386,757open jobs
10,104companies
50,651added this week
Browse all
Salary
$93k – $183k per year (Estimated)
Location
In office (Edinburgh)
Seniority
Staff · 10+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Wordsmith. Welcome to Wordsmith, the home of:.

GRC Lead

Edinburgh

Wordsmith

Wordsmith is building the AI-enabled command centre for in-house legal teams.

Our customers are some of the most demanding enterprise legal departments in the world, and they hold us to a high bar on security, privacy, and responsible AI.

We're looking for a senior leader to take ownership of security and compliance as we scale.

The Role

GRC Leads own security and compliance at Wordsmith end-to-end - setting the strategy for IT and infrastructure security, running our certification program across SOC 2, ISO 27001, and ISO 42001, embedding responsible-AI practices into how we build and ship product, and making sure privacy and regulatory obligations (GDPR and beyond) are handled properly as we grow.

This is a senior role that blends strategy and hands-on execution. You'll set multi-year direction, represent Wordsmith's security posture to executives, customers, and - as we grow - the board, and build the team, tooling, and controls the company needs at the next stage, not just maintain what exists today.

What You'll Do

Security Strategy & Leadership

  • Own Wordsmith's multi-year IT security and compliance roadmap - setting priorities, budget, and tooling decisions in partnership with Engineering and company leadership.

IT & Infrastructure Security

  • Own security architecture across corporate IT and infrastructure - identity & access management, endpoint protection, and cloud/network security - and lead incident response when issues arise.

Compliance & Certification

  • Own SOC 2 Type II, ISO 27001/27017/27018, and ISO 42001 end-to-end - policies, controls, audit evidence, and the audits themselves.

AI Governance

  • Run our AI governance program, including AI Impact Assessments and model/AI-vendor risk reviews, ensuring responsible, compliant AI use across the product.

Privacy Operations

  • Own privacy operations end-to-end - GDPR and other regulatory obligations, DPIAs, RoPA maintenance, sub-processor management, and Data Subject Request fulfilment.

Third-Party & Vendor Risk

  • Assess vendors and AI tools for security, privacy, and AI risk before they're adopted, and put the right contractual safeguards in place at a program level.

Team & Function Building

  • Build the people, process, and tooling the function needs as it scales - starting as the senior owner of the program today, with a mandate to build out a team as Wordsmith grows.

Executive & Board Reporting

  • Own risk and compliance reporting to leadership and, as we scale, the board - translating technical risk into business terms.

Customer & Deal Support

  • Act as the senior voice on security for enterprise deals - security questionnaires, DPAs, and our Trust Center - partnering with Sales, Customer Success, and Legal to unblock deals without cutting corners.

Automation & Tooling

  • Build lean, automation-first tooling (e.g. Vanta) for evidence collection and ongoing compliance monitoring, so the program scales without scaling headcount unnecessarily.

What we're looking for

Essential

  • 8-10+ years in security, IT, or compliance roles, including a track record of owning a security or compliance function end-to-end at a fast-growing SaaS or tech company.

  • Proven experience building or scaling a security/compliance program from an early stage - ideally including time as the sole or founding owner of the function.

  • Deep, hands-on expertise across SOC 2, the ISO 27000 series, and ideally ISO 42001.

  • Strong grounding in core IT security fundamentals - identity & access management, endpoint/device security, and cloud or network infrastructure security.

  • Practical, working knowledge of GDPR and related privacy regulation (ePrivacy or similar).

  • Experience presenting security posture, risk, and roadmap to executives, boards, or investors.

  • Experience building and/or managing a team - or a clear point of view on how you'd grow one as the function scales.

  • Comfortable owning budget and vendor decisions at a strategic level, not just executing against someone else's plan.

  • A strong cross-functional operator and executive communicator, bridging Security, IT, Legal/Privacy, Engineering, and GTM.

Valued

  • Prior experience as a Head of Security, Director of Security/IT, or similar senior/leadership title.

  • Relevant certifications - e.g. CISSP/ISC2, CISM, AIGP, CIPP/E, CIPT, CCSK, or FIP.

  • Experience in legal tech, AI, or another highly regulated SaaS environment.

  • Experience designing AI risk or impact-assessment processes from scratch.

  • Familiarity with tools such as Datagrail, MineOS, Whistic, or SafeBase.

