Skip to main content
Post your CV and find your next job on Indeed!

Business Risk Consultant jobs

Sort by: -
    • Provide advisory input into operational resilience, business continuity and third party risk management.
    • Facilitate risk workshops, control reviews and senior…
    • Make a real impact in cyber resilience by ensuring business continuity when it matters most.*.
    • Act as the primary liaison between business stakeholders, driving…
  • View similar jobs with this employer
    • Strong risk management experience, including operating effective risk management strategies, policy, and frameworks in an organisation.
    • Contribute to business development activities, including proposals and thought leadership.
    • Leads multidisciplinary teams and plays a key role in work winning,…
    • Significant experience in technically leading teams in the production of flood risk assessments and/or flood risk activity permits.
    • Peer reviewing survey reports released by consultants and broker risk engineering.
    • Advises the SBS Underwriting Team about client risks, risk quality and loss…
  • View similar jobs with this employer
    • We’ll build you up to managing a portfolio of (smaller) clients and assisting senior consultants to deliver advice to larger/more complex employers and trustees…
    • Reducing risk by providing transparency and guidance to the relevant businesses; and.
    • Third-Party and Supplier Risk: Ensuring risks are managed outside the…
    • Test recovery capabilities and highlight concentration or dependency risks.
    • Strong analytical and MI capability to identify trends and emerging risks.
  • View similar jobs with this employer
    • Translate the Europe BI business plan into actionable RC strategies that drive new business conversion, improved risk selection, loss reduction, customer…
    • Tailor our risk insights to specific senior stakeholders to ensure our risk reporting supports decision making and risk mitigation across BCG.
    • Leading risk identification workshops with project teams.
    • Maintaining and managing the project risk register.
    • Risk Manager - POSITION FULL TIME BASED IN CUMBRIA…
    • Provide direct risk management input to bids and proposals to secure new business.
    • Perform risk assurance checks to ensure the quality of project and programme…
    • Conduct independent assurance checks on Safety Case development, validating technical methods, evidence bases and the strength of arguments relating to…
  • View similar jobs with this employer
    • We use deterministic and probabilistic techniques to help our clients to assess the risk associated with facilities and activities and confirm that risks are…

Job Post Details

Governance, Risk & Compliance Consultant - job post

Sword Group
3.3 out of 5 stars
GlasgowHybrid work
Full-time
Responded to 75% or more applications in the past 30 days, typically within 1 day.

Job details

Job type

  • Full-time

Location

GlasgowHybrid work

Benefits

Pulled from the full job description

  • Annual leave
  • Company pension

Full job description

Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, dedicated to driving transformational change for our clients. We leverage proven technology, specialist teams, and extensive domain expertise to create robust technical foundations across platforms, data, and business applications. Our mission is fueled by a passion for technology as a means to solve complex business problems and achieve our clients' objectives.

About the Role:

As a GRC Consultant, you will advise and support our clients across governance, risk management and regulatory compliance. The role focuses on aligning cyber, information security, operational resilience and wider risk frameworks to UK‑specific regulatory, safety and operational requirements.

You will work closely with client stakeholders to assess maturity, design and implement control frameworks, and provide pragmatic, risk‑based guidance that supports safe, secure and resilient operations.

Deliver governance, risk and compliance consulting engagements for a variety of clients and industries, including UK Oil & Gas (operators, service companies and joint ventures). CNI, Finance and Public Sector

  • Lead or support GRC maturity assessments, gap analyses and audits against relevant standards and regulations
  • Interpret and apply UK specific regulatory requirements, translating them into practical, implementable controls
  • Design and implement GRC frameworks covering risk management, policy, assurance and reporting
  • Support compliance activities aligned to various regulations and assurance requirements
  • Develop and maintain risk registers, control libraries and assurance plans
  • Facilitate risk workshops, control reviews and senior stakeholder briefings
  • Support cyber and information security governance aligned to ISO 27001, NCSC guidance and sector best practice
  • Provide advisory input into operational resilience, business continuity and third party risk management
  • Produce clear, evidence based client deliverables including reports, executive summaries and remediation roadmaps
  • Support pre audit, regulatory inspection and client assurance activities

Requirements


Essential

  • Good experience and background of producing high quality documentation and solution artefacts
  • Proven experience in Governance, Risk and Compliance roles within regulated or critical infrastructure environments
  • Strong understanding of the UK Oil & Gas and finance regulatory landscape
  • Working knowledge of key frameworks and standards, such as:
    • ISO/IEC 27001
    • ISO 22301 (Business Continuity)
    • UK NIS Regulations and NCSC guidance
    • NIST CSF
    • UK GDPR
    • Data Protection Act
    • DORA
  • Experience conducting risk assessments, control gap analyses and assurance activities
  • Proven ability to drive adoption, stakeholder buy-in and embedding change
  • Strong background in end-end to delivery (from design to implementation and embedding)
  • Ability to engage confidently with technical, operational and executive stakeholders
  • Strong written communication skills with experience producing client facing reports
  • Strong ability to translate technical and GRC concepts into clear, business-friendly language
  • Experience working in consulting or advisory environments

Desirable / Valuable

  • Knowledge of:
    • IEC 62443 for OT/ICS security
    • Operational Technology (OT) and industrial control environments
  • Familiarity with NCSC Cyber Assessment Framework (CAF) or sector‑specific assurance models
  • Experience supporting regulatory audits (HSE, NIS competent authority, client audits)

Certifications such as:

  • ISO 27001 Lead Implementer / Lead Auditor
  • CISM, CRISC or CISSP
  • IRM or ISO risk management qualifications
  • Understanding of supply‑chain and third‑party risk in Oil & Gas, CNI and finance ecosystems
  • Familiarity with GRC tooling such as OneTrust or Archer
  • Ability to contribute to business development or service offering development

Benefits


At Sword, our core values and culture are based on caring about our people, investing in training and career development, and building inclusive teams where we are all encouraged to contribute to achieve success. We offer comprehensive benefits designed to support your professional development and enhance your overall quality of life. In addition to a Competitive Salary, here's what you can expect as part of our benefits package:

  • Personalised Career Development: We create a development plan customised to your goals and aspirations, with a range of learning and development opportunities within a culture that encourages growth.
  • Flexible working: Flexible work arrangements to support your work-life balance. We can’t promise to always be able to meet every request, however, are keen to discuss your individual preferences to make it work where we can.
  • A Fantastic Benefits Package: This includes generous annual leave allowance, enhanced family friendly benefits, pension scheme, access to private health, well-being, and insurance schemes.

At Sword we are dedicated to fostering a diverse and inclusive workplace and are proud to be an equal opportunities employer, ensuring that all applicants receive fair and equal consideration for employment, regardless of whether they meet every requirement. If you don’t tick all the boxes but feel you have some of the relevant skills and experience we’re looking for, please do consider applying and highlight your transferable skills and experience. We embrace diversity in all its forms, valuing individuals regardless of age, disability, gender identity or reassignment, marital or civil partner status, pregnancy or maternity status, race, colour, nationality, ethnic or national origin, religion or belief, sex, or sexual orientation. Your perspective and potential are important to us.

If we can do anything to help make the hiring process more accessible, please let our talent acquisition team know when you apply so we can support any adjustments.

Let Employers Find YouUpload Your Resume