Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Technical GRC Specialist

£50k - £65k per year

Capacity

Software-as-a-Service (SaaS) Security Practitioner

Our mission at Capacity is to help teams do their best work through our AI-powered support automation platform. Capacity provides everything you need to automate support and business processes in one powerful omni-channel platform.

We believe that each individual voice, perspective and background brings inherent value to enhance our product, serve our customers and generate more ideas to solve complex problems. By continuing to hire talented, driven and humble teammates, we have the opportunity to see Capacity become a premier brand enterprise SaaS platform.

Capacity has raised over $100 million dollars from over 150 investors, giving us the opportunity to make ambitious investments in our team and big bets on our future. Our total addressable market is enormous. Any company that wants to grow revenue, reduce costs, and improve customer and employee satisfaction is an opportunity for Capacity to shine.

Why This Job Is Exciting

The role:

We are looking for an experienced software-as-a-service (SaaS) security practitioner to join our growing Governance, Risk & Compliance (GRC) team. This role will primarily take ownership of our security hardening standards and our Third-Party Risk Management (TPRM), focusing on proactive improvements in cybersecurity, ensuring audit readiness, and scaling GRC processes through automation.

This is a high-impact role suited to someone who wants to influence cybersecurity at scale, enjoys working cross-functionally, and is able to balance strong risk management with commercial pragmatism.

You will work closely with operational stakeholders across the organization, helping strengthen our overall security posture, including vendor assurance, while enabling the business to move safely and quickly.

Responsibilities

In this role, you will be responsible for the following:

Security Hardening & Technical GRC

  • Provide hands-on support in the assessment, improvement, and maintenance of technical security baselines based on industry best practices (e.g., NIST, CIS, ISO). You will ensure these configurations satisfy global regulatory mandates (e.g., HIPAA, GDPR).
  • Leverage automated tools to monitor security and compliance posture.
  • Act as a GRC interface with Infrastructure and Engineering teams to ensure hardening requirements are technically feasible and effectively implemented.

Third-Party Risk Management

  • Manage and continuously improve the company's Third-Party Risk Management programme across suppliers, vendors and strategic partners.
  • Own end-to-end due diligence processes for new and existing vendors, including inherent risk assessments, security/privacy reviews and ongoing monitoring.
  • Review vendor assurance documentation such as ISO 27001 certificates, SOC 2 reports, penetration test summaries, policies and compliance evidence.
  • Identify, document and communicate vendor risks, remediation actions and approval recommendations.
  • Maintain risk tiering and reassessment schedules for critical and high-risk vendors.
  • Act as a trusted partner to internal stakeholders during vendor onboarding, renewals and procurement decisions.
  • Engage directly with suppliers to resolve due diligence issues and drive remediation.

GRC Operations & Improvement

  • Maintain audit-ready documentation within GRC systems.
  • Support team members as necessary with global and contractual compliance efforts, as well as internal and external audits.
  • Contribute to security and compliance policy, process, and control improvements.
  • Identify opportunities for automation, simplification, and improved GRC tooling.

What success looks like in the first 12 months:

  • Strong audit readiness with high-quality, reliable technical evidence.
  • Effective use of GRC tooling to automate and streamline compliance processes.
  • Mature and efficient Third-Party Risk Management workflows.
  • Improved turnaround times for vendor assessments and internal requests.
  • Clear visibility of cybersecurity control effectiveness and risk posture.
  • Reduced manual effort through automation and improved processes.

Requirements:

Essential

  • 3+ years' experience in compliance, GRC, vendor risk management, information security, internal audit or related fields.
  • Proven experience in cybersecurity and managing third-party/vendor due diligence programmes.
  • Strong understanding of common assurance frameworks such as ISO 27001, SOC 2, NIST or equivalent.
  • Good working knowledge of UK GDPR / privacy considerations in supplier relationships.
  • Familiarity with cloud/SaaS environments and common systems (e.g. identity providers, cloud platforms, collaboration tools).
  • Experience reviewing supplier security documentation and identifying practical risks.
  • Strong organisational skills with the ability to manage multiple priorities independently.
  • Excellent written and verbal communication skills; proficient in English.

Desirable

  • SaaS / software industry experience.
  • Experience in a multi-entity or fast-growth business environment.
  • Familiarity with Vanta or other GRC tools.
  • Relevant certifications (e.g. ISO 27001 Lead Implementer/Auditor, CISM, CRISC, CIPM, CIPP/E).

