GRC Audit & Assurance Consultant
Solutions Architecture, London
GRC Audit & Assurance Consultant
Solutions Architecture, London

The team you'll be working with:

The Lead GRC Consultant will lead and deliver governance, risk, compliance and assurance activities across a complex cyber security programme. The role combines structured GRC assessment with evidence-led assurance, control and process review, gap assessment, remediation planning and stakeholder engagement. The consultant will work across IT and OT environments, using frameworks such as the NCSC Cyber Assessment Framework (CAF) where applicable, while maintaining a broader focus on security governance, risk management, compliance and control effectiveness.

What you'll be doing:

Key Responsibilities

• Lead GRC assessment and assurance activities across the agreed programme scope, coordinating inputs from cyber security, risk, compliance, architecture, IT and OT stakeholders.

• Perform evidence-led assurance by reviewing policies, standards, procedures, technical artefacts, operational records, risk information and other supporting evidence to determine whether stated controls and practices are demonstrably implemented.

• Conduct structured gap assessments against agreed regulatory, contractual and security-framework requirements, including NCSC CAF/eCAF where applicable.

• Review and challenge customer self-assessments, control assertions and supporting rationale, identifying supported, partially supported, unsupported or contradictory positions.

• Assess governance arrangements, risk-management processes, control ownership, policy frameworks, assurance processes, evidence management and compliance reporting.

• Facilitate interviews, workshops, walkthroughs and challenge sessions with business, technical and operational stakeholders.

• Maintain clear traceability between requirements, controls, evidence, findings, risks, recommendations and remediation actions.

• Distinguish between control deficiencies and evidence deficiencies, and clearly document assessment limitations or areas requiring further validation.

• Develop evidence-based findings with clear criteria, observed condition, supporting evidence, risk/impact and proportionate recommendation.

• Assess control design and, where sufficient evidence is available, operating effectiveness and sustainability of controls.

• Consolidate assessment findings into maturity, gap and readiness views for senior stakeholders and programme governance.

• Develop prioritised remediation recommendations, target control outcomes and evidence requirements, and support remediation planning and tracking.

• Review remediation evidence and determine whether findings can be validated as addressed, partially addressed or remain open.

• Contribute to executive reporting, audit/readiness reporting, regulatory preparation and management briefings.

• Apply internal quality assurance and peer-review expectations to ensure conclusions are consistent, evidence-based and defensible.

Leadership Responsibilities

• Provide day-to-day leadership and direction to GRC assessors and supporting consultants.

• Allocate assessment areas and review working papers, evidence mapping, findings and scoring for consistency and quality.

• Establish a consistent assessment and evidence-evaluation approach across the team.

• Challenge unsupported conclusions and ensure professional judgements are evidence-based and clearly documented.

• Coordinate with technical specialists so relevant IT/OT findings are appropriately incorporated into GRC and compliance assessments.

• Escalate material evidence gaps, scope limitations, dependencies and risks through the agreed governance route.

• Present findings, maturity positions, risks and recommendations to customer SMEs, management and executives.

What experience you'll bring:

Essential Experience

• Current PriCSP (Audit) certification/accreditation is mandatory for this role.

Strong practical experience in cyber security governance, risk and compliance, assurance, audit or security maturity assessment.

• Demonstrable experience delivering structured gap assessments against recognised cyber security frameworks, standards or regulatory requirements.

• Experience with NCSC CAF/eCAF assessments or comparable control-based assurance frameworks.

• Strong evidence-assessment capability, including determining relevance, sufficiency, reliability, currency, consistency and traceability of evidence.

• Experience reviewing security policies, standards, procedures, risk registers, control evidence, architecture artefacts and operational records.

• Experience assessing control design and, where appropriate, control implementation and operating effectiveness.

• Strong stakeholder interviewing, workshop facilitation and challenge skills across technical, operational and senior-management audiences.

• Ability to write clear, defensible findings and recommendations suitable for executive, audit and regulatory audiences.

• Experience translating findings into prioritised remediation actions, control improvements and evidence requirements.

• Experience operating in complex environments spanning business, IT and/or OT stakeholders.

Desirable Experience

• Critical National Infrastructure, utilities, water, energy, transport, government or similarly regulated-sector experience.

• Experience supporting NIS compliance, regulatory submissions, audit readiness or formal assurance programmes.

• Experience conducting mock assessments, executive challenge sessions or independent quality reviews.

• Relevant certifications such as CISSP, CISM, CRISC, GICSP, ISO 27001 Lead Auditor/Lead Implementer or equivalent GRC/assurance qualifications.

Who we are:

At NTT DATA, you have endless opportunities to think big, act bold and take ownership. As a $30+ billion business and technology services, AI and digital infrastructure leader, we co-innovate solutions with clients and partners globally for business and societal impact. Serving 75% of the Fortune Global 100, with experts in over 70 countries, we encourage experimentation and recognize great work. Proudly a Global Top Employer, NTT DATA is part of NTT Group, which invests over $3 billion annually in R&D. Make this the place where you belong, learn, and build your network. Make this the place where you grow.

what we'll offer you:

We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensure that there are continuous growth and development opportunities for our people. We also offer the opportunity to have flexible work options.

You can find more information about NTT DATA UK & Ireland here: https://uk.nttdata.com/

We are an equal opportunities employer. We believe in the fair treatment of all our employees and commit to promoting equity and diversity in our employment practices. We are committed to creating a diverse and inclusive workforce. We actively collaborate with individuals who have disabilities and long-term health conditions which have an effect on their ability to do normal daily activities, ensuring that barriers are eliminated when it comes to employment opportunities. In line with our commitment, we guarantee an interview to applicants who declare to us, during the application process, that they have a disability and meet the minimum requirements for the role. If you require any reasonable adjustments during the recruitment process, please let us know. Join us in building a truly diverse and empowered team.

Back to search Email to a friend Apply now

Location
Epworth House, London

“Upon joining the NTT DATA UK family, you will experience a culturally diverse organisation living our values of Clients First, Teamwork and Foresight as we partner with our customers every day.

At NTT DATA UK, we are proud to support and invest in our people. We offer a variety of rewarding career paths and opportunities to develop professionally - with access to cutting edge innovation.”

Niccolo Spataro, CEO, NTT DATA UK

NTT DATA
#loveyourwork
Apply
Jobs at NTT DATA

Browse all