GRC Consultant - Insurance - 6 Months - Outside iR35
MJA (London) Ltd
GRC Consultant – Third-Party Risk & Governance
Location: London (Hybrid) 2/3 days a week in the office
Day Rate - Outside iR35
The Opportunity
We are seeking an experienced Governance, Risk & Compliance (GRC) Consultant to join a leading insurance organisation. This role will focus on strengthening and maintaining the organisation's third-party governance framework, ensuring suppliers and business partners operate in line with regulatory requirements, internal policies, and security standards.
Working closely with Information Security, Procurement, Legal, Compliance, and business stakeholders, you will play a key role in assessing and managing third-party risk while driving continuous improvements across the GRC function.
Key Responsibilities
- Manage and enhance the third-party risk management framework.
- Conduct governance and risk assessments for suppliers and strategic partners.
- Review and maintain GRC policies, standards, and procedures.
- Ensure compliance with regulatory and industry frameworks relevant to the insurance sector.
- Coordinate supplier due diligence, onboarding, and ongoing risk reviews.
- Identify, assess, and track remediation activities for third-party risks.
- Produce risk reports, dashboards, and governance documentation for senior stakeholders.
- Support internal and external audits and regulatory requests.
- Work with business owners to ensure policy compliance across the organisation.
- Promote risk awareness and governance best practice throughout the business.
Skills & Experience
- Proven experience in a Governance, Risk & Compliance (GRC) role.
- Strong knowledge of third-party risk management and supplier assurance.
- Experience developing and maintaining GRC policies, standards, and governance frameworks.
- Understanding of information security and operational risk principles.
- Experience working within the insurance, financial services, or regulated sectors.
- Knowledge of recognised frameworks such as ISO 27001, NIST CSF, CIS Controls, COBIT, or similar.
- Familiarity with regulatory requirements including GDPR and operational resilience.
- Excellent stakeholder management and communication skills.
- Strong analytical and documentation skills.
- Experience using GRC platforms such as Archer, ServiceNow GRC, OneTrust, or similar is desirable.
Desirable Certifications
- ISO 27001 Lead Implementer or Lead Auditor
- Certified Information Systems Auditor (CISA)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Third Party Risk Professional (CTPRP) (desirable)
Application opens at the source listing. Free for jobseekers.