GRC & Client Assurance Specialist
6 days ago
Join beqom - where tech meets impact beqom is a high-growth B2B SaaS company that provides industry-leading tools for pay equity and transparency, compensation, and performance management. Trusted by some of the world's most respected companies, beqom enables HR and business leaders to navigate global compliance and make smarter pay decisions that attract, retain, and motivate top talent. Founded in Switzerland and serving clients worldwide, our powerful, enterprise-ready products are fueled by beqom pay intelligence. The Role The GRC & Client Assurance Specialist is responsible for supporting the organization's Governance, Risk, and Compliance (GRC) framework and ensuring that clients receive timely, accurate, and compliant responses related to security, privacy, and regulatory requirements. This role bridges the gap between internal compliance functions and client-facing teams by managing security assessments, due diligence questionnaires, and audit requests, while maintaining strong alignment with the company's ISO, SOC, and regulatory obligations. The specialist ensures that organizational controls, policies, and certifications ISO/SOC are effectively communicated to clients, drives continuous improvement in risk and compliance processes, and helps build client trust through transparency and operational excellence. What will you be doing? Client Assurance and Vendor Due Diligence (High Priority) Security Liaison: Serve as the primary Subject Matter Expert (SME) for all client and prospect security inquiries (RFPs, RFIs), completing comprehensive Security Questionnaires (e.g., SIG, CAIQ) with technical accuracy. Audit Facilitation: Manage client-side security audits and requests for evidence, translating complex technical controls into auditable documentation for client risk teams. Contractual Compliance: Review client contracts to identify, map, and ensure adherence to specific security and compliance requirements (e.g., data residency, breach notification timelines, specific control mandates). Bridge Letter Management: Coordinate the creation and delivery of SOC 2 Bridging Letters (Gap Letters) signed by management to ensure continuous assurance for clients between audit periods. Control Management and Internal Auditing Control Mapping: Maintain the continuous mapping of organisational controls against required frameworks: SOC 2 (Security, Availability, Confidentiality, etc.) and ISO 27001 Evidence Collection: Streamline and automate the ongoing collection of control evidence (e.g., vulnerability scans, access review logs, change management records) required for external audits. Internal Reviews: Perform and document periodic Internal Audits and User Access Reviews (UARs) for high-risk and privileged accounts (ensuring adherence to the Principle of Least Privilege). Policy Maintenance: Assist the GRC Manager in reviewing, updating, and distributing security policies and standards to ensure they reflect the current compliance posture and regulatory landscape. Technical Risk and Remediation Risk Analysis: Support the maintenance of the Information Security Management System (ISMS) risk register by performing ad‑hoc risk assessments on new features, vendor integrations, and material changes to the production environment. Remediation Tracking: Collaborate directly with the Engineering and DevOps teams to translate audit findings and control deficiencies into actionable, prioritized remediation tasks. What are we looking for? Experience: Minimum 3+ years of direct experience in an Information Security, IT Audit, or GRC role, preferably within a SaaS or B2B technology company. Framework Expertise (Mandatory): Demonstrated expertise working with and maintaining continuous compliance for SOC 2 Type II and ISO/IEC 27001. Technical Literacy: Ability to read and understand technical documentation, cloud architecture diagrams (AWS/Azure), and security concepts (encryption, network segmentation, IAM roles). Communication: Exceptional written and verbal communication skills, specifically the ability to translate technical risks into business impact for executive and client audiences. Process Acumen: Strong understanding of IT General Controls (ITGCs), change management, vulnerability management, and incident response processes. Bonus points if you have: CISA (Certified Information Systems Auditor) CRISC (Certified in Risk and Information Systems Control) ISO 27001 Lead Implementer/Auditor certification Cloud Certification (e.g., AWS Certified Security - Specialty or Azure Security Engineer Associate) Why join us? Your career, your design. Unleash your ambition in our dynamic, autonomous environment. Drive meaningful change. Build a fairer future for every employee by joining a market leader that is improving the world of work. Belong to something bigger. Collaborate with a passionate, diverse and talented team around the globe. #J-18808-Ljbffr
-
GRC & Client Assurance Strategist
1 week ago
City Of London, United Kingdom beqom Full timeA leading B2B SaaS company in the City of London seeks a GRC & Client Assurance Specialist. The role involves managing governance, risk, and compliance initiatives, serving as a security liaison, and ensuring adherence to ISO and SOC regulations. Candidates should have a minimum of 3 years of experience and strong communication skills. The role offers a...
