GRC Consultant

Job Description

GRC Consultant (Governance, Risk & Compliance)

Contract | 3 Months | Remote | 3 Days per Week | £500–£600 per day

Build a compliance function from the ground up.

We’re partnering with an ambitious software business that’s experiencing significant growth and preparing to onboard several major enterprise clients. With that growth comes increasing scrutiny around governance, security and compliance and they’re looking for an experienced GRC Consultant to build a scalable compliance framework that will support the business for years to come.

This isn’t a box-ticking exercise.

You’ll be embedded within the team, working closely with senior stakeholders to understand the business, identify gaps, implement best practices, and create a pragmatic compliance function that actually works.

Following the initial engagement, there’s a strong opportunity to continue supporting the business on a retained, long-term basis.

What you’ll be doing

You’ll take ownership of the company’s Governance, Risk & Compliance capability, including:

Reviewing the current compliance landscape and identifying gaps
Building a practical compliance framework across the business
Leading PCI DSS compliance initiatives
Developing and improving GDPR processes and documentation
Supporting security standards such as ISO 27001, SOC 2 and/or Cyber Essentials
Creating policies, procedures and governance documentation
Building and maintaining risk registers
Preparing the business for future audits and assessments
Managing client security questionnaires and compliance requests
Tracking ongoing compliance requirements, renewals and evidence
Coordinating external security assessments and penetration testing where required
Advising leadership on evolving compliance and regulatory requirements

What we’re looking for

We’re looking for someone who has genuinely done this before.

You’ll be comfortable coming into a growing technology business, understanding what exists today and creating a practical roadmap to get everything where it needs to be.

Ideally you’ll have experience with:

Governance, Risk & Compliance (GRC)
PCI DSS
GDPR
ISO 27001, SOC 2 and/or Cyber Essentials
Security governance and audit preparation
Policy creation and documentation
Risk management frameworks
Working independently with multiple stakeholders
Supporting SaaS or technology businesses

Nice to have

Experience with Point of Sale (POS) compliance
Knowledge of French compliance or regulatory requirements
Experience supporting businesses operating across multiple European markets

Why this role?

This client could engage a consultancy.

Instead, they want an experienced independent consultant who’ll become part of the team, build relationships with stakeholders and leave behind a compliance framework that scales with the business.

If you enjoy taking ownership, solving problems and making a visible impact, this is the kind of engagement where you’ll genuinely shape how a company approaches governance and compliance.

The Details

Contract: Initial 3-month engagement
Commitment: Approximately 3 days per week
Rate: £500–£600 per day
Location: Hybrid/Remote
Start: ASAP
Potential for ongoing retained work following the initial project

If you’re an experienced GRC Consultant looking for a contract where you can make a genuine impact – not simply maintain existing processes – we’d love to hear from you.

Job Information

Job ID

70711

Published Date

06-08-2026

Contact Name

Sameer Chouhan

Phone Number

Contact email

sameer@rmgdigital.io

Share this job

Apply for your new role

To apply for a position, please complete the following form. Once we receive your application, we’ll review it carefully and reach out to you if we think you could be a good fit for the position.