GRC & Client Assurance Specialist
4 days ago
Join beqom - where tech meets impact
beqom is a high-growth B2B SaaS company that provides industry-leading tools for pay equity and transparency, compensation, and performance management.
Trusted by some of the world's most respected companies, beqom enables HR and business leaders to navigate global compliance and make smarter pay decisions that attract, retain, and motivate top talent.
Founded in Switzerland and serving clients worldwide, our powerful, enterprise-ready products are fueled by beqom pay intelligence.
The Role
The GRC & Client Assurance Specialist is responsible for supporting the organization's Governance, Risk, and Compliance (GRC) framework and ensuring that clients receive timely, accurate, and compliant responses related to security, privacy, and regulatory requirements.
This role bridges the gap between internal compliance functions and client-facing teams by managing security assessments, due diligence questionnaires, and audit requests, while maintaining strong alignment with the company's ISO, SOC, and regulatory obligations.
The specialist ensures that organizational controls, policies, and certifications ISO/SOC are effectively communicated to clients, drives continuous improvement in risk and compliance processes, and helps build client trust through transparency and operational excellence.
What will you be doing?
Client Assurance and Vendor Due Diligence (High Priority)
- Security Liaison: Serve as the primary Subject Matter Expert (SME) for all client and prospect security inquiries (RFPs, RFIs), completing comprehensive Security Questionnaires (e.g., SIG, CAIQ) with technical accuracy.
- Audit Facilitation: Manage client-side security audits and requests for evidence, translating complex technical controls into auditable documentation for client risk teams.
- Contractual Compliance: Review client contracts to identify, map, and ensure adherence to specific security and compliance requirements (e.g., data residency, breach notification timelines, specific control mandates).
- Bridge Letter Management: Coordinate the creation and delivery of SOC 2 Bridging Letters (Gap Letters) signed by management to ensure continuous assurance for clients between audit periods.
Control Management and Internal Auditing
- Control Mapping: Maintain the continuous mapping of organisational controls against required frameworks: SOC 2 (Security, Availability, Confidentiality, etc.) and ISO 27001
- Evidence Collection: Streamline and automate the ongoing collection of control evidence (e.g., vulnerability scans, access review logs, change management records) required for external audits.
- Internal Reviews: Perform and document periodic Internal Audits and User Access Reviews (UARs) for high-risk and privileged accounts (ensuring adherence to the Principle of Least Privilege).
- Policy Maintenance: Assist the GRC Manager in reviewing, updating, and distributing security policies and standards to ensure they reflect the current compliance posture and regulatory landscape.
Technical Risk and Remediation
- Risk Analysis: Support the maintenance of the Information Security Management System (ISMS) risk register by performing ad-hoc risk assessments on new features, vendor integrations, and material changes to the production environment.
- Remediation Tracking: Collaborate directly with the Engineering and DevOps teams to translate audit findings and control deficiencies into actionable, prioritized remediation tasks.
What are we looking for?
- Experience: Minimum 3+ years of direct experience in an Information Security, IT Audit, or GRC role, preferably within a SaaS or B2B technology company.
- Framework Expertise (Mandatory): Demonstrated expertise working with and maintaining continuous compliance for SOC 2 Type II and ISO/IEC 27001.
- Technical Literacy: Ability to read and understand technical documentation, cloud architecture diagrams (AWS/Azure), and security concepts (encryption, network segmentation, IAM roles).
- Communication: Exceptional written and verbal communication skills, specifically the ability to translate technical risks into business impact for executive and client audiences.
- Process Acumen: Strong understanding of IT General Controls (ITGCs), change management, vulnerability management, and incident response processes.
Bonus points if you have:
- CISA (Certified Information Systems Auditor)
- CRISC (Certified in Risk and Information Systems Control)
- ISO 27001 Lead Implementer/Auditor certification
- Cloud Certification (e.g., AWS Certified Security – Specialty or Azure Security Engineer Associate)
Why join us?
- Your career, your design. Unleash your ambition in our dynamic, autonomous environment.
- Drive meaningful change. Build a fairer future for every employee by joining a market leader that is improving the world of work.
- Belong to something bigger. Collaborate with a passionate, diverse and talented team around the globe.