You are motivated by:

  • Hustle: You inspire others to work as hard as you. You will find a way, no matter how hard the task is.
  • Ownership: You have an owner/builder mentality. You care about what you deliver and own your mistakes.
  • Proactivity: You don't wait for someone to tell you what to do or what problems to solve. You are always looking for ways to learn and improve.
  • Excellence: You set a high bar and surpass expectations. You hit your goals and ask for more.
  • Humility: You are not above any task in the organization and are willing to drop what you're doing to help a teammate.

What you can expect from us

The team:

Capacity team members enjoy the opportunity and benefits of working at an artificial intelligence startup, but with leaders who've worked at places like Apple, Ebay, Visa, Answers.com, Oracle, Boeing, and many more world-class companies. The culture at Capacity encourages innovation, independent problem solving, and collaboration as we continue to mature our product in the ever-changing world of AI.

We provide:

  • Private health insurance
  • Profit Interest Unit Appreciation Rights
  • 25 days paid leave
  • Pension
  • Group life assurance
  • Group income protection
  • Flexible work environment
  • A supportive, diverse workplace where we prioritize respect for each other and our clients
  • A fun and collaborative team culture

Salary range:

  • The expected base salary for the Technical GRC Specialist role is between £50,000 and £65,000; actual salary will be commensurate with a candidate's experience, skill and location.

Still unsure?

At Capacity we value more than just hard skills. Our goal is to build a holistic and diverse team. If you aren't sure if you qualify, just apply! We will carefully consider your application and are always grateful for any time and effort invested in Capacity.

But wait, there's more!

At Capacity we believe in more than just building amazing products and helping our customers. Although we are a remote workforce, we remember the neighborhood where we started. We still strive to elevate our community by furthering access to education and careers in the tech space. Our affiliated nonprofit, Create A Loop, brings rigorous computer science courses to underserved communities with little to no access to formal computer science education. There are many opportunities for our Capacity team members to serve and educate our Create A Loop students throughout the year.

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Technical GRC Specialist in United States vacancy
  •  ...Overall 12+ years of experience on SAP GRC implementation, specifically: a. SAP GRC Risk Management b. SAP GRC Access Control c. SAP GRC Process Control and Fraud Management d. GRC reporting At least two full life cycle implementation... 
    Suggested

    Rootshell Enterprise Technologies

    New York, NY
    1 day ago
  •  .... Preferred: Cyber Security is highly preferred. IT Manufacturing background is nice to have. Regulatory compliance/GRC not very important. Cares more about analytical skills + cyber security experience. Would have mention of the frameworks. Description... 
    Suggested
    H1b
    Local area

    ShiftCode Analytics

    Waukegan, IL
    3 days ago
  •  ...Job Description Insight Global is seeking a Senior IT GRC Specialist to join one of their clients in Dallas, Texas. The Sr. IT GRC Specialist...  ...Privacy Policy: Skills and Requirements · Bachelor's or Technical Degree preferred (Computer Science, Information Systems,... 
    Suggested

    Insight Global

    Dallas, TX
    4 days ago
  • $130k - $150k

     ...Must Have Technical/Functional Skills The Business Systems Analyst (BSA) will have a strong understanding of risk management,...  ...Risk, and Compliance (eGRC) platforms (e.g., Archer, ServiceNow GRC, MetricStream, or similar). This role will act as a bridge... 
    Suggested

    Tata Consultancy Services

    Plano, TX
    5 days ago
  •  ...Location: Remote Reports to: GRC Manager Time commitment: minimum 20 hours weekly Headcount: 1 person Summary: We are...  ...Risk, and Compliance (GRC) Analyst with a strong background in technical incident response. The ideal candidate will help build and mature... 
    Suggested
    Remote work

    Menzies Philanthropic Foundation

    Little Elm, TX
    5 days ago
  •  ...Application Support Specialist (Information Security GRC Tool) We are looking for a colleague who can act both as a power user supporting expert...  ...understanding user needs, structuring them, translating them into technical requirements, and ensuring effective collaboration with... 
    Remote work

    Deutsche Telekom IT Solutions

    United States
    3 days ago
  • A technology solutions company is seeking a Business System Analyst in Cleveland, OH. The role requires expertise in GRC and risk management, along with a solid understanding of Business Analyst and System Analyst responsibilities. Candidates should possess good SQL knowledge... 
    Full time

