Lead GRC Consultant

Cathcart Technology

Easter Howgate

Hybrid

GBP 70,000 - 110,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Bonus
Share scheme

Job summary

Cathcart Technology in Edinburgh is seeking a Lead GRC Consultant to join its Information Security team. This senior role focuses on governance, risk and compliance, shaping the security framework across a global environment.

You’ll take ownership of ISO 27001, security risk assessments, third-party risk, audit and control effectiveness. There is an evolving focus on AI governance and GRC tooling like ServiceNow GRC/OneTrust, with a hybrid office pattern and a competitive package.

Qualifications

  • Senior GRC role focusing on ISO 27001, risk assessments and third-party risk.
  • Experience implementing and operating ISMS.
  • Strong analytical skills and ability to communicate risk to leadership.
  • Experience with enterprise GRC platforms such as ServiceNow GRC or OneTrust.

Responsibilities

  • Lead day-to-day operation and ongoing improvement of the organisation’s ISO 27001-aligned Information Security Management System.
  • Own and develop security policies, standards, controls and exception management processes.
  • Lead information security risk assessments across new technology, projects, services and business initiatives.
  • Assess the effectiveness of security controls and work with stakeholders to develop and track appropriate risk treatment plans.
  • Manage third-party security risk, including supplier assessments, due diligence, remediation and ongoing monitoring.
  • Support internal and external audits, customer security assessments and certification activities.
  • Analyze and communicate security risks clearly to both technical and non-technical stakeholders, including senior leadership.
  • Configure and continually improve GRC tooling, supporting risk registers, control libraries, assessments, exceptions and third-party workflows.
  • Work closely with teams around privacy, regulatory and data protection requirements.
  • Help develop the governance and security framework around the responsible use of AI, including GenAI and emerging agentic technologies.
  • Act as a trusted advisor to IT, Engineering, Security and business teams, making sure security requirements are practical and can be Embedded into the way teams operate.
  • Produce clear reporting, briefings and presentations for senior stakeholders and support wider security awareness activity.

Skills

GRC
ISO 27001
Risk management
Audit
Third-party risk
Stakeholder comms
GRC tooling

Tools

ServiceNow GRC
OneTrust

Job description

Lead GRC Consultant required to join a well established global technology company with a strong base in Edinburgh. This is a senior role within the Information Security team, focused on governance, risk and compliance, with responsibility for helping shape and continually improve the organisation's security framework across a global environment.

You’ll take ownership of key GRC areas, including ISO 27001, security risk assessments, third-party risk, audit and control effectiveness. There is also an interesting element around the governance and responsible use of AI, helping the business understand and manage the security and data risks that come with emerging technologies.

The Company:

This is a long standing and highly respected player in the tech space, known for developing technology used by some of the world's most recognised companies. While you won’t see their name in the spotlight, their work sits behind products used by millions of people around the world. With a reputation for engineering excellence and trusted partnerships at the highest levels, this business has quietly built a global footprint while keeping a down to earth, collaborative culture.

The Role:

This is a broad GRC role where you’ll have genuine ownership and influence across the Information Security function. You’ll be responsible for operating and improving the company’s ISO 27001-aligned security management framework, while working closely with IT, Security, Engineering and wider business teams to identify and manage risk.

A key part of the role will be assessing security risks around new systems, services and business initiatives, working with stakeholders to understand how controls are designed and whether they are operating effectively. You’ll also play a significant role in third-party risk, reviewing suppliers and service providers and ensuring any identified risks are properly understood and addressed.

There is an evolving focus on AI governance too. As the business continues to adopt AI technologies, you’ll help establish the security and risk framework around their use, including acceptable-use guidance, risk assessments and appropriate controls for new AI tools and services.

You’ll also have the opportunity to improve the way GRC is delivered through technology, with responsibility for administering and optimising enterprise GRC platforms such as ServiceNow GRC or OneTrust.

