GRC Lead

Wordsmith
Edinburgh
Workplace: HybridFull timeFunction: Legal, Risk & ComplianceSkills: ["Cross-functional collaboration","Incident response leadership","Security operations","Risk assessment","Communication"]

Build and own the IT security function for an AI-enabled legal command centre, covering device management, IAM, and infrastructure/cloud security. Lead end-to-end incident response and security monitoring using tools like EDR/DLP/SIEM. Own SOC 2 Type II and ISO 27001/27017/27018, automate audit evidence, and support AI governance and vendor risk. Partner with Sales, Customer Success, and Legal to support enterprise security questionnaires and manage the Trust Center.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Wordsmith
Wordsmith
1 month ago

GRC Lead

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 8 hours agoStatus: Live

Job Summary

Build and own the IT security function for an AI-enabled legal command centre, covering device management, IAM, and infrastructure/cloud security. Lead end-to-end incident response and security monitoring using tools like EDR/DLP/SIEM. Own SOC 2 Type II and ISO 27001/27017/27018, automate audit evidence, and support AI governance and vendor risk. Partner with Sales, Customer Success, and Legal to support enterprise security questionnaires and manage the Trust Center.
Location: Edinburgh
Workplace: Hybrid
Employment Type: Full time
Job Function: Legal, Risk & Compliance

Key Responsibilities

  • •Build IT security from the ground up across device management, identity/access, and infrastructure/cloud security controls.
  • •Lead full-lifecycle security incident response, coordinating with internal teams and external partners and running post-incident reviews and tabletop exercises.
  • •Operate and tune security monitoring and detection tooling such as EDR, DLP, and SIEM to detect and respond to threats.
  • •Own SOC 2 Type II and ISO 27001/27017/27018 end-to-end, including policy, audit evidence, and audits, with automated evidence collection.
  • •Support AI governance and vendor risk assessments, and partner on enterprise deal support including security questionnaires, DPAs, and contract terms while managing the Trust Center.

Key Requirements

  • •Experience running IT security operations at a fast-growing SaaS company, including device management and identity/access management.
  • •Hands-on experience with MDM platforms such as Jamf or Intune.
  • •Hands-on experience with IAM tooling (e.g. Okta) and cloud infrastructure security (e.g. AWS).
  • •Experience leading security incident response from investigation through post-incident review.
  • •Working knowledge of SOC 2 and the ISO 27000 series.
Experience:SaaSLegal techAIHighly regulated
Skills:Cross-functional collaborationIncident response leadershipSecurity operationsRisk assessmentCommunication
Certifications:CISSP/ISC2CCSKCIPP/EAIGP
Tech Stack:JamfIntuneOktaAWSSOC 2ISO 27001ISO 27017ISO 27018EDRDLPSIEMSOCaaSGDPRISO 42001VantaCrowdstrikeZscalerDatadogWhistic

Company Brief

Wordsmith
Provides an AI-powered writing platform that generates human-like marketing copy, blog posts, and content at scale, helping teams automate content creation, improve SEO, and accelerate writing workflows.
Industry: SaaS
Website