hirly

Wordsmith

GRC Lead

Edinburgh

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Wordsmith first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.6M live jobs from 190,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Lead / management
Country
GB
Work mode
On-site / unstated
First seen by hirly
11 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

GRC Lead

Edinburgh

Wordsmith

Wordsmith is building the AI-enabled command centre for in-house legal teams.

Our customers are some of the most demanding enterprise legal departments in the world, and they hold us to a high bar on security, privacy, and responsible AI.

We're looking for a senior leader to take ownership of security and compliance as we scale.

The Role

GRC Leads own security and compliance at Wordsmith end-to-end — setting the strategy for IT and infrastructure security, running our certification program across SOC 2, ISO 27001, and ISO 42001, embedding responsible-AI practices into how we build and ship product, and making sure privacy and regulatory obligations (GDPR and beyond) are handled properly as we grow.

This is a senior role that blends strategy and hands-on execution. You'll set multi-year direction, represent Wordsmith's security posture to executives, customers, and — as we grow — the board, and build the team, tooling, and controls the company needs at the next stage, not just maintain what exists today.

What You'll Do

Security Strategy & Leadership

Own Wordsmith's multi-year IT security and compliance roadmap — setting priorities, budget, and tooling decisions in partnership with Engineering and company leadership.

IT & Infrastructure Security

Own security architecture across corporate IT and infrastructure — identity & access management, endpoint protection, and cloud/network security — and lead incident response when issues arise.

Compliance & Certification

Own SOC 2 Type II, ISO 27001/27017/27018, and ISO 42001 end-to-end — policies, controls, audit evidence, and the audits themselves.

AI Governance

Run our AI governance program, including AI Impact Assessments and model/AI-vendor risk reviews, ensuring responsible, compliant AI use across the product.

Privacy Operations

Own privacy operations end-to-end — GDPR and other regulatory obligations, DPIAs, RoPA maintenance, sub-processor management, and Data Subject Request fulfilment.

Third-Party & Vendor Risk

Assess vendors and AI tools for security, privacy, and AI risk before they're adopted, and put the right contractual safeguards in place at a program level.

Team & Function Building

Build the people, process, and tooling the function needs as it scales — starting as the senior owner of the program today, with a mandate to build out a team as Wordsmith grows.

Executive & Board Reporting

Own risk and compliance reporting to leadership and, as we scale, the board — translating technical risk into business terms.

Customer & Deal Support

Act as the senior voice on security for enterprise deals — security questionnaires, DPAs, and our Trust Center — partnering with Sales, Customer Success, and Legal to unblock deals without cutting corners.

Automation & Tooling

Build lean, automation-first tooling (e.g. Vanta) for evidence collection and ongoing compliance monitoring, so the program scales without scaling headcount unnecessarily.

What we're looking for

Essential

8-10+ years in security, IT, or compliance roles, including a track record of owning a security or compliance function end-to-end at a fast-growing SaaS or tech company.

Proven experience building or scaling a security/compliance program from an early stage — ideally including time as the sole or founding owner of the function.

Deep, hands-on expertise across SOC 2, the ISO 27000 series, and ideally ISO 42001.

Strong grounding in core IT security fundamentals — identity & access management, endpoint/device security, and cloud or network infrastructure security.

Practical, working knowledge of GDPR and related privacy regulation (ePrivacy or similar).

Experience presenting security posture, risk, and roadmap to executives, boards, or investors.

Experience building and/or managing a team — or a clear point of view on how you'd grow one as the function scales.

Comfortable owning budget and vendor decisions at a strategic level, not just executing against someone else's plan.

A strong cross-functional operator and executive communicator, bridging Security, IT, Legal/Privacy, Engineering, and GTM.

Valued

Prior experience as a Head of Security, Director of Security/IT, or similar senior/leadership title.

Relevant certifications — e.g. CISSP/ISC2, CISM, AIGP, CIPP/E, CIPT, CCSK, or FIP.

Experience in legal tech, AI, or another highly regulated SaaS environment.

Experience designing AI risk or impact-assessment processes from scratch.

Familiarity with tools such as Datagrail, MineOS, Whistic, or SafeBase.

Why this role matters

You'll take a senior leadership seat over security and compliance, with real ownership over how the function is shaped and grown.

You'll sit at the centre of trust for a fast-growing legal AI platform, directly enabling enterprise sales and customer confidence.

You'll have a clear path to building and leading a team as the function scales with the company.

What you can expect

A small, focused leadership group where your work has visible, immediate impact.

Competitive compensation, benefits, and meaningful equity.

How we work

We're an in-office team in Edinburgh. We work together because it helps us collaborate closely across product, engineering, and legal teams. You should expect to be in the office as your default.

This is a high ownership role. You'll be trusted to set strategy, represent security to executives and customers, and drive outcomes without heavy oversight.

Original posting on Wordsmith's site ↗

Listed on hirly, a job board. hirly is not the employer: Wordsmith is hiring for this role.

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job