Why this role matters

You'll take a senior leadership seat over security and compliance, with real ownership over how the function is shaped and grown.

You'll sit at the centre of trust for a fast-growing legal AI platform, directly enabling enterprise sales and customer confidence.

You'll have a clear path to building and leading a team as the function scales with the company.

What you can expect

A small, focused leadership group where your work has visible, immediate impact.

Competitive compensation, benefits, and meaningful equity.

How we work

We're an in-office team in Edinburgh. We work together because it helps us collaborate closely across product, engineering, and legal teams. You should expect to be in the office as your default.

This is a high ownership role. You'll be trusted to set strategy, represent security to executives and customers, and drive outcomes without heavy oversight.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
386,757 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Edinburgh
In office • Contractor • 15+ years exp • Lviv
Java
Python
Scala
TypeScript
AI/ML
Claude
Cursor
LLM
DevOps
AWS
CI/CD
Cybersecurity
GDPR
HIPAA
SOC 2
Analytics
ETL/ELT
Apply
Lead DevOps Engineer 5 hours ago
$29k – $70k per year (Estimated) • In office • 6+ years exp • Bengaluru
AI/ML
AWS Bedrock
Deepgram
ElevenLabs
Gemini
LiveKit
LLM
Speech Recognition
Text-to-Speech
TPU
Vertex AI
Whisper
Mobile
Twilio
DevOps
Amazon CloudWatch
Amazon EC2
Amazon EKS
AWS
Azure
Azure AKS
CI/CD
CloudFormation
Datadog
Docker
FinOps
GCP
GitHub
GitHub Actions
GitLab
GitLab CI
Google GKE
Grafana
gRPC
Helm
IAM
Istio
Kubernetes
Linkerd
Pulumi
Self-Healing
Service Mesh
Terraform
WebRTC
WebSockets
Cybersecurity
ISO 27001
SOC 2
Zero Trust
Analytics
A/B Testing
Cryptography
Vault
Apply
$22k – $46k per year (Estimated) • In office • Full-Time • 5+ years exp • Gurgaon
Python
SQL
Databases
Databricks
Cybersecurity
GDPR
HIPAA
Analytics
Power BI
Apply
$45k – $117k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Veghel
Cybersecurity
ISO 27001
Apply
$214k per year • Remote/Hybrid • Full-Time • 3+ years exp • High School Diploma • Irving
Cybersecurity
GDPR
Apply
Support Engineer 1 month ago
$44k – $99k per year (Estimated) • In office • Full-Time • Edinburgh
AI/ML
AI Agents
Apply
Product Manager 2 months ago
$90k – $202k per year (Estimated) • Remote/Hybrid • Full-Time • Edinburgh • London
AI/ML
Claude
Claude Code
Apply
$77k – $150k per year (Estimated) • In office • Full-Time • 5+ years exp • Edinburgh • London
Python
SQL
AI/ML
AI Agents
Hallucination
LLM
Analytics
A/B Testing
Apply
Product Designer 4 months ago
$86k – $189k per year (Estimated) • In office • Full-Time • Edinburgh • London
TypeScript
AI/ML
AI Agents
Apply
$45k – $136k per year (Estimated) • In office • Full-Time • 3+ years exp • London • Edinburgh
JavaScript
AI/ML
AI Agents
Frontend
GSAP
Mobile
Lottie
Design
Adobe After Effects
Blender
Canva
Cinema 4D
Figma
Rive
Apply
$94k – $201k per year (Estimated) • In office • Contractor • Edinburgh
AI/ML
AI Agents
ChatGPT
Apply
$55k – $61k per year • Remote/Hybrid • Full-Time • 2+ years exp • Dundee • Edinburgh
Game Dev
Unity
Design
Adobe XD
Figma
Rive
Apply
$132k – $237k per year (Estimated) • Remote/Hybrid • Full-Time • Houston • Edinburgh • London • Boston • Gurgaon
Databases
Snowflake
DevOps
AWS
Marketing
Amplitude
Apply
$72k – $135k per year (Estimated) • Remote/Hybrid • Full-Time • London • Edinburgh
Python
SQL
Apply
$125k – $147k per year • Remote/Hybrid • Full-Time • Edinburgh
DevOps
API Gateway
GCP
Kong
Apply
See all jobs
This is one of many
386,757 more open roles from verified company boards, updated every day.