GRC Coordinator
Posted 8hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
GRC Coordinator managing Third-Party Risk Management processes within a growing SaaS group. Organizing compliance requests and maintaining documentation for audits.
Responsibilities:
- Own the day-to-day running of our Third-Party Risk Management (TPRM) process, coordinating vendor due diligence from intake through to sign-off with guidance from the wider team.
- Send, track, and chase vendor security questionnaires and assurance evidence (e.g. ISO 27001 certificates, SOC 2 reports, penetration test summaries).
- Maintain the vendor register, risk tiering, and reassessment schedules, keeping records accurate and audit-ready.
- Act as the first point of contact for incoming GRC requests including security questionnaires, customer and prospect due diligence, and general queries relating to ISO 27001, ISO 42001, GDPR and other data protection regulations, SOC 2, HIPAA, and PCI DSS.
- Triage and prioritise incoming requests, log them in Jira, and assign them to the right GRC team member, tracking each through to completion.
- Chase outstanding security awareness training, following up with individuals and managers to drive completion rates up.
- Attend team and stakeholder meetings, take clear notes, and capture actions in Jira.
- Help gather and organise compliance evidence for internal and external audits, under direction from the Director of GRC and the Senior Director of Global Risk & Compliance.
- Keep GRC documentation and trackers tidy, current, and audit-ready.
- Suggest improvements to how we organise and run GRC operations as you learn the ropes.
Requirements:
- Right to work in the UK without sponsorship; we are unable to offer visa sponsorship for this role.
- Highly organised, with the ability to juggle and prioritise multiple requests and deadlines without dropping things.
- Strong written and verbal communication; clear, professional, and concise.
- Comfortable with everyday workplace and collaboration tools, and quick to pick up new systems (we use Jira to log and track work).
- A methodical, detail-oriented approach and a genuine interest in building a career in compliance, security, or risk.
- Reliable and proactive when working independently in a remote setting.
- Willingness to travel occasionally to our European or US offices.
- Some exposure to compliance, GRC, risk, audit, information security, or a related coordination/administrative role.
- Awareness of one or more common frameworks or regulations (ISO 27001, ISO 42001, SOC 2, GDPR, HIPAA, PCI DSS); a willingness to learn matters more than deep expertise.
- Familiarity with Jira, Vanta, KnowBe4, or similar GRC / ticketing / training tools.
- Experience in a SaaS / software or fast-growth, multi-entity business.
- A foundational qualification, or study towards one (e.g. ISO 27001 Foundation, BCS/ISEB Data Protection, CIPP/E).
Benefits:
- Private health insurance
- Company Profits Interest Units or Profits Interest Units Appreciation Rights eligibility
- 25 days paid leave plus bank holidays
- Pension
- Group life assurance
- Group income protection
- Flexible work environment
- A supportive, diverse workplace where we prioritize respect for each other and our clients
- A fun and collaborative team culture















