Governance Risk & Compliance Manager implementing risk management strategies at Sword. Overseeing compliance and security governance practices within the organisation.
Responsibilities
Security Governance – Develop and refine security policies, frameworks, and procedures, maintaining alignment and accreditation ISO 27001 and Cyber Essentials Plus
Risk Management – Conduct ongoing security risk assessments across vendors, projects, and internal teams, identifying areas of concern and driving remediation efforts
Legal, Regulatory, and Contractual Requirements – Ensure Sword remains compliant with relevant legal, contractual, and regulatory obligations, keeping pace with evolving regulations in all areas where Sword operates
Third-Party & Supply Chain Security – Assess and manage security risks related to suppliers and partners, ensuring robust security measures are maintained
Certification Management – Oversee and drive Sword’s certification in both Cyber Essentials Plus and ISO 27001 including management of the ISMS
Business Resilience – Refine and mature the Sword business continuity and disaster recovery plans including regular testing and exercising
Audit & Compliance – Ongoing audit and compliance of Sword policies and procedures against relevant contractual and regulatory obligations
Data Protection – Central coordination of GDPR compliance across Sword including standardising processes and procedures with Data Protection Officers
Security Culture – Drive improvements in the internal security culture through ongoing awareness, training and communications on policies, processes, and procedures
Continuous Improvement – Deliver the risk & compliance program through a series of continuous and incremental improvements.
Requirements
Direct experience, or strong working knowledge, of GRC frameworks aligned with industry standards and organisational goals
Cyber Security Frameworks (NIST), regulations such as the General Data Protection Regulations (GDPR) and Network Information Systems (NIS2), and industry standards such as ISO 27001
Ability to identify, assess, and mitigate risks across business processes and technical environments
Experience managing audits and compliance reporting, including designing effective controls, developing audit plans, interfacing with auditors, and responding to findings
Technical proficiency with GRC tools and platforms, including compliance monitoring technologies and data analysis (e.g., advanced Excel skills)
Analytical and problem-solving skills to interpret complex regulations, resolve compliance issues, and provide strategic advice to leadership
Excellent communication skills, both written and verbal, including the ability to convey complex regulatory and risk issues in understandable terms to stakeholders across the business
Significant experience in a similar role preferably in an international organisation. Qualifications and Personal Skills
Major industry certification such as CISA, CRISC, ISO 27001, etc.
Experience in relevant Governance, Risk, and Compliance frameworks and technologies
Takes ownership and accountability with an ability to self-manage tasks and activities to consistently deliver results
Dedicated and proactive learner who keeps up to date with security regulations and is continuously improving and refining skills
Excellent communication, negotiation and influencing skills – able to influence operational effectiveness across an organisation to achieve results.
Benefits
Personalised Career Development: We create a development plan customised to your goals and aspirations, with a range of learning and development opportunities within a culture that encourages growth.
Flexible working: Flexible work arrangements to support your work-life balance. We can’t promise to always be able to meet every request, however, are keen to discuss your individual preferences to make it work where we can.
A Fantastic Benefits Package: This includes generous annual leave allowance, enhanced family friendly benefits, pension scheme, access to private health, well-being, and insurance schemes.
Compliance Officer ensuring compliance with Estonian financial regulations and working closely with authorities. Drafting policies and conducting training within a remote - first crypto payments company.
Compliance Manager overseeing regulatory compliance in Australia's energy sector startup. Leading compliance strategies and risk mitigation for consumer energy resources at Brighte.
Senior Regulatory Scientist conducting compliance reviews and developing regulatory strategies for medical devices at COOK. Ensuring adherence to regulatory standards while supporting clinical evaluations and audits.
Ethics & Compliance Specialist at Cook Australia acting as the key compliance contact. Partnering with teams to enhance and enforce compliance program across various regions and areas.
Trade Compliance Manager overseeing trade compliance and logistics operations for NXP in Malaysia. Ensuring adherence to regulations and leading supply chain security initiatives.
Director of Technology providing strategic leadership at the ICO's Technology directorate. Overseeing regulatory interventions and ensuring effective policy development in a complex environment.
VP leading compliance architecture for complex multi - jurisdiction deals in fintech. Engaging with clients and translating regulatory changes into commercial opportunities for global markets.
Senior Manager managing cultural resource management and Tribal relations program at Invenergy. Leading development and implementation for energy development compliance across the US.
Lead Compliance Investigator at HCSC handling high - risk internal investigations. Responsible for preparing reports and guiding management on compliance - related issues.