Governance, Risk and Compliance (GRC Consultant
Governance, Risk & Compliance (GRC) Consultant
Help organisations stay secure, resilient and ready for whatever comes next.
At Sapphire, we've been helping organisations navigate cyber risk for nearly 30 years. As the cyber threat landscape evolves, so do we. That's why we're looking for a talented Governance, Risk & Compliance (GRC) Consultant to join our growing Security Consulting team.
Whether you're already working in cyber consultancy or looking to take the next step in your GRC career, this is an opportunity to work with a diverse range of clients, tackle meaningful challenges, and help shape the future of cyber resilience.
What you'll do
You'll work closely with clients to strengthen their security governance, manage risk, improve compliance, and build confidence in their cyber security programmes.
Your work will include:
✅ Delivering cyber risk assessments and security reviews
✅ Supporting ISO 27001 and other compliance initiatives
✅ Developing policies, frameworks and governance documentation
✅ Helping clients manage supplier and third-party risk
✅ Supporting security improvement programmes and audit readiness activities
✅ Producing clear, practical reports and recommendations
✅ Building trusted relationships with stakeholders at all levels
You'll collaborate with experts across Sapphire's SOC, Security Assurance, Penetration Testing and Consulting teams to deliver joined-up, client-focused solutions.
What we're looking for
We're interested in people with the right attitude, curiosity and consulting mindset as much as specific credentials.
You may be a great fit if you have:
- Experience in cyber security, risk, compliance or consulting
- Knowledge of security frameworks such as ISO 27001, NIST or CAF
- Strong analytical and problem-solving skills
- Excellent communication and report-writing abilities
- Confidence working with both technical and non-technical stakeholders
- A passion for helping organisations improve and mature their security posture
Bonus points if you have experience with:
- ISO 27701, ISO 22301 or other assurance frameworks
- Third-party risk management
- GDPR and privacy requirements
- AI governance and emerging regulations
- GRC platforms such as OneTrust or Vanta
- Cloud environments such as Microsoft Azure or AWS
Why Sapphire?
Flexible remote and hybrid working
Training, development and certification support
Career progression opportunities in a growing cyber consultancy
Supportive and collaborative culture
Work with organisations across multiple sectors and industries
Everyone belongs at Sapphire
We know that great candidates don't always match every requirement. If you're excited by the role and believe you can make an impact, we'd love to hear from you.
At Sapphire, we're committed to creating an inclusive workplace where everyone feels valued, respected and able to thrive.
Interested? Apply today and help organisations build a safer digital future. ✨
Ready to help organisations tackle cyber risk and build resilience? Join Sapphire as a GRC Consultant and work with leading organisations to shape stronger, safer futures. #CyberSecurity #GRC #InfoSec #ConsultingJobs #HiringNow #SapphireCyberSecurity