Technical GRC Specialist
£50k - £65k per yearCapacity
Software-as-a-Service (SaaS) Security Practitioner
Our mission at Capacity is to help teams do their best work through our AI-powered support automation platform. Capacity provides everything you need to automate support and business processes in one powerful omni-channel platform.
We believe that each individual voice, perspective and background brings inherent value to enhance our product, serve our customers and generate more ideas to solve complex problems. By continuing to hire talented, driven and humble teammates, we have the opportunity to see Capacity become a premier brand enterprise SaaS platform.
Capacity has raised over $100 million dollars from over 150 investors, giving us the opportunity to make ambitious investments in our team and big bets on our future. Our total addressable market is enormous. Any company that wants to grow revenue, reduce costs, and improve customer and employee satisfaction is an opportunity for Capacity to shine.
Why This Job Is Exciting
The role:
We are looking for an experienced software-as-a-service (SaaS) security practitioner to join our growing Governance, Risk & Compliance (GRC) team. This role will primarily take ownership of our security hardening standards and our Third-Party Risk Management (TPRM), focusing on proactive improvements in cybersecurity, ensuring audit readiness, and scaling GRC processes through automation.
This is a high-impact role suited to someone who wants to influence cybersecurity at scale, enjoys working cross-functionally, and is able to balance strong risk management with commercial pragmatism.
You will work closely with operational stakeholders across the organization, helping strengthen our overall security posture, including vendor assurance, while enabling the business to move safely and quickly.
Responsibilities
In this role, you will be responsible for the following:
Security Hardening & Technical GRC
- Provide hands-on support in the assessment, improvement, and maintenance of technical security baselines based on industry best practices (e.g., NIST, CIS, ISO). You will ensure these configurations satisfy global regulatory mandates (e.g., HIPAA, GDPR).
- Leverage automated tools to monitor security and compliance posture.
- Act as a GRC interface with Infrastructure and Engineering teams to ensure hardening requirements are technically feasible and effectively implemented.
Third-Party Risk Management
- Manage and continuously improve the company's Third-Party Risk Management programme across suppliers, vendors and strategic partners.
- Own end-to-end due diligence processes for new and existing vendors, including inherent risk assessments, security/privacy reviews and ongoing monitoring.
- Review vendor assurance documentation such as ISO 27001 certificates, SOC 2 reports, penetration test summaries, policies and compliance evidence.
- Identify, document and communicate vendor risks, remediation actions and approval recommendations.
- Maintain risk tiering and reassessment schedules for critical and high-risk vendors.
- Act as a trusted partner to internal stakeholders during vendor onboarding, renewals and procurement decisions.
- Engage directly with suppliers to resolve due diligence issues and drive remediation.
GRC Operations & Improvement
- Maintain audit-ready documentation within GRC systems.
- Support team members as necessary with global and contractual compliance efforts, as well as internal and external audits.
- Contribute to security and compliance policy, process, and control improvements.
- Identify opportunities for automation, simplification, and improved GRC tooling.
What success looks like in the first 12 months:
- Strong audit readiness with high-quality, reliable technical evidence.
- Effective use of GRC tooling to automate and streamline compliance processes.
- Mature and efficient Third-Party Risk Management workflows.
- Improved turnaround times for vendor assessments and internal requests.
- Clear visibility of cybersecurity control effectiveness and risk posture.
- Reduced manual effort through automation and improved processes.
Requirements:
Essential
- 3+ years' experience in compliance, GRC, vendor risk management, information security, internal audit or related fields.
- Proven experience in cybersecurity and managing third-party/vendor due diligence programmes.
- Strong understanding of common assurance frameworks such as ISO 27001, SOC 2, NIST or equivalent.
- Good working knowledge of UK GDPR / privacy considerations in supplier relationships.
- Familiarity with cloud/SaaS environments and common systems (e.g. identity providers, cloud platforms, collaboration tools).
- Experience reviewing supplier security documentation and identifying practical risks.
- Strong organisational skills with the ability to manage multiple priorities independently.
- Excellent written and verbal communication skills; proficient in English.
Desirable
- SaaS / software industry experience.
- Experience in a multi-entity or fast-growth business environment.
- Familiarity with Vanta or other GRC tools.
- Relevant certifications (e.g. ISO 27001 Lead Implementer/Auditor, CISM, CRISC, CIPM, CIPP/E).
You are motivated by:
- Hustle: You inspire others to work as hard as you. You will find a way, no matter how hard the task is.
- Ownership: You have an owner/builder mentality. You care about what you deliver and own your mistakes.
- Proactivity: You don't wait for someone to tell you what to do or what problems to solve. You are always looking for ways to learn and improve.
- Excellence: You set a high bar and surpass expectations. You hit your goals and ask for more.
- Humility: You are not above any task in the organization and are willing to drop what you're doing to help a teammate.
