GWI

Technology

InformationSecurityGovernance,RiskandComplianceSpecialist

£65–95k ~AI est. London, United Kingdom FULL TIME Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid-Senior candidates.

The Brief

“Information Security Governance, Risk and Compliance Specialist at GWI. Skills: Information Security GRC, Compliance posture, Vendor risk management, Client security. Own and maintain ISO 27001 certification. Maintain compliance across security frameworks”

Industry & Context.

Technology

What They're Looking For.

Must Have

3-5 years in information security compliance role, Develop and maintain security policies, Conduct vendor security assessments, Manage client security onboarding requirements, Implement and manage cloud security best practices

Nice to Have

Familiarity with Drata or Vanta, ISO 27001 certification

What You'll Do.

Own and maintain ISO 27001 certification

Maintain compliance across security frameworks

Develop information security policies

Implement information security policies

Maintain information security policies

Develop security procedures

Implement security procedures

Maintain security procedures

Lead vendor risk management

Lead client security assessments

Respond to client security questionnaires

Manage client onboarding requirements

Build security trust portal

Maintain security trust portal

Drive security awareness

How You'll Work.

Team & Collaboration

Information Security teams; Product teams; Technology teams; Legal team

Communication Scope

Translate GRC topics; Internal guidance; Keep business informed

Full Job Description

Location: London, UK Weekly office requirement: Hybrid – 2 days per week Employment type: Permanent Seniority level: Mid-Senior At GWI we're always looking for extraordinary people who thrive on making an extraordinary impact. Right now we're looking for an Information Security GRC Specialist to play a key role in our Legal team in London. If that's you, and making a difference gets you out of bed in the morning, keep reading. It could be the start of something, well, extraordinary. Sounds great, what will I be doing? 🤔 As our Information Security GRC Specialist you'll play a pivotal role in shaping the future of security compliance at GWI. Reporting into our General Counsel and working closely with our Information Security, Product, and Technology teams, you'll own our compliance posture across security frameworks, vendor risk, and client-facing security requirements — while building a security-conscious culture across the business. A few things you'll be responsible for: 👉 Own and maintain GWI's ISO 27001 certification and compliance across relevant security frameworks, keeping our posture sharp as the threat landscape evolves. 👉 Develop, implement, and maintain information security policies and procedures aligned with industry best practices. 👉 Lead vendor risk management and client security assessments — including responding to client security questionnaires and onboarding requirements. 👉 Build and maintain GWI's security trust portal, showcasing our credentials to clients and stakeholders using tools such as Drata or Vanta. 👉 Drive security awareness across the business through training programmes and internal communications that promote a strong GRC culture. It's also fun; shaking things up is what working for GWI is all about. You'll need to be flexible, comfortable with continuous change, and working in a high-tempo environment. What do I need to bring with me? 🧳 You'll need to be able to demonstrate the core skills this role requires. You don't have

Free ATS check

Applying for this Information Security Governance, Risk and Compliance Specialist role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Greenhouse

  • Create a Greenhouse profile before applying — it saves time across multiple applications.
  • Upload your resume as a PDF; the parser handles it better than Word.
  • Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
  • Enable email notifications to track application status in real time.

ANONYMOUS · UNFILTERED

What do employees actually say about GWI?

Real rants from real employees. Read before you apply.

Read Company Rants →