Key Responsibilities:
  • Lead the day-to-day operation and ongoing improvement of the organisation’s ISO 27001-aligned Information Security Management System.
  • Own and develop security policies, standards, controls and exception management processes.
  • Lead information security risk assessments across new technology, projects, services and business initiatives.
  • Assess the effectiveness of security controls and work with stakeholders to develop and track appropriate risk treatment plans.
  • Manage third-party security risk, including supplier assessments, due diligence, remediation and ongoing monitoring.
  • Support internal and external audits, customer security assessments and certification activities.
  • Analyse and communicate security risks clearly to both technical and non-technical stakeholders, including senior leadership.
  • Configure and continually improve GRC tooling, supporting risk registers, control libraries, assessments, exceptions and third-party workflows.
  • Work closely with teams around privacy, regulatory and data protection requirements.
  • Help develop the governance and security framework around the responsible use of AI, including GenAI and emerging agentic technologies.
  • Act as a trusted advisor to IT, Engineering, Security and business teams, making sure security requirements are practical and can be Embedded into the way teams operate.
  • Produce clear reporting, briefings and presentations for senior stakeholders and support wider security awareness activity.
Key Skills & Background:
  • Strong experience within Information Security, with a particular focus on GRC, risk management and/or security compliance.
  • Practical experience working with ISO 27001, including the ISMS life cycle, risk assessment, treatment and security controls.
  • Experience across both internal security risk assessments and third-party/vendor risk management.
  • Good technical understanding across areas such as cloud/SaaS, identity, networks, endpoints and security operations.
  • Experience using an enterprise GRC platform, ideally ServiceNow GRC, although experience with other platforms such as OneTrust will also be relevant.
  • Ability to work with technical and business stakeholders and translate security and compliance requirements into practical actions.
  • Strong analytical skills and the ability to assess risk in the context of wider business objectives.
  • Comfortable working independently, managing multiple priorities and taking ownership through to completion.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC or ISO 27001 Lead Implementer/Lead Auditor would be advantageous, but are not essential.

The company boasts one of the best offices in Edinburgh City Centre, offering a stunning, modern workspace that perfectly complements its dynamic and innovative culture. The office is equipped with great amenities, creating an environment that’s not only comfortable but also designed to inspire collaboration and creativity.

This is a hybrid role, with a minimum of two days per week in the Edinburgh office. On top of this, the company offers a very competitive salary and a great benefits package including bonus and share scheme.

This is an opportunity to join a global technology business where Information Security is an important part of how the organisation operates. You’ll have the scope to influence security governance at a global level, work closely with senior stakeholders and play a key role in how the business manages both established and emerging risks, particularly as AI adoption continues to develop.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead GRC Consultant
Lead GRC Consultant

Cathcart Technology • City of Edinburgh

Hybrid
GBP 90,000 - 130,000
Bonus
Share scheme
Senior Information Security Analyst
Senior Information Security Analyst

Cathcart Technology • City of Edinburgh

Hybrid
GBP 90,000 - 120,000
Bonus
Share scheme
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
IT GRC Senior Analyst
IT GRC Senior Analyst

Nigel Wright Recruitment • Newcastle upon Tyne

Hybrid
GBP 70,000 - 90,000
Hybrid work policy
Senior GRC Lead: ISO 27001, AI Governance & Risk
Senior GRC Lead: ISO 27001, AI Governance & Risk

Cathcart Technology • City of Edinburgh

Hybrid
GBP 90,000 - 130,000
Bonus
Share scheme
Lead Information Security Analyst, GRC
Lead Information Security Analyst, GRC

Cirrus Logic • City of Edinburgh

Hybrid
GBP 90,000 - 130,000
Hybrid work
Governance, Risk & Compliance Lead
Governance, Risk & Compliance Lead

Elevation Recruitment Group • Leeds

Hybrid
GBP 50,000 - 60,000
Car Allowance
Bonus
Benefits
Senior Information Security (GRC) Specialist
Senior Information Security (GRC) Specialist

La Fosse • Greater London

Hybrid
GBP 81,000 - 99,000
Pension
Benefits
Information Security Officer
Information Security Officer

TyneStack Ltd • Newcastle upon Tyne

Hybrid
GBP 45,000 - 70,000
Hybrid working
Exposure to ISO 27001/NIST in cloud
Regulated financial tech environment
Senior GRC Consultant – AI Governance & ISO 27001, Hybrid
Senior GRC Consultant – AI Governance & ISO 27001, Hybrid

Cathcart Technology • Easter Howgate

Hybrid
GBP 70,000 - 110,000
Bonus
Share scheme