Career

GRC

A GRC practitioner helps the organisation take risk on purpose. You turn appetite into language delivery can use, design controls people actually operate, and keep evidence alive so audit is a confirmation, not a panic. You are not a checkbox factory, and you are not there to freeze change with theatre.

What this job is responsible for

  • Risk appetite translated into plain thresholds teams can apply without a lawyer present
  • Control frameworks mapped to real digital processes, with named operators and evidence locations
  • Assurance plans that test what matters, not what is easy to sample
  • Policy exceptions with owners, timeboxes, compensating controls and review dates
  • UK GDPR and information governance partnership so data risk sits next to delivery risk
  • Escalation paths that join risk, incident, audit findings and RAID without duplicate registers

Signs things are going well

  • Risks are written as future uncertain events with cause, impact and treatment, not vague worries
  • Controls have day-to-day operators; policy authors alone do not count as operation
  • Exceptions expire or renew on purpose; silent forever-exceptions are treated as findings
  • Delivery teams ask for GRC help early, before design decisions harden
  • Audit findings get lasting fixes with owners, not screenshots and hope
  • RAG on control health is trusted because it has been red in public before

How this role works with nearby roles

  • Delivery Manager: Owns the delivery risk story and pace. You deepen control design, assurance readiness and appetite language so their RAID is not fiction.
  • DevOps / SRE: Implements technical controls, observability and pipeline gates. You set what the control must achieve and what evidence is enough.
  • Project Manager: Owns project RAID and tolerances. Align risk categories and reporting so registers do not drift into parallel truths.
  • Product Owner: Owns value trade-offs. You make residual risk and compliance constraints visible so priority is honest, not surprising at go-live.

Who this guide is for

GRC, risk, compliance, security governance and assurance specialists supporting digital delivery in regulated UK environments (Civil Service and private sector) who want a plain, relentless guide to proportionate control.