Risk Management Officer

Propel

Greater London

Hybrid

GBP 90,000 - 120,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Market-leading compensation
Share options
Private healthcare
25 days holiday
Enhanced parental leave
L&D budget

Job summary

Propel is seeking a Security GRC Manager to own the security compliance programme end to end in a high-growth B2B SaaS environment. You will drive ISO 27001, SOC 1/2, HIPAA and future frameworks with a hands-on approach across controls, evidence and customer interactions.

London-based, Monday to Thursday in the office, you will coordinate audits, lead customer security reviews, build trust portals and translate compliance into commercial value while maturing security, privacy and risk across

Qualifications

  • 4+ years in GRC, security compliance, trust, audit, information security or related area.
  • Hands-on with frameworks such as SOC 2, ISO 27001, HIPAA or GDPR.
  • Experience supporting enterprise sales, procurement, RFPs or customer security reviews.
  • Experience using AI to improve GRC workflows, such as policy drafting or evidence management.

Responsibilities

  • Own the security compliance programme across ISO 27001, SOC 1, SOC 2, HIPAA and future frameworks
  • Run audit cycles throughout the year and coordinate external auditors and internal control owners
  • Own controls, evidence, policies, risk registers, access reviews, vendor reviews and business continuity processes
  • Lead customer-facing security reviews, questionnaires, RFPs and enterprise diligence
  • Build and maintain trust collateral, security portals and reusable questionnaire answer libraries
  • Work closely with Product and Engineering to translate compliance requirements into practical controls
  • Use AI to improve and automate areas such as policy drafting, evidence management and questionnaire responses
  • Help improve the maturity of security, privacy, risk and customer trust as the business moves further upmarket
  • Apply strong risk judgement and focus teams on meaningful security improvements rather than compliance theatre

Skills

GRC management
Security compliance
Audit coordination
Customer reviews
Policy drafting
Risk assessment
AI in GRC

Job description

I’m working with a high-growth B2B SaaS business that is building out its security and compliance function as it continues to scale into more demanding enterprise markets.

They’re looking for a Security GRC Manager to take ownership of the security compliance programme end to end, while also playing a key role in enterprise customer trust and security reviews.

This is a hands-on role rather than one focused purely on coordinating audits. You’ll own the operating rhythm across frameworks including ISO 27001, SOC 1, SOC 2 and HIPAA, keeping controls running, evidence organised, policies current, risks visible and audits moving throughout the year.

You’ll also work directly with enterprise customers across security reviews, questionnaires, procurement, RFPs and diligence, helping turn security and compliance into a commercial asset rather than a blocker.

This would suit someone who enjoys owning the detail as well as the bigger picture, can operate across multiple teams and is comfortable being hands‑on with controls, evidence and customer conversations.

What you’ll be doing
  • Own the security compliance programme across ISO 27001, SOC 1, SOC 2, HIPAA and future frameworks
  • Run audit cycles throughout the year and coordinate external auditors and internal control owners
  • Own controls, evidence, policies, risk registers, access reviews, vendor reviews and business continuity processes
  • Lead customer‑facing security reviews, questionnaires, RFPs and enterprise diligence
  • Build and maintain trust collateral, security portals and reusable questionnaire answer libraries
  • Work closely with Product and Engineering to translate compliance requirements into practical controls
  • Use AI to improve and automate areas such as policy drafting, evidence management and questionnaire responses
  • Help improve the maturity of security, privacy, risk and customer trust as the business moves further upmarket
  • Apply strong risk judgement and focus teams on meaningful security improvements rather than compliance theatre
What they’re looking for
  • 4+ years’ experience across GRC, security compliance, trust, audit, information security, privacy operations or a related area
  • Hands‑on experience with frameworks such as SOC 2, ISO 27001, SOC 1, HIPAA or GDPR
  • Experience supporting enterprise sales, procurement, RFPs or customer security reviews
  • Confidence leading customer conversations around security, privacy and risk
  • Experience using AI to improve GRC workflows, such as policy drafting, questionnaire responses or vendor reviews
  • Strong written communication and attention to detail
  • Good understanding of modern B2B SaaS environments, including cloud infrastructure, access management, vendors, product development and customer data
  • Strong risk judgement and the ability to prioritise what genuinely matters
  • Experience building or owning a trust centre, customer‑facing security portal or security questionnaire library
  • Comfortable working autonomously in a high‑growth environment where processes are still evolving

London | Monday to Thursday in the office

Market-leading compensation + share options + private healthcare + 25 days holiday + enhanced parental leave + L&D budget

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead GRC Consultant
Lead GRC Consultant

Cathcart Technology • City of Edinburgh

Hybrid
GBP 90,000 - 130,000
Bonus
Share scheme
Governance, Risk & Compliance Lead
Governance, Risk & Compliance Lead

Tria • Greater London, Manchester

Remote
GBP 90,000 - 120,000
20% Bonus
Car allowance
Private health
+1
Enterprise Security GRC Manager — Trust & Compliance Lead
Enterprise Security GRC Manager — Trust & Compliance Lead

Propel • Greater London

Hybrid
GBP 90,000 - 120,000
Market-leading compensation
Share options
Private healthcare
+3
Lead GRC Consultant
Lead GRC Consultant

Cathcart Technology • Easter Howgate

Hybrid
GBP 70,000 - 110,000
Bonus
Share scheme
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
GRC Security Specialist
GRC Security Specialist

Remote Worker LTD. • Greater London

Hybrid
GBP 70,000 - 100,000
Information Security & Compliance Lead
Information Security & Compliance Lead

Avanti Recruitment • United Kingdom

On-site
GBP 70,000 - 100,000
25 days' holiday
NEST pension
Perkbox benefits
+2
GRC Security Specialist
GRC Security Specialist

Abound • Greater London

On-site
GBP 90,000 - 130,000
Compliance & Assurance Lead
Compliance & Assurance Lead

SureCloud • Greater London

Hybrid
GBP 70,000 - 110,000
IT GRC Senior Analyst
IT GRC Senior Analyst

Nigel Wright Recruitment • Newcastle upon Tyne

Hybrid
GBP 70,000 - 90,000
Hybrid work policy