Enable job alerts via email!

Security GRC Specialist

Employment Hero

United Kingdom

Remote

GBP 40,000 - 80,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An innovative firm is seeking a Security GRC Specialist to enhance its information security management strategy. This role involves developing a comprehensive security strategy, maintaining compliance with industry standards, and collaborating with various teams to implement effective security measures. The company promotes a remote-first culture, offering flexibility and autonomy in your work. With a commitment to continuous improvement and cutting-edge tools, this position is perfect for those passionate about cybersecurity and eager to make a significant impact in a fast-growing tech environment. Join a team that values diverse perspectives and fosters professional growth.

Benefits

Employee Share Options
Generous Paternity Leave Policy
Subsidised Egg Freezing
Work From Home Office Expense Budget
Outstanding Learning & Development Opportunities

Qualifications

  • Degree in IT or equivalent experience required.
  • CISSP, CISM, or CISA certifications highly desirable.
  • Knowledge of ISO 27001, SOC2, NIST frameworks essential.

Responsibilities

  • Develop and execute information security strategy aligned with company objectives.
  • Write and maintain security policies ensuring compliance.
  • Conduct internal audits and provide recommendations based on findings.

Skills

Information Security Management
Cybersecurity Threat Mitigation
Compliance Frameworks (ISO27001, SOC2)
Risk Management
Excellent Written and Oral Communication
Continuous Improvement
Consultative Skills
Attention to Detail
Learning and Development

Education

Degree in Information Technology
Industry Certifications (CISSP, CISM, CISA)

Tools

Governance, Risk and Compliance (GRC) Tools

Job description

Who We Are

Employment Hero is on a mission to make employment easier and more valuable for everyone. Our Employment Operating System brings hiring, HR, payroll and benefits into an all-in-one solution.

Since our inception in 2014, we've scaled to a $2 billion valuation and gained a presence in 6 countries globally - Australia, New Zealand, Singapore, Malaysia, the UK and Canada. We now service over 300,000 businesses and more than 2 million employees.

The EH Way

At Employment Hero, we're proud of our unique DNA, which we call The EH Way.

  • We are Mission First - everything we do (from what we work on, to how we allocate capital and where we focus) is driven by our Mission
  • We are Remote First - we champion a remote environment with a preference for asynchronous communication and a high degree of autonomy
  • We are AI First - we are committed to using AI to accelerate our mission; AI is not just a tool, it's a fundamental part of how we operate, innovate, and scale
  • We are Apolitical - we do not take a position on political or social topics, unless it relates to our Mission
  • We Live by Our Values - we role model our values 100% of the time
  • We Expect High Performance - we set a high standard and we're not satisfied with being average
This role

As our Security GRC Specialist, you'll be working with the Global Security GRC Team and will be instrumental in shaping the information security management strategy for Employment Hero.

Your key focus areas will be:
  • Operate the information security management system across Employment Hero
  • Develop and execute a holistic information security strategy that aligns with the company's objectives and effectively mitigates cyber threats
  • Write and maintain information security policies to ensure compliance and the protection of sensitive data
  • Support the improvement and management of our cyber security capabilities
  • Stay up to date with the latest cybersecurity threats, trends, and technologies, and proactively recommend enhancements to the company's security posture
  • Collaborate with internal stakeholders, including IT, product, legal, and engineering teams, to identify security requirements and implement appropriate controls and safeguards
  • Respond to compliance audit requests and demonstrate a strong understanding of compliance frameworks and regulations such as ISO27001, SOC2
  • Conduct internal audits and provide recommendations to key stakeholders based on findings
  • Implement and maintain security tools and systems to ensure optimal performance and address evolving threats
Who you are

To thrive at Employment Hero, you'll need to embody The EH Way - operating with focus, agility, and an obsession with impact. For this role, you'll also bring:
  • A degree in information technology, information security, risk management, or equivalent work experience
  • Industry certifications such as CISSP, CISM or CISA are highly desirable
  • Demonstrated knowledge and understanding of contemporary frameworks and methodologies, such as ISO 27001, SOC2, NIST 800-53, NIST Cyber Security Framework (CSF), and Australian Information Security Manual (ISM)
  • Excellent written, oral, and influencing skills with the ability to work autonomously
  • A strong focus on continuous improvement, with a proven ability to challenge the status quo constructively
  • Broad knowledge of current Governance, Risk and Compliance (GRC) technological tools and methodologies
  • Strong consultative skills, enabling effective communication of complex concepts to both technical and non-technical audiences
  • Meticulous attention to detail
  • A strong desire to learn and expand knowledge in the field of information security
What we can offer

At Employment Hero, we don't just talk about a better way to work - we live it. Joining Employment Hero means:
  • You will work remotely, with the flexibility to own your time and impact
  • You will access cutting-edge tools to amplify your work, knowledge and outputs
  • You'll surround yourself with ambitious, outcome-driven colleagues who challenge you to do the best work of your life
  • You'll own ESOP (employee share options) in one of the world's fastest-growing tech companies
  • You'll also have access to a wide range of benefits that includes a very generous paternity leave policy, subsidised egg freezing (so you can make the choice that's right for you, on your terms), a WFH office expense budget, and outstanding learning & development opportunities

At Employment Hero, we are committed to safeguarding the privacy of your application data. To understand how we do so, you can read our Applicant Privacy Policy here: https://employmenthero.com/legals/applicant-privacy-policy/

Employment Hero celebrates diverse perspectives and experiences, we invite people of all backgrounds and identities to apply for this position.

Seniority level
  • Associate
Employment type
  • Full-time
Job function
  • Information Technology
  • Industries
  • Technology, Information and Internet
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Information Security GRC Specialist

JR United Kingdom

Greater London

On-site

GBP 55,000 - 65,000

3 days ago
Be an early applicant

Information Security GRC Specialist

JR United Kingdom

Milton Keynes

On-site

GBP 50,000 - 65,000

3 days ago
Be an early applicant

Information Security GRC Specialist

TN United Kingdom

London

On-site

GBP 60,000 - 80,000

21 days ago