-
Information Security Specialist: GRC
2 weeks ago
London, Greater London, United Kingdom UK National Audit Office Full time £68,000 - £80,000 per year• Role: Information Security Specialist: GRC• Type of contract: Full Time, permanent• Location: Hybrid working. On-site, London or Newcastle, minimum 2 days pw• Salary: London c£68,000 Newcastle c£59,000 plus Civil Service employer pension contribution of 28.9%Please note, we are not able to sponsor work visas or accept temporary visas as we are...
-
GRC Analyst
4 days ago
London, Greater London, United Kingdom Maxwell Bond Full time £50,000 - £57,000 per yearGRC Analyst – Cybersecurity ConsultancyLocation: Remote UK (Occasional Office Visits)Salary:£50,000-£57,000 + BenefitsOverviewWe're representing a highly accredited UKcybersecurity consultancythat is seeking aGRC Analystto join its growing governance, risk, and compliance team.This role offers the opportunity to work across a diverse portfolio of...
-
UK&I Region GRC Manager
6 days ago
London, Greater London, United Kingdom Copyrighto.2022 Full time £80,000 - £120,000 per yearJob Location: Greenford Job Location: Greenford Company Description Ferrero is a family-owned company with a truly progressive and global outlook and iconic brands such as Nutella, Tic Tac, Ferrero Rocher, Raffaello, Kinder Bueno and Kinder Surprise. As the love for our brands continues to grow, so too does our global reach. Represented in more...
-
Implementation Manager
1 week ago
London, Greater London, United Kingdom Culture Amp Full time £45,000 - £80,000 per yearJoin us on our mission to make a better world of work. Culture Amp is the world's leading employee experience platform, revolutionizing how 25 million employees across more than 6,500 companies create a better world of work. Culture Amp empowers companies of all sizes and industries to transform employee engagement, drive performance management, and develop...
-
Implementation Manager
1 week ago
London, Greater London, United Kingdom Culture Amp Full time £40,000 - £80,000 per yearJoin us on our mission to make a better world of work.Culture Amp is the world's leading employee experience platform, revolutionizing how 25 million employees across more than 6,500 companies create a better world of work. Culture Amp empowers companies of all sizes and industries to transform employee engagement, drive performance management, and develop...
-
Lead InfoSec GRC Manager
10 hours ago
London, Greater London, United Kingdom Schroders Full time £80,000 - £120,000 per yearJob DescriptionWho we're looking forWe are seeking an experienced technology risk or information security professional to join our team at Schroders. This role involves collaboration across various disciplines with a particular emphasis on securing our digital footprint, as well as third-party and supply chain risk. Experience using AI and automation to...
-
London, Greater London, United Kingdom hackajob Full timehackajob*is collaborating withRightmove*to connect them with exceptional tech professionals for this role.Head of Technology Risk and Delivery AssuranceIT - General - London - Hybrid, London, City of (Hybrid)The roleWe are seeking an experienced and strategic Head of Technology Risk and Delivery Assurance, to join our Product Development team. This is a...
-
GRC Manager
1 week ago
London, Greater London, United Kingdom Polaris Software Full time £60,000 - £90,000 per yearAbout UsAt Polaris, we're on a mission to create a safer and fairer world. We provide software solutions that empower police forces and local authorities to enforce and track traffic and parking offences, manage permits and licenses, and control high-risk assets like firearms and tasers.Since securing support from August Equity in May 2023, we've been on...
-
Client Success Advisor
1 week ago
London, Greater London, United Kingdom Diligent Corporation Full time £60,000 - £80,000 per yearAbout UsDiligent is the AI leader in governance, risk and compliance (GRC) SaaS solutions, helping more than 1 million users and 700,000 board members to clarify risk and elevate governance. The Diligent One Platform gives practitioners, the C-Suite and the board a consolidated view of their entire GRC practice so they can more effectively manage risk, build...
-
Head of Information Security GRC
2 days ago
London, Greater London, United Kingdom Trainline Full time £50,000 - £120,000 per yearAbout usWe are champions of rail, inspired to build a greener, more sustainable future of travel. Trainline enables millions of travellers to find and book the best value tickets across carriers, fares, and journey options through our highly rated mobile app, website, and B2B partner channels. Great journeys start with Trainline Now Europe's number 1...