What you can expect from us
The team:
Capacity team members enjoy the opportunity and benefits of working at an artificial intelligence startup, but with leaders who've worked at places like Apple, Ebay, Visa, Answers.com, Oracle, Boeing, and many more world-class companies. The culture at Capacity encourages innovation, independent problem solving, and collaboration as we continue to mature our product in the ever-changing world of AI.
We provide:
- Private health insurance
- Profit Interest Unit Appreciation Rights
- 25 days paid leave
- Pension
- Group life assurance
- Group income protection
- Flexible work environment
- A supportive, diverse workplace where we prioritize respect for each other and our clients
- A fun and collaborative team culture
Salary range:
- The expected base salary for the Technical GRC Specialist role is between £50,000 and £65,000; actual salary will be commensurate with a candidate's experience, skill and location.
Still unsure?
At Capacity we value more than just hard skills. Our goal is to build a holistic and diverse team. If you aren't sure if you qualify, just apply! We will carefully consider your application and are always grateful for any time and effort invested in Capacity.
But wait, there's more!
At Capacity we believe in more than just building amazing products and helping our customers. Although we are a remote workforce, we remember the neighborhood where we started. We still strive to elevate our community by furthering access to education and careers in the tech space. Our affiliated nonprofit, Create A Loop, brings rigorous computer science courses to underserved communities with little to no access to formal computer science education. There are many opportunities for our Capacity team members to serve and educate our Create A Loop students throughout the year.
- ...Overall 12+ years of experience on SAP GRC implementation, specifically: a. SAP GRC Risk Management b. SAP GRC Access Control c. SAP GRC Process Control and Fraud Management d. GRC reporting At least two full life cycle implementation...Suggested
- .... Preferred: Cyber Security is highly preferred. IT Manufacturing background is nice to have. Regulatory compliance/GRC not very important. Cares more about analytical skills + cyber security experience. Would have mention of the frameworks. Description...SuggestedH1bLocal area
- ...Job Description Insight Global is seeking a Senior IT GRC Specialist to join one of their clients in Dallas, Texas. The Sr. IT GRC Specialist... ...Privacy Policy: Skills and Requirements · Bachelor's or Technical Degree preferred (Computer Science, Information Systems,...Suggested
$130k - $150k
...Must Have Technical/Functional Skills The Business Systems Analyst (BSA) will have a strong understanding of risk management,... ...Risk, and Compliance (eGRC) platforms (e.g., Archer, ServiceNow GRC, MetricStream, or similar). This role will act as a bridge...Suggested- ...Location: Remote Reports to: GRC Manager Time commitment: minimum 20 hours weekly Headcount: 1 person Summary: We are... ...Risk, and Compliance (GRC) Analyst with a strong background in technical incident response. The ideal candidate will help build and mature...SuggestedRemote work
- ...Application Support Specialist (Information Security GRC Tool) We are looking for a colleague who can act both as a power user supporting expert... ...understanding user needs, structuring them, translating them into technical requirements, and ensuring effective collaboration with...Remote work
- A technology solutions company is seeking a Business System Analyst in Cleveland, OH. The role requires expertise in GRC and risk management, along with a solid understanding of Business Analyst and System Analyst responsibilities. Candidates should possess good SQL knowledge...Full time
- ...to keep our world moving forward. Job Description Senior GRC Analyst, Cybersecurity Frameworks We are seeking a Senior GRC... ...ability to drive results through effective engagement with senior technical and business leaders. ESSENTIAL DUTIES AND RESPONSIBILITIES:...Temporary workRemote workFlexible hoursShift work
- ...Overview Job Title – Business Analyst - Must Have GRC Exp is Required (Remote) Location - REMOTE Duration – 6+ Months Contract to Long Term Total Hours/week - 40.00 1st Shift Responsibilities Facilitating requirement gathering for the governance. Risk...Contract workRemote workDay shift
- ...What to Expect Tesla is looking for a GRC Senior System Analyst to join our Governance... ...for an Governance and Automation Specialist to embed agentic solutions into our governance... ...for efficiency. This role will bridge technical AI implementation with robust governance...Hourly payFull timeTemporary workFlexible hours
- Overview Senior GRC Analyst with deep, hands-on expertise in DoD and federal compliance programs, particularly CMMC 2.0 Level 2 and... ...and remediate gaps in collaboration with internal stakeholders. Technical Control Validation Partner with Engineering, CloudOps, and Security...
- ...Enterprise Risk Systems Administrator in Plano, Texas. This role is crucial for the administration of our Governance, Risk, and Compliance (GRC) systems. Responsibilities include optimizing risk platforms, conducting data analysis, and ensuring regulatory compliance....
