • Aberdeen City

Hybrid
GBP 60,000 - 90,000
Company pension
Private medical insurance
Dental insurance
+3