Career
GRC
A GRC practitioner helps the organisation take risk on purpose. You turn appetite into language delivery can use, design controls people actually operate, and keep evidence alive so audit is a confirmation, not a panic. You are not a checkbox factory, and you are not there to freeze change with theatre.
Open a section
What this job is responsible for
- Risk appetite translated into plain thresholds teams can apply without a lawyer present
- Control frameworks mapped to real digital processes, with named operators and evidence locations
- Assurance plans that test what matters, not what is easy to sample
- Policy exceptions with owners, timeboxes, compensating controls and review dates
- UK GDPR and information governance partnership so data risk sits next to delivery risk
- Escalation paths that join risk, incident, audit findings and RAID without duplicate registers
Signs things are going well
- Risks are written as future uncertain events with cause, impact and treatment, not vague worries
- Controls have day-to-day operators; policy authors alone do not count as operation
- Exceptions expire or renew on purpose; silent forever-exceptions are treated as findings
- Delivery teams ask for GRC help early, before design decisions harden
- Audit findings get lasting fixes with owners, not screenshots and hope
- RAG on control health is trusted because it has been red in public before
How this role works with nearby roles
- Delivery Manager: Owns the delivery risk story and pace. You deepen control design, assurance readiness and appetite language so their RAID is not fiction.
- DevOps / SRE: Implements technical controls, observability and pipeline gates. You set what the control must achieve and what evidence is enough.
- Project Manager: Owns project RAID and tolerances. Align risk categories and reporting so registers do not drift into parallel truths.
- Product Owner: Owns value trade-offs. You make residual risk and compliance constraints visible so priority is honest, not surprising at go-live.
Who this guide is for
GRC, risk, compliance, security governance and assurance specialists supporting digital delivery in regulated UK environments (Civil Service and private sector) who want a plain, relentless guide to proportionate control.