Governance, Risk and Compliance (GRC Consultant

Governance, Risk & Compliance (GRC) Consultant

Help organisations stay secure, resilient and ready for whatever comes next.

At Sapphire, we've been helping organisations navigate cyber risk for nearly 30 years. As the cyber threat landscape evolves, so do we. That's why we're looking for a talented Governance, Risk & Compliance (GRC) Consultant to join our growing Security Consulting team.

Whether you're already working in cyber consultancy or looking to take the next step in your GRC career, this is an opportunity to work with a diverse range of clients, tackle meaningful challenges, and help shape the future of cyber resilience.

What you'll do

You'll work closely with clients to strengthen their security governance, manage risk, improve compliance, and build confidence in their cyber security programmes.

Your work will include:

✅ Delivering cyber risk assessments and security reviews

✅ Supporting ISO 27001 and other compliance initiatives

✅ Developing policies, frameworks and governance documentation

✅ Helping clients manage supplier and third-party risk

✅ Supporting security improvement programmes and audit readiness activities

✅ Producing clear, practical reports and recommendations

✅ Building trusted relationships with stakeholders at all levels

You'll collaborate with experts across Sapphire's SOC, Security Assurance, Penetration Testing and Consulting teams to deliver joined-up, client-focused solutions.

What we're looking for

We're interested in people with the right attitude, curiosity and consulting mindset as much as specific credentials.

You may be a great fit if you have:

  • Experience in cyber security, risk, compliance or consulting
  • Knowledge of security frameworks such as ISO 27001, NIST or CAF
  • Strong analytical and problem-solving skills
  • Excellent communication and report-writing abilities
  • Confidence working with both technical and non-technical stakeholders
  • A passion for helping organisations improve and mature their security posture

Bonus points if you have experience with:

  • ISO 27701, ISO 22301 or other assurance frameworks
  • Third-party risk management
  • GDPR and privacy requirements
  • AI governance and emerging regulations
  • GRC platforms such as OneTrust or Vanta
  • Cloud environments such as Microsoft Azure or AWS

Why Sapphire?

Flexible remote and hybrid working

Training, development and certification support

Career progression opportunities in a growing cyber consultancy

Supportive and collaborative culture

Work with organisations across multiple sectors and industries

Everyone belongs at Sapphire

We know that great candidates don't always match every requirement. If you're excited by the role and believe you can make an impact, we'd love to hear from you.

At Sapphire, we're committed to creating an inclusive workplace where everyone feels valued, respected and able to thrive.

Interested? Apply today and help organisations build a safer digital future.

Ready to help organisations tackle cyber risk and build resilience? Join Sapphire as a GRC Consultant and work with leading organisations to shape stronger, safer futures. #CyberSecurity #GRC #InfoSec #ConsultingJobs #HiringNow #SapphireCyberSecurity

Job Details

Company
Sapphire
Location
Glasgow, UK
Hybrid / Remote Options
Posted