GRC Lead
Wordsmith
<p style="min-height:1.5em"><strong>GRC Lead</strong></p><p style="min-height:1.5em"><strong>Edinburgh</strong></p><p style="min-height:1.5em"><strong>Wordsmith</strong></p><p style="min-height:1.5em">Wordsmith is building the AI-enabled command centre for in-house legal teams.</p><p style="min-height:1.5em">Our customers are some of the most demanding enterprise legal departments in the world, and they hold us to a high bar on security, privacy, and responsible AI.</p><p style="min-height:1.5em">We're looking for a senior leader to take ownership of security and compliance as we scale.</p><p style="min-height:1.5em"><strong>The Role</strong></p><p style="min-height:1.5em">GRC Leads own security and compliance at Wordsmith end-to-end — setting the strategy for IT and infrastructure security, running our certification program across SOC 2, ISO 27001, and ISO 42001, embedding responsible-AI practices into how we build and ship product, and making sure privacy and regulatory obligations (GDPR and beyond) are handled properly as we grow.</p><p style="min-height:1.5em">This is a senior role that blends strategy and hands-on execution. You'll set multi-year direction, represent Wordsmith's security posture to executives, customers, and — as we grow — the board, and build the team, tooling, and controls the company needs at the next stage, not just maintain what exists today.</p><p style="min-height:1.5em"><strong>What You'll Do</strong></p><p style="min-height:1.5em"><strong>Security Strategy & Leadership</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Own Wordsmith's multi-year IT security and compliance roadmap — setting priorities, budget, and tooling decisions in partnership with Engineering and company leadership.</p></li></ul><p style="min-height:1.5em"><strong>IT & Infrastructure Security</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Own security architecture across corporate IT and infrastructure — identity & access management, endpoint protection, and cloud/network security — and lead incident response when issues arise.</p></li></ul><p style="min-height:1.5em"><strong>Compliance & Certification</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Own SOC 2 Type II, ISO 27001/27017/27018, and ISO 42001 end-to-end — policies, controls, audit evidence, and the audits themselves.</p></li></ul><p style="min-height:1.5em"><strong>AI Governance</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Run our AI governance program, including AI Impact Assessments and model/AI-vendor risk reviews, ensuring responsible, compliant AI use across the product.</p></li></ul><p style="min-height:1.5em"><strong>Privacy Operations</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Own privacy operations end-to-end — GDPR and other regulatory obligations, DPIAs, RoPA maintenance, sub-processor management, and Data Subject Request fulfilment.</p></li></ul><p style="min-height:1.5em"><strong>Third-Party & Vendor Risk</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Assess vendors and AI tools for security, privacy, and AI risk before they're adopted, and put the right contractual safeguards in place at a program level.</p></li></ul><p style="min-height:1.5em"><strong>Team & Function Building</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Build the people, process, and tooling the function needs as it scales — starting as the senior owner of the program today, with a mandate to build out a team as Wordsmith grows.</p></li></ul><p style="min-height:1.5em"><strong>Executive & Board Reporting</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Own risk and compliance reporting to leadership and, as we scale, the board — translating technical risk into business terms.</p></li></ul><p style="min-height:1.5em"><strong>Customer & Deal Support</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Act as the senior voice on security for enterprise deals — security questionnaires, DPAs, and our Trust Center — partnering with Sales, Customer Success, and Legal to unblock deals without cutting corners.</p></li></ul><p style="min-height:1.5em"><strong>Automation & Tooling</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Build lean, automation-first tooling (e.g. Vanta) for evidence collection and ongoing compliance monitoring, so the program scales without scaling headcount unnecessarily.</p></li></ul><p style="min-height:1.5em"><strong>What we're looking for</strong></p><p style="min-height:1.5em"><strong>Essential</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">8-10+ years in security, IT, or compliance roles, including a track record of owning a security or compliance function end-to-end at a fast-growing SaaS or tech company.</p></li><li><p style="min-height:1.5em">Proven experience building or scaling a security/compliance program from an early stage — ideally including time as the sole or founding owner of the function.</p></li><li><p style="min-height:1.5em">Deep, hands-on expertise across SOC 2, the ISO 27000 series, and ideally ISO 42001.</p></li><li><p style="min-height:1.5em">Strong grounding in core IT security fundamentals — identity & access management, endpoint/device security, and cloud or network infrastructure security.</p></li><li><p style="min-height:1.5em">Practical, working knowledge of GDPR and related privacy regulation (ePrivacy or similar).</p></li><li><p style="min-height:1.5em">Experience presenting security posture, risk, and roadmap to executives, boards, or investors.</p></li><li><p style="min-height:1.5em">Experience building and/or managing a team — or a clear point of view on how you'd grow one as the function scales.</p></li><li><p style="min-height:1.5em">Comfortable owning budget and vendor decisions at a strategic level, not just executing against someone else's plan.</p></li><li><p style="min-height:1.5em">A strong cross-functional operator and executive communicator, bridging Security, IT, Legal/Privacy, Engineering, and GTM.</p></li></ul><p style="min-height:1.5em"><strong>Valued</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Prior experience as a Head of Security, Director of Security/IT, or similar senior/leadership title.</p></li><li><p style="min-height:1.5em">Relevant certifications — e.g. CISSP/ISC2, CISM, AIGP, CIPP/E, CIPT, CCSK, or FIP.</p></li><li><p style="min-height:1.5em">Experience in legal tech, AI, or another highly regulated SaaS environment.</p></li><li><p style="min-height:1.5em">Experience designing AI risk or impact-assessment processes from scratch.</p></li><li><p style="min-height:1.5em">Familiarity with tools such as Datagrail, MineOS, Whistic, or SafeBase.</p></li></ul><p style="min-height:1.5em"><strong>Why this role matters</strong></p><p style="min-height:1.5em">You'll take a senior leadership seat over security and compliance, with real ownership over how the function is shaped and grown.</p><p style="min-height:1.5em">You'll sit at the centre of trust for a fast-growing legal AI platform, directly enabling enterprise sales and customer confidence.</p><p style="min-height:1.5em">You'll have a clear path to building and leading a team as the function scales with the company.</p><p style="min-height:1.5em"><strong>What you can expect</strong></p><p style="min-height:1.5em">A small, focused leadership group where your work has visible, immediate impact.</p><p style="min-height:1.5em">Competitive compensation, benefits, and meaningful equity.</p><p style="min-height:1.5em"><strong>How we work</strong></p><p style="min-height:1.5em">We're an in-office team in Edinburgh. We work together because it helps us collaborate closely across product, engineering, and legal teams. You should expect to be in the office as your default.</p><p style="min-height:1.5em">This is a high ownership role. You'll be trusted to set strategy, represent security to executives and customers, and drive outcomes without heavy oversight.</p><p>Find more <a href="https://www.arbeitnow.co.uk/english-speaking-jobs">English Speaking Jobs in United Kingdom</a> on Arbeitnow</a>