    E*Pro Inc

    Cleveland, OH
    3 days ago
  •  ...to keep our world moving forward. Job Description Senior GRC Analyst, Cybersecurity Frameworks We are seeking a Senior GRC...  ...ability to drive results through effective engagement with senior technical and business leaders. ESSENTIAL DUTIES AND RESPONSIBILITIES:... 
    Temporary work
    Remote work
    Flexible hours
    Shift work

    SanDisk

    Irvine, CA
    2 days ago
  •  ...Overview Job Title – Business Analyst - Must Have GRC Exp is Required (Remote) Location - REMOTE Duration – 6+ Months Contract to Long Term Total Hours/week - 40.00 1st Shift Responsibilities Facilitating requirement gathering for the governance. Risk... 
    Contract work
    Remote work
    Day shift

    MILLENNIUMSOFT

    Tempe, AZ
    9 days ago
  •  ...What to Expect Tesla is looking for a GRC Senior System Analyst to join our Governance...  ...for an Governance and Automation Specialist to embed agentic solutions into our governance...  ...for efficiency. This role will bridge technical AI implementation with robust governance... 
    Hourly pay
    Full time
    Temporary work
    Flexible hours

    Tesla

    Austin, TX
    4 days ago
  • Overview Senior GRC Analyst with deep, hands-on expertise in DoD and federal compliance programs, particularly CMMC 2.0 Level 2 and...  ...and remediate gaps in collaboration with internal stakeholders. Technical Control Validation Partner with Engineering, CloudOps, and Security... 

    Neier Inc.

    Houston, TX
    4 days ago
  •  ...Enterprise Risk Systems Administrator in Plano, Texas. This role is crucial for the administration of our Governance, Risk, and Compliance (GRC) systems. Responsibilities include optimizing risk platforms, conducting data analysis, and ensuring regulatory compliance.... 

    First United Bank and Trust

    Plano, TX
    3 days ago
  •  ...Location: Remote Reports to: GRC Manager Time commitment: minimum 20 hours weekly Summary: As we grow, the protection of our customers’ and clients’ data is paramount. We are looking for a skilled and proactive Governance, Risk, and Compliance (GRC) Analyst... 
    Remote work

    Menzies Philanthropic Foundation

    Little Elm, TX
    5 days ago
  • $96.56k - $124.96k

     ...Join Dorsey's Information Security team as a GRC Information Security Systems Analyst to help safeguard our firm and clients by driving high-impact security initiatives across audits, risk, governance, and compliance. Reporting directly to the Information Security Systems... 
    Contract work
    Temporary work
    Currently hiring
    Work at office
    Worldwide
    Flexible hours

    Dorsey & Whitney

    Minneapolis, MN
    3 days ago
  • Mmc,-LLC- in Austin, Texas is looking for a GRC Data Analyst to oversee the company's compliance program, manage vendor risk, and automate evidence collection across various controls. As part of the Governance, Risk, and Compliance team, you will be responsible for maintaining... 

    Mmc,-LLC-

    Austin, TX
    3 days ago
  • The Vanguard Group is seeking a Governance, Risk & Compliance Analyst, Specialist in Dallas, Texas. This role focuses on delivering GRC modernization initiatives, conducting risk assessments, and shaping security policies across the enterprise. The ideal candidate will... 
    Visa sponsorship

    The Vanguard Group

    Dallas, TX
    4 days ago
  •  ...on role focuses on automating compliance workflows, data governance, and AI-driven automation. Key responsibilities include designing GRC workflows, building dashboards, and supporting data management. Required skills include 5 years in GRC compliance analysis, knowledge... 

    Spectraforce Technologies

    San Francisco, CA
    3 days ago
  • $111.6k - $124k

     ...Nuclear Training technology strategy. Clean Energy Center (CEC) specialist in curricula development activities involving the...  ...department.   Minimum Qualifications   Bachelor's degree in a technical discipline, education, or training with 3 years of related experience... 

    Constellation Energy

    Pottstown, PA
    4 days ago
  • Synchrony Financial is seeking a detail-oriented Sr. Business Analyst to join its GRC Risk Management Systems team in Boston, Massachusetts. This role involves advocating for GRC technology and working closely with various stakeholders to manage organizational risks effectively... 

