
GRC Coordinator
Posted Jul 23

Posted Jul 23
This is a fully remote position, open to applicants in United Kingdom.
• Oversee the daily operations of our Third-Party Risk Management (TPRM) process, facilitating vendor due diligence from initial intake to final approval with support from the broader team.
• Distribute, monitor, and follow up on vendor security questionnaires and assurance documentation (such as ISO 27001 certificates, SOC 2 reports, and penetration test summaries).
• Manage the vendor register, risk categorization, and reassessment timelines, ensuring records are precise and ready for audits.
• Serve as the primary contact for incoming GRC requests, including security questionnaires, due diligence for customers and prospects, and general inquiries concerning ISO 27001, ISO 42001, GDPR, and other data protection regulations, as well as SOC 2, HIPAA, and PCI DSS.
• Prioritize and triage incoming requests, log them in Jira, and assign them to the appropriate GRC team member, monitoring each request until completion.
• Follow up on outstanding security awareness training, engaging with individuals and managers to improve completion rates.
• Participate in team and stakeholder meetings, taking clear notes and recording actions in Jira.
• Assist in gathering and organizing compliance evidence for both internal and external audits under the guidance of the Director of GRC and the Senior Director of Global Risk & Compliance.
• Ensure that GRC documentation and trackers are organized, up-to-date, and ready for audits.
• Propose enhancements to the organization and management of GRC operations as you gain experience.
• Eligibility to work in the UK without sponsorship; we cannot provide visa sponsorship for this position.
• Highly organized, able to manage and prioritize multiple requests and deadlines effectively.
• Excellent written and verbal communication skills; clear, professional, and concise.
• Comfortable using everyday workplace and collaboration tools, with a quick learning curve for new systems (we utilize Jira for logging and tracking tasks).
• A methodical, detail-oriented mindset and a genuine interest in pursuing a career in compliance, security, or risk management.
• Dependable and proactive when working independently in a remote environment.
• Willingness to travel occasionally to our offices in Europe or the US.
• Some experience in compliance, GRC, risk management, auditing, information security, or a related coordination/administrative role.
• Familiarity with one or more common frameworks or regulations (ISO 27001, ISO 42001, SOC 2, GDPR, HIPAA, PCI DSS); a willingness to learn is more important than deep expertise.
• Experience with Jira, Vanta, KnowBe4, or similar GRC/ticketing/training tools.
• Background in a SaaS/software or rapidly growing, multi-entity business.
• A foundational qualification, or ongoing study towards one (e.g., ISO 27001 Foundation, BCS/ISEB Data Protection, CIPP/E).
• Private health insurance
• Eligibility for Company Profits Interest Units or Profits Interest Units Appreciation Rights
• 25 days of paid leave plus bank holidays
• Pension plan
• Group life assurance
• Group income protection
• Flexible work environment
• A supportive, diverse workplace that prioritizes respect for one another and our clients
• A fun and collaborative team culture
CVS Health
FreedomCare
Northrop Grumman
Get handpicked remote jobs straight to your inbox weekly.