Enable job alerts via email!

Information Security GRC Lead

Smarsh

London

On-site

GBP 70,000 - 90,000

Full time

Yesterday
Be an early applicant

Job summary

A digital communications firm is seeking a GRC Lead in London to manage security governance, risk management, and compliance operations. The role involves developing and maintaining security policies, overseeing control assurance programs, and engaging with various stakeholders. Candidates should have extensive experience in compliance roles within SaaS environments and possess strong communication skills. This strategic yet hands-on role requires collaboration across teams and time zones.

Benefits

Best Places to Work Awards
Opportunities for professional development
Diversity commitment

Qualifications

  • 7+ years’ experience in security governance, risk, or compliance roles within SaaS or regulated industries.
  • Proven ability to work across business, engineering, and legal teams to embed governance effectively.
  • Familiarity with regulatory landscapes such as ISO, SOC 2, GDPR.

Responsibilities

  • Lead the maintenance and improvement of Smarsh’s ISO-aligned ISMS.
  • Drive the risk assessment lifecycle and integrate risk metrics into dashboards.
  • Manage customer security assessments and ensure timely high-quality responses.

Skills

Security governance
Risk management
Compliance
Communication skills

Education

Professional certifications (CISA, CISM, ISO LA, CISSP, CRISC) preferred

Tools

GRC platforms

Job description

Social network you want to login/join with:

Who are we? Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 0 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in communication channels before those risks become regulatory fines or headlines. Relentless innovation has fueled our journey to consistent leadership recognition from analysts like Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 0 list of fastest-growing American companies since 8.

Summary Smarsh is committed to embedding security as a business enabler. As a senior member of the GRC team, you will be instrumental in ensuring that our security governance, risk, and compliance efforts are integrated, scalable, and proactive. The GRC Lead plays a cross-functional leadership role, supporting the Senior Manager, GRC, and taking ownership of key programmes that span our ISMS, controls assurance, risk management, third-party oversight, and regulatory compliance. You’ll engage with stakeholders across InfoSec, Legal, Product, Engineering, and Customer teams to operationalise governance and build trust.

This is a strategic yet hands-on role, ideal for someone who thrives in driving governance initiatives, facilitating risk discussions, and ensuring compliance readiness while working closely with Engineering, Security, and Product teams. You must be comfortable working as part of a global team in a dynamic, fast-paced environment. Collaboration across time zones and geographies is a key part of our culture and success.

How will you contribute?

  1. ISMS Governance & Controls Assurance
  2. Lead the maintenance and continuous improvement of Smarsh’s ISO-aligned ISMS.
  3. Oversee the control assurance programme, ensuring robust evidence collection, control testing, and continuous monitoring.
  4. Own key internal and external audit workstreams, including SOC 2, ISO, FedRAMP and customer audits.
  5. Cybersecurity Risk Management
  6. Drive the risk assessment lifecycle, embedding business, technical, and supply chain risk perspectives.
  7. Enhance risk methodologies and tools, integrating real-time risk metrics into dashboards and governance forums.
  8. Support risk acceptance processes and facilitate cross-functional remediation plans.
  9. Regulatory, Contractual & Client Assurance
  10. Monitor emerging regulations (DORA, SEC, UK AI Act) and translate them into actionable internal obligations.
  11. Manage customer security assessments and DDQs, enabling frictionless trust through reusable assurance artefacts.
  12. Coordinate timely, high-quality client responses and external assurance artefacts.
  13. Third-Party & Supply Chain Risk
  14. Lead third-party security reviews and ensure governance controls are extended across the vendor lifecycle.
  15. Partner with Procurement and Legal to align contractual security requirements and risk acceptance criteria.
  16. Policy Governance & Stakeholder Reporting
  17. Maintain the InfoSec policy lifecycle and track compliance across business units.
  18. Develop and maintain security governance metrics and reporting for the CISO and wider executive team.
  19. Support the operation of governance forums and steering committees.
  20. Security Awareness & Culture
  21. Deliver targeted security training and awareness campaigns aligned to regulatory and business needs.
  22. Promote a security-aware culture of governance accountability and enablement across teams.
  23. GRC Operations & Enablement
  24. Own and refine core GRC workflows, including documentation, issue tracking, evidence management, and status reporting.
  25. Maintain and expand GRC tooling integrations, ensuring high-quality automation and reporting outputs.

What will you bring?

  • 7– years’ experience in security governance, risk, or compliance roles within SaaS or regulated industries.
  • Strong track record operationalising ISMS frameworks, managing control assurance, and supporting external audits.
  • Hands-on experience with GRC platforms, security metrics reporting, and risk assessments.
  • Proven ability to work across business, engineering, and legal teams to embed governance effectively.
  • Familiarity with modern regulatory landscapes and frameworks such as ISO, SOC 2, GDPR, DORA, FedRAMP and SEC Cyber rules.
  • Strong communication skills, with the ability to create executive-level reporting and artifacts.
  • Experience leading client assurance programmes or third-party risk management.
  • Professional certifications (CISA, CISM, ISO LA, CISSP, CRISC) preferred.

About our culture

Smarsh hires lifelong learners with a passion for innovating with purpose, humility and humor. Collaboration is at the heart of everything we do. We work closely with the most popular communications platforms and the world’s leading cloud infrastructure platforms. We use the latest in AI/ML technology to help our customers break new ground at scale. We are a global organization that values diversity, and we believe that providing opportunities for everyone to be their authentic self is key to our success. Smarsh leadership, culture, and commitment to developing our people have all garnered Best Places to Work Awards. Come join us and find out what the best work of your career looks like.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.