GWI
Technology
InformationSecurityGovernance,RiskandComplianceSpecialist
Neural analysis suggests this role is
optimal for Mid-Senior candidates.
“Information Security Governance, Risk and Compliance Specialist at GWI. Skills: Information Security GRC, Compliance posture, Vendor risk management, Client security. Own and maintain ISO 27001 certification. Maintain compliance across security frameworks”
Industry & Context.
What They're Looking For.
Must Have
3-5 years in information security compliance role, Develop and maintain security policies, Conduct vendor security assessments, Manage client security onboarding requirements, Implement and manage cloud security best practices
Nice to Have
Familiarity with Drata or Vanta, ISO 27001 certification
What You'll Do.
Own and maintain ISO 27001 certification
Maintain compliance across security frameworks
Develop information security policies
Implement information security policies
Maintain information security policies
Develop security procedures
Implement security procedures
Maintain security procedures
Lead vendor risk management
Lead client security assessments
Respond to client security questionnaires
Manage client onboarding requirements
Build security trust portal
Maintain security trust portal
Drive security awareness
How You'll Work.
Team & Collaboration
Information Security teams; Product teams; Technology teams; Legal team
Communication Scope
Translate GRC topics; Internal guidance; Keep business informed
Full Job Description
Location: London, UK Weekly office requirement: Hybrid – 2 days per week Employment type: Permanent Seniority level: Mid-Senior At GWI we're always looking for extraordinary people who thrive on making an extraordinary impact. Right now we're looking for an Information Security GRC Specialist to play a key role in our Legal team in London. If that's you, and making a difference gets you out of bed in the morning, keep reading. It could be the start of something, well, extraordinary. Sounds great, what will I be doing? 🤔 As our Information Security GRC Specialist you'll play a pivotal role in shaping the future of security compliance at GWI. Reporting into our General Counsel and working closely with our Information Security, Product, and Technology teams, you'll own our compliance posture across security frameworks, vendor risk, and client-facing security requirements — while building a security-conscious culture across the business. A few things you'll be responsible for: 👉 Own and maintain GWI's ISO 27001 certification and compliance across relevant security frameworks, keeping our posture sharp as the threat landscape evolves. 👉 Develop, implement, and maintain information security policies and procedures aligned with industry best practices. 👉 Lead vendor risk management and client security assessments — including responding to client security questionnaires and onboarding requirements. 👉 Build and maintain GWI's security trust portal, showcasing our credentials to clients and stakeholders using tools such as Drata or Vanta. 👉 Drive security awareness across the business through training programmes and internal communications that promote a strong GRC culture. It's also fun; shaking things up is what working for GWI is all about. You'll need to be flexible, comfortable with continuous change, and working in a high-tempo environment. What do I need to bring with me? 🧳 You'll need to be able to demonstrate the core skills this role requires. You don't have
Applying for this Information Security Governance, Risk and Compliance Specialist role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Greenhouse
- Create a Greenhouse profile before applying — it saves time across multiple applications.
- Upload your resume as a PDF; the parser handles it better than Word.
- Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
- Enable email notifications to track application status in real time.
ANONYMOUS · UNFILTERED
What do employees actually say about GWI?
Real rants from real employees. Read before you apply.