    Synchrony Financial

    Boston, MA
    2 days ago
  •  ...the nation’s premier law firms, with more than 700 lawyers across the United States. Akerman is seeking an IT Technician - Technical Admin Specialist to be based in its Orlando, FL office. This is an onsite position. The IT Technician – Technical Admin Specialist is... 
    Work at office

    Akerman

    Orlando, FL
    1 day ago
  •  ...hybrid opportunity based in Jersey City, NJ, supporting strategic GRC initiatives and ongoing business-as-usual compliance programs....  ...Microsoft Office skills, especially Excel, PowerPoint, and Word. ~ Technical aptitude with data models, databases, backend data uploads,... 
    Work at office

    Axiom Path

    Jersey City, NJ
    11 days ago
  •  ...Senior Information Security Analyst with expertise in ServiceNow GRC. As a Senior Information Security Analyst you will be...  ...Generalist Certifications: ~ ServiceNow Certified Implementation Specialist, - GRC (preferred) ~ Certified Information Systems Security Professional... 

    Insight Global

    Minneapolis, MN
    1 day ago
  •  ...Operational Support Specialist - GRC Onsite Location: Greenville, SC Pay rate: Hourly This is a full-time W2 position with no...  ...ensuring software solutions meet end-user requirements. Produce technical documentation related to job bulletins, procedures, and... 
    Hourly pay
    Full time
    Temporary work
    For contractors
    Work at office
    Local area
    Remote work

    DATASOFT TECHNOLOGIES

    Greenville, SC
    1 day ago
  • A leading staffing firm is seeking a GRC Analyst for a 100% remote opportunity. This role involves designing, implementing, and managing controls and risk workflows using AuditBoard while ensuring compliance with industry standards. The successful candidate will need over... 
    Remote work

    Vaco by Highspring

    Dallas, TX
    4 days ago
  • $89.6k - $194k

     ...SAP Application Security and GRC Analyst (Sr.) - U.S. Citizenship Required Category: ERP/CRM/Tools Main location: United States...  ...processes. Success in this role will be achieved through your strong technical expertise, proactive problem‐solving abilities, and excellent... 
    Full time
    Contract work
    Work at office
    Local area
    2 days per week

    CGI Technologies and Solutions, Inc.

    Lebanon, VA
    1 day ago
  • $125k - $150k

     ...Titl e: IT Technical Specialist Location: Charlotte, NC (Hybrid) Position Type: Full Time Compensation Pay Range: $125,000-$150,000 Per Year Position Overview: Our Charlotte-based client is seeking a full-time IT Technical Specialist. This... 
    Full time
    Remote work

    Mitchell Martin

    United States
    1 day ago
  •  ...Tech Support Specialist (IT Helpdesk, SaaS Support, Zendesk/Jira) – Remote | U.S. Hours Position Type: Full-Time, Remote Working Hours...  ...Tech Support Specialist to provide fast, clear, and effective technical support for customers and internal users. This role is... 
    Full time
    Remote work

    Pavago

    United States
    1 day ago
  •  ...Technical Services IT Specialist Job no: 50000415 Work type: Full time Location: Virginia Beach Categories: Staff & Administration The Technical Services IT Specialist acts as the main liaison for all information technology support, including... 
    Full time
    Temporary work
    Work at office
    Flexible hours
    Shift work
    Night shift

    Regent University

    Virginia Beach, VA
    5 days ago
  •  ...Woodbridge, VA Work Shift First (Days) Overview: Sentara Northern Virginia Medical Center is hiring an IT Technical Support Specialist! Overview The IT Technical Support Specialist is a customer-facing role responsible for providing technical... 
    Temporary work
    Remote work
    Shift work

    Sentara Healthcare

    Woodbridge, VA
    3 days ago
  • $27 - $29 per hour

     ...Technical Support Specialist Hourly Rate: $27.00 - $29.00/ Hr. Shifts Needed: Full time Monday-Friday Job Status: Full time Work Locations: Chino Hills, CA Redwood Family Care Network is an innovative leader in delivering person-centered home and community-based... 
    Hourly pay
    Daily paid
    Full time
    Work experience placement
    Remote work
    Work from home
    Monday to Friday
    Shift work

    CorePower Yoga

    Riverside, CA
    17 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Technical GRC Specialist. Be the first to apply!