-
GRC & Client Assurance Specialist
2 weeks ago
London, Greater London, United Kingdom beqom Full time £60,000 - £100,000 per yearJoin beqom - where tech meets impactbeqom is a high-growth B2B SaaS company that provides industry-leading tools for pay equity and transparency, compensation, and performance management.Trusted by some of the world's most respected companies, beqom enables HR and business leaders to navigate global compliance and make smarter pay decisions that attract,...
-
GRC Specialist
2 weeks ago
City of Edinburgh, United Kingdom Wood Mackenzie Ltd Full timeGRC Specialist page is loaded## GRC Specialistremote type: Hybridlocations: Edinburgh, GBtime type: Full timeposted on: Posted 6 Days Agojob requisition id: JR2481Wood Mackenzie is the global data and analytics business for the renewables, energy, and natural resources industries. Enhanced by technology. Enriched by human intelligence. In an...
-
Delivery Lead
4 weeks ago
london, United Kingdom CoreStream GRC Full timeCoreStream GRC - Delivery Lead / Project Manager / Consultant Hybrid role in Central London (50% office-based) Salary: £45,000 – £65,000 (depending on experience) About CoreStream GRC At CoreStream GRC, we provide organizations with technology to efficiently manage risk, compliance, and audit activities through a risk management solution that is both...
-
GRC/Cybersecurity Consultant
4 weeks ago
london, United Kingdom X4 Technology Full timeJob Title: GRC/Cybersecurity Consultant Location: Fully Remote (UK wide travel required) Employment Type: Permanent Salary: Competitive Start Date: Immediate Industry: IT Services & Consulting A leading Security Consultancy in the UK is seeking a Senior Security Consultant with a strong background in security assessments, GRC, and security architecture to...
-
IT GRC Analyst
1 week ago
City Of London, England, United Kingdom ARC IT Recruitment Full time £60,000 - £80,000 per yearA leading financial services organisation based in the heart of the City of London is seeking an IT GRC Analyst to join its growing team. This is an excellent opportunity for a professional with at least 3 years of experience in IT Governance, Risk, and Compliance (GRC) to take the next step in their career, contributing to the ongoing development and...
-
Assurance Manager
4 days ago
City Of London, United Kingdom Barhale Holdings Ltd Full timeAbout Barhale Barhale is a business founded on family values, having been established by our Chairman, Dennis Curran, in 1980. We are one of the largest privately owned civil engineering and infrastructure specialists in the UK, with over 40 years of experience in providing design, civil engineering and maintenance services working across multiple sectors,...
-
Assurance Manager
4 days ago
City Of London, United Kingdom Barhale Full timeAbout Barhale Barhale is a business founded on family values, having been established by our Chairman, Dennis Curran, in 1980. We are one of the largest privately owned civil engineering and infrastructure specialists in the UK, with over 40 years of experience in providing design, civil engineering and maintenance services working across multiple sectors,...
-
SAP GRC
1 week ago
London, United Kingdom StackStudio Digital Ltd. Full timeJob Description SAP GRC / CSV Specialist (Pharma Domain)End Client Domain: PharmaIncrease your chances of reaching the interview stage by reading the complete job description and applying promptly.Location: London, UKWork Model: 1 2 Days Onsite (Flexible Hybrid)Contract: Fixed Term (12 months)Must-Have Domain ExperiencePharma, manufacturing experienceSystems...
-
SAP GRC
2 weeks ago
London, United Kingdom StackStudio Digital Ltd. Full timeJob Description SAP GRC / CSV Specialist (Pharma Domain)End Client Domain: PharmaIncrease your chances of reaching the interview stage by reading the complete job description and applying promptly.Location: London, UKWork Model: 1 2 Days Onsite (Flexible Hybrid)Contract: Fixed Term (12 months)Must-Have Domain ExperiencePharma, manufacturing experienceSystems...