Senior InfoSec GRC Specialist

Clearwater Analytics (CWAN)

England

On-site

GBP 65,000 - 85,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

A leading analytics firm is seeking a Lead Recruiter in the UK, responsible for supporting security inquiries and compliance processes. The role involves managing security assessments, reviewing vendor compliance, and leading audit processes. Candidates should have 7+ years of experience with SOC2, ISO 27001 audits, and security policies, along with excellent communication skills and the ability to work in teams. This is a full-time position offering opportunities for growth within the organization.

Qualifications

  • Minimum of 7+ years of role-specific experience.
  • Experience managing and responding to Client/Prospect Security Assessments.
  • Demonstrated experience with SOC 1, SOC 2, or ISO 27001 audits.

Responsibilities

  • Assist in the production of responses to security questions.
  • Act as first point of escalation for security compliance questions.
  • Review third-party vendors for security and compliance controls.

Skills

Knowledge of SOC2 and ISO 27001 control frameworks
Ability to work effectively in a team environment
Excellent attention to detail
Strong documentation skills
Excellent verbal, written and interpersonal communication skills
Proficient in Microsoft Office

Tools

Atlassian (JIRA)

Job description

Lead Recruiter at Clearwater Analytics - Hiring in UK, France, Germany, Luxembourg

Job Description

The Senior InfoSec GRC Specialist plays a pivotal role across multiple dimensions. They are instrumental in crafting responses to security inquiries within "request for proposals" (RFPs) and ensuring their prompt delivery. As the initial point of contact for addressing customer security concerns, they actively seek avenues to optimize the efficiency of the security customer engagement process. Moreover, they utilize structured methods and protocols to identify and assess risk, implement pertinent controls, formalize agreements, and diligently follow through on necessary procedures. Effective communication is at the core of their responsibilities, encompassing the dissemination of strategies, standards, policies, procedures, and awareness campaigns to all business partners. They take purposeful actions to guarantee global business units' compliance with relevant frameworks and conduct comprehensive reviews of proposed vendor engagement terms and conditions. Additionally, they apply the company's risk profile, offer pertinent feedback, and meticulously document any deviations from the established processes.

Responsibilities
  • Assists in the production of response to security questions in “request for proposals” (RFP’s) or customer assessments (Due Diligence Questionnaires).
  • Acts as first point of escalation for security/compliance questions for current and prospective customers.
  • Review third party vendors for security and compliance controls; assesses risk based on a given risk assessment framework (Third Party Risk Management/Vendor Assessment).
  • Assists and/or takes the lead in managing/overseeing annual SOC2 & ISO27001 audits.
  • Contributes in annual InfoSec Policies review/edits/updates and provides considered input.
  • Review proposed client engagement terms and conditions and apply the company risk profile, providing the appropriate feedback as to any changes needed and documenting exceptions to the process.
  • Assists in the collation of Enterprise Risk, control and mitigation updates, along with KRIs.
  • Identifies efficiency improvements in the security customer engagement process.
  • Communicates strategies, standards, policies, procedures, communications, and awareness efforts with all business partners.
  • Takes actions as directed to ensure compliance of global business units in actions necessary to ensure compliance with applicable frameworks.
  • Keeps up to date with evolving regulations and legislation related to privacy and security as they pertain to Clearwater.
  • Ability to manage time effectively by hitting assigned deadlines and milestones.
  • Requires minimum supervision to work on daily tickets and tasks, can use documentation and team resources to complete most tasks.
  • Capably resolves all but the most complex operational issues without the need for escalation.
  • Willingness and ability to maintain a positive, quality‑oriented, reliable and flexible attitude.
  • Actively seeks opportunities for improving key processes and systems without requiring daily direction.
  • Demonstrates the ability to take on an assignment, project, or problem and lead, define, and implement a solution to completion.
Requirements
  • Knowledge of SOC2 and ISO 27001 control frameworks.
  • Knowledge of risk frameworks and risk management processes.
  • Ability to work effectively in a team environment and across all organizational levels, where flexibility, collaboration, and adaptability are important.
  • Excellent attention to detail and strong documentation skills.
  • Excellent verbal, written and interpersonal communication skills.
  • Experienced in Atlassian (JIRA) and proficient in Microsoft Office.
Experience
  • 7+ years of role-specific experience, preferred.
  • Demonstrated experience in owning, managing and responding to Client/Prospect Security Assessments (DDQs, RFPs etc.).
  • Experience working with Third Party Risk Management/Vendor Assessment tasks.
  • Demonstrated experience with SOC 1, SOC 2, and/or ISO 27001 audits and monitoring control activities.
  • Experience in owning/editing/contributing to Information Security Policies.
  • Experience performing or undergoing internal and external audits.
  • Experience with compliance, audit, or operations including development of internal controls, policies, and procedures.
  • Experience assisting in risk management processes, control frameworks, KRIs.
  • Experience communicating technical controls and processes with customers and stakeholders.
  • Demonstrated professional application of information security, compliance, assurance and/or other security practices and principles.
Seniority level
  • Mid‑Senior level
Employment type
  • Full‑time
Job function
  • Information Technology and General Business
Industries
  • Software Development
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security GRC Specialist
Information Security GRC Specialist

Morson Edge (Financial Services) • Greater London

Hybrid
GBP 90,000 - 120,000
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Control Risks • Greater London

On-site
GBP 60,000 - 80,000
Competitively positioned compensation package
Discretionary global bonus scheme
Hybrid working arrangements
Principal GRC Consultant
Principal GRC Consultant

SCC • Birmingham

On-site
GBP 85,000 - 120,000
Hybrid working
2 volunteering days a year
Career development
Assistant Manager – Information Security
Assistant Manager – Information Security

Jobtailor • Greater London

Hybrid
GBP 70,000 - 95,000
Information Security and Data Protection Analyst
Information Security and Data Protection Analyst

Interact Software • Manchester

On-site
GBP 45,000 - 65,000
Senior Security Consultant (GRA)
Senior Security Consultant (GRA)

FSP Consulting Services Limited • England

On-site
GBP 60,000 - 80,000
Collaborative environment
Hybrid working options
Industry-leading coaching and mentoring
+1
Senior SOC Analyst
Senior SOC Analyst

Focus Group • Manchester

Hybrid
GBP 60,000 - 90,000
Head of Cyber GRC
Head of Cyber GRC

Cyber UK • United Kingdom

On-site
Senior Information Security Consultant (GRC)
Senior Information Security Consultant (GRC)

CyberNorth • United Kingdom

Hybrid
GBP 70,000 - 100,000