Governance, Risk and Compliance (GRC Consultant
Job Description
🚀 Governance, Risk & Compliance (GRC) Consultant
\nHelp organisations stay secure, resilient and ready for whatever comes next.
\nAt Sapphire, we've been helping organisations navigate cyber risk for nearly 30 years. As the cyber threat landscape evolves, so do we. That's why we're looking for a talented Governance, Risk & Compliance (GRC) Consultant to join our growing Security Consulting team.
\nWhether you're already working in cyber consultancy or looking to take the next step in your GRC career, this is an opportunity to work with a diverse range of clients, tackle meaningful challenges, and help shape the future of cyber resilience.
\nWhat you'll do
\nYou'll work closely with clients to strengthen their security governance, manage risk, improve compliance, and build confidence in their cyber security programmes.
\nYour work will include:
\n'05; Delivering cyber risk assessments and security reviews
\n'05; Supporting ISO 27001 and other compliance initiatives
\n'05; Developing policies, frameworks and governance documentation
\n'05; Helping clients manage supplier and third-party risk
\n'05; Supporting security improvement programmes and audit readiness activities
\n'05; Producing clear, practical reports and recommendations
\n'05; Building trusted relationships with stakeholders at all levels
\nYou'll collaborate with experts across Sapphire's SOC, Security Assurance, Penetration Testing and Consulting teams to deliver joined-up, client-focused solutions.
\nWhat we're looking for
\nWe're interested in people with the right attitude, curiosity and consulting mindset as much as specific credentials.
\nYou may be a great fit if you have:
\n- \n
- Experience in cyber security, risk, compliance or consulting \n
- Knowledge of security frameworks such as ISO 27001, NIST or CAF \n
- Strong analytical and problem-solving skills \n
- Excellent communication and report-writing abilities \n
- Confidence working with both technical and non-technical stakeholders \n
- A passion for helping organisations improve and mature their security posture \n
Bonus points if you have experience with:
\n- \n
- ISO 27701, ISO 22301 or other assurance frameworks \n
- Third-party risk management \n
- GDPR and privacy requirements \n
- AI governance and emerging regulations \n
- GRC platforms such as OneTrust or Vanta \n
- Cloud environments such as Microsoft Azure or AWS \n
Why Sapphire?
\n💙 Flexible remote and hybrid working
\n📚 Training, development and certification support
\n🚀 Career progression opportunities in a growing cyber consultancy
\n🤝 Supportive and collaborative culture
\n🌍 Work with organisations across multiple sectors and industries
\nEveryone belongs at Sapphire
\nWe know that great candidates don't always match every requirement. If you're excited by the role and believe you can make an impact, we'd love to hear from you.
\nAt Sapphire, we're committed to creating an inclusive workplace where everyone feels valued, respected and able to thrive.
\nInterested? Apply today and help organisations build a safer digital future. 🔐'28;
\n🔐 Ready to help organisations tackle cyber risk and build resilience? Join Sapphire as a GRC Consultant and work with leading organisations to shape stronger, safer futures. #CyberSecurity #GRC #InfoSec #ConsultingJobs #HiringNow #SapphireCyberSecurity
