Smarsh

Governance, Risk & Compliance - Lead

Belfast, Northern Ireland, United Kingdom

Not SpecifiedCompensation
Senior (5 to 8 years), Expert & Leadership (9+ years)Experience Level
Full TimeJob Type
UnknownVisa
Biotechnology, Information Services, Financial ServicesIndustries

GRC Lead

Employment Type: Full-Time

Position Overview

Smarsh is committed to embedding security as a business enabler. As a senior member of the GRC team, you will be instrumental in ensuring that our security governance, risk, and compliance efforts are integrated, scalable, and proactive. The GRC Lead plays a cross-functional leadership role, supporting the Senior Manager, GRC, and taking ownership of key programmes that span our ISMS, controls assurance, risk management, third-party oversight, and regulatory compliance. You’ll engage with stakeholders across InfoSec, Legal, Product, Engineering, and Customer teams to operationalise governance and build trust. This is a strategic yet hands-on role, ideal for someone who thrives in driving governance initiatives, facilitating risk discussions, and ensuring compliance readiness while working closely with Engineering, Security, and Product teams. You must be comfortable working as part of a global team in a dynamic, fast-paced environment. Collaboration across time zones and geographies is a key part of our culture and success.

Responsibilities

ISMS Governance & Controls Assurance

  • Lead the maintenance and continuous improvement of Smarsh’s ISO 27001-aligned ISMS.
  • Oversee the control assurance programme, ensuring robust evidence collection, control testing, and continuous monitoring.
  • Own key internal and external audit workstreams, including SOC 2, ISO 27001, FedRAMP and customer audits.

Cybersecurity Risk Management

  • Drive the risk assessment lifecycle, embedding business, technical, and supply chain risk perspectives.
  • Enhance risk methodologies and tools, integrating real-time risk metrics into dashboards and governance forums.
  • Support risk acceptance processes and facilitate cross-functional remediation plans.

Regulatory, Contractual & Client Assurance

  • Monitor emerging regulations (e.g. DORA, SEC, UK AI Act) and translate them into actionable internal obligations.
  • Manage customer security assessments and DDQs, enabling frictionless trust through reusable assurance artefacts.
  • Coordinate timely, high-quality client responses and external assurance artefacts.

Third-Party & Supply Chain Risk

  • Lead third-party security reviews and ensure governance controls are extended across the vendor lifecycle.
  • Partner with Procurement and Legal to align contractual security requirements and risk acceptance criteria.

Policy Governance & Stakeholder Reporting

  • Maintain the InfoSec policy lifecycle and track compliance across business units.
  • Develop and maintain security governance metrics and reporting for the CISO and wider executive team.
  • Support the operation of governance forums and steering committees.

Security Awareness & Culture

  • Deliver targeted security training and awareness campaigns aligned to regulatory and business needs.
  • Promote a security-aware culture of governance accountability and enablement across teams.

GRC Operations & Enablement

  • Own and refine core GRC workflows, including documentation, issue tracking, evidence management, and status reporting.
  • Maintain and expand GRC tooling integrations, ensuring high-quality automation and reporting outputs.

Requirements

  • 7–10 years’ experience in security governance, risk, or compliance roles within SaaS or regulated industries.
  • Strong track record operationalising ISMS frameworks, managing control assurance, and supporting audits.

Company Information

Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 6500 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in 80+ communication channels before those risks become regulatory fines or headlines. Relentless innovation has fueled our journey to consistent leadership recognition from analysts like Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 5000 list of fastest-growing American companies since 2008.

Skills

ISO 27001
ISMS
Risk Management
Compliance
Governance
Controls Assurance
Third-Party Risk Management
Regulatory Compliance
Information Security

Smarsh

Archiving and compliance solutions provider

About Smarsh

Smarsh provides archiving and compliance solutions specifically designed for financial services, government agencies, and other regulated industries. Their main product is a cloud-based archive that allows organizations to securely store, search, and manage their communications data, including emails, text messages, and social media interactions. This system helps businesses meet complex security, data privacy, and regulatory requirements. Smarsh differentiates itself from competitors by offering a scalable Software-as-a-Service (SaaS) model that caters to both large enterprises and smaller organizations, ensuring that clients can adapt to evolving regulations. Their goal is to help organizations efficiently manage their communication data, identify risks, and maintain compliance, particularly through tools like Connected Capture for Microsoft Teams, which supports remote workforces.

Portland, OregonHeadquarters
2001Year Founded
$42.4MTotal Funding
BUYOUTCompany Stage
Enterprise Software, Cybersecurity, Financial ServicesIndustries
1,001-5,000Employees

Benefits

Health Insurance
Dental Insurance
Life Insurance
Disability Insurance
Unlimited Paid Time Off
Paid Vacation
Paid Sick Leave
Paid Holidays
Hybrid Work Options
Stock Options
401(k) Company Match
Employee Assistance Programme
Wellness Program
Adoption Assistance
Group Income Protection
Group Life Assurance
Maternity Leave
Paternity Leave
Workplace Pension Scheme
Monthly Wellness Allowance
Company Bonus

Risks

Integration with OpenAI's API may pose compliance and security challenges.
EU's AI Act requires significant adjustments to Smarsh's AI systems.
Expansion into Latin America may expose Smarsh to regional instability.

Differentiation

Smarsh offers cloud-native, context-aware archiving solutions for regulated industries.
The company integrates with popular tools like Microsoft Teams for seamless compliance.
Smarsh serves 9 of the top 10 banks, showcasing its industry trust.

Upsides

Smarsh's global expansion includes a new office in Costa Rica for enhanced support.
Integration with OpenAI's ChatGPT API enhances Smarsh's AI compliance capabilities.
Partnership with Verizon simplifies mobile compliance procurement for Verizon's clients.

Land your dream remote job 3x faster with AI