- ...Location: Remote Reports to: GRC Manager Time commitment: minimum 20 hours weekly Summary: As we grow, the protection of our customers’ and clients’ data is paramount. We are looking for a skilled and proactive Governance, Risk, and Compliance (GRC) Analyst...Remote work
$96.56k - $124.96k
...Join Dorsey's Information Security team as a GRC Information Security Systems Analyst to help safeguard our firm and clients by driving high-impact security initiatives across audits, risk, governance, and compliance. Reporting directly to the Information Security Systems...Contract workTemporary workCurrently hiringWork at officeWorldwideFlexible hours- Mmc,-LLC- in Austin, Texas is looking for a GRC Data Analyst to oversee the company's compliance program, manage vendor risk, and automate evidence collection across various controls. As part of the Governance, Risk, and Compliance team, you will be responsible for maintaining...
- The Vanguard Group is seeking a Governance, Risk & Compliance Analyst, Specialist in Dallas, Texas. This role focuses on delivering GRC modernization initiatives, conducting risk assessments, and shaping security policies across the enterprise. The ideal candidate will...Visa sponsorship
- ...on role focuses on automating compliance workflows, data governance, and AI-driven automation. Key responsibilities include designing GRC workflows, building dashboards, and supporting data management. Required skills include 5 years in GRC compliance analysis, knowledge...
$111.6k - $124k
...Nuclear Training technology strategy. Clean Energy Center (CEC) specialist in curricula development activities involving the... ...department. Minimum Qualifications Bachelor's degree in a technical discipline, education, or training with 3 years of related experience...- Synchrony Financial is seeking a detail-oriented Sr. Business Analyst to join its GRC Risk Management Systems team in Boston, Massachusetts. This role involves advocating for GRC technology and working closely with various stakeholders to manage organizational risks effectively...
- ...the nation’s premier law firms, with more than 700 lawyers across the United States. Akerman is seeking an IT Technician - Technical Admin Specialist to be based in its Orlando, FL office. This is an onsite position. The IT Technician – Technical Admin Specialist is...Work at office
- ...hybrid opportunity based in Jersey City, NJ, supporting strategic GRC initiatives and ongoing business-as-usual compliance programs.... ...Microsoft Office skills, especially Excel, PowerPoint, and Word. ~ Technical aptitude with data models, databases, backend data uploads,...Work at office
- ...Senior Information Security Analyst with expertise in ServiceNow GRC. As a Senior Information Security Analyst you will be... ...Generalist Certifications: ~ ServiceNow Certified Implementation Specialist, - GRC (preferred) ~ Certified Information Systems Security Professional...
- ...Operational Support Specialist - GRC Onsite Location: Greenville, SC Pay rate: Hourly This is a full-time W2 position with no... ...ensuring software solutions meet end-user requirements. Produce technical documentation related to job bulletins, procedures, and...Hourly payFull timeTemporary workFor contractorsWork at officeLocal areaRemote work
- A leading staffing firm is seeking a GRC Analyst for a 100% remote opportunity. This role involves designing, implementing, and managing controls and risk workflows using AuditBoard while ensuring compliance with industry standards. The successful candidate will need over...Remote work
$89.6k - $194k
...SAP Application Security and GRC Analyst (Sr.) - U.S. Citizenship Required Category: ERP/CRM/Tools Main location: United States... ...processes. Success in this role will be achieved through your strong technical expertise, proactive problem‐solving abilities, and excellent...Full timeContract workWork at officeLocal area2 days per week$125k - $150k
...Titl e: IT Technical Specialist Location: Charlotte, NC (Hybrid) Position Type: Full Time Compensation Pay Range: $125,000-$150,000 Per Year Position Overview: Our Charlotte-based client is seeking a full-time IT Technical Specialist. This...Full timeRemote work- ...Tech Support Specialist (IT Helpdesk, SaaS Support, Zendesk/Jira) – Remote | U.S. Hours Position Type: Full-Time, Remote Working Hours... ...Tech Support Specialist to provide fast, clear, and effective technical support for customers and internal users. This role is...Full timeRemote work
- ...Technical Services IT Specialist Job no: 50000415 Work type: Full time Location: Virginia Beach Categories: Staff & Administration The Technical Services IT Specialist acts as the main liaison for all information technology support, including...Full timeTemporary workWork at officeFlexible hoursShift workNight shift
- ...Woodbridge, VA Work Shift First (Days) Overview: Sentara Northern Virginia Medical Center is hiring an IT Technical Support Specialist! Overview The IT Technical Support Specialist is a customer-facing role responsible for providing technical...Temporary workRemote workShift work
$27 - $29 per hour
...Technical Support Specialist Hourly Rate: $27.00 - $29.00/ Hr. Shifts Needed: Full time Monday-Friday Job Status: Full time Work Locations: Chino Hills, CA Redwood Family Care Network is an innovative leader in delivering person-centered home and community-based...Hourly payDaily paidFull timeWork experience placementRemote workWork from homeMonday to FridayShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Technical GRC Specialist. Be the first to apply!
- technical support associate United States
- decision support analyst United States
- desktop support analyst United States
- senior technical analyst United States
- technical data analyst United States
- user support analyst United States
- logistics support analyst United States
- customer support technician United States
- technical support analyst United States
- support analyst United States


