Rodeo
Get started

NTT DATA

GRC Audit & Assurance Consultant

London
Posted about 20 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

GRC Audit & Assurance Consultant

Hybrid Variable - London or Birmingham or Glasgow

Role Type

Senior GRC / Cyber Assurance Consultant

Focus

Governance, risk, compliance, gap assessment and evidence-led assurance

Role Purpose

The Lead GRC Consultant will lead and deliver governance, risk, compliance and assurance activities across a complex cyber security programme. The role combines structured GRC assessment with evidence-led assurance, control and process review, gap assessment, remediation planning and stakeholder engagement. The consultant will work across IT and OT environments, using frameworks such as the NCSC Cyber Assessment Framework (CAF) where applicable, while maintaining a broader focus on security governance, risk management, compliance and control effectiveness.

What you'll be doing

  • Lead GRC assessment and assurance activities across the agreed programme scope, coordinating inputs from cyber security, risk, compliance, architecture, IT and OT stakeholders.
  • Perform evidence-led assurance by reviewing policies, standards, procedures, technical artefacts, operational records, risk information and other supporting evidence to determine whether stated controls and practices are demonstrably implemented.
  • Conduct structured gap assessments against agreed regulatory, contractual and security-framework requirements, including NCSC CAF/eCAF where applicable.
  • Review and challenge customer self-assessments, control assertions and supporting rationale, identifying supported, partially supported, unsupported or contradictory positions.
  • Assess governance arrangements, risk-management processes, control ownership, policy frameworks, assurance processes, evidence management and compliance reporting.
  • Facilitate interviews, workshops, walkthroughs and challenge sessions with business, technical and operational stakeholders.
  • Maintain clear traceability between requirements, controls, evidence, findings, risks, recommendations and remediation actions.
  • Distinguish between control deficiencies and evidence deficiencies, and clearly document assessment limitations or areas requiring further validation.
  • Develop evidence-based findings with clear criteria, observed condition, supporting evidence, risk/impact and proportionate recommendation.
  • Assess control design and, where sufficient evidence is available, operating effectiveness and sustainability of controls.
  • Consolidate assessment findings into maturity, gap and readiness views for senior stakeholders and programme governance.
  • Develop prioritised remediation recommendations, target control outcomes and evidence requirements, and support remediation planning and tracking.
  • Review remediation evidence and determine whether findings can be validated as addressed, partially addressed or remain open.
  • Contribute to executive reporting, audit/readiness reporting, regulatory preparation and management briefings.
  • Apply internal quality assurance and peer-review expectations to ensure conclusions are consistent, evidence-based and defensible.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Leadership Responsibilities

  • Provide day-to-day leadership and direction to GRC assessors and supporting consultants.
  • Allocate assessment areas and review working papers, evidence mapping, findings and scoring for consistency and quality.
  • Establish a consistent assessment and evidence-evaluation approach across the team.
  • Challenge unsupported conclusions and ensure professional judgements are evidence-based and clearly documented.
  • Coordinate with technical specialists so relevant IT/OT findings are appropriately incorporated into GRC and compliance assessments.
  • Escalate material evidence gaps, scope limitations, dependencies and risks through the agreed governance route.
  • Present findings, maturity positions, risks and recommendations to customer SMEs, management and executives.

What you'll bring

  • Current PriCSP (Audit) certification/accreditation is mandatory for this role.
  • Strong practical experience in cyber security governance, risk and compliance, assurance, audit or security maturity assessment.
  • Demonstrable experience delivering structured gap assessments against recognised cyber security frameworks, standards or regulatory requirements.
  • Experience with NCSC CAF/eCAF assessments or comparable control-based assurance frameworks.
  • Strong evidence-assessment capability, including determining relevance, sufficiency, reliability, currency, consistency and traceability of evidence.
  • Experience reviewing security policies, standards, procedures, risk registers, control evidence, architecture artefacts and operational records.
  • Experience assessing control design and, where appropriate, control implementation and operating effectiveness.
  • Strong stakeholder interviewing, workshop facilitation and challenge skills across technical, operational and senior-management audiences.
  • Ability to write clear, defensible findings and recommendations suitable for executive, audit and regulatory audiences.
  • Experience translating findings into prioritised remediation actions, control improvements and evidence requirements.
  • Experience operating in complex environments spanning business, IT and/or OT stakeholders.

Desirable Experience

  • Critical National Infrastructure, utilities, water, energy, transport, government or similarly regulated-sector experience.
  • Experience supporting NIS compliance, regulatory submissions, audit readiness or formal assurance programmes.
  • Experience conducting mock assessments, executive challenge sessions or independent quality reviews.
  • Relevant certifications such as CISSP, CISM, CRISC, GICSP, ISO 27001 Lead Auditor/Lead Implementer or equivalent GRC/assurance qua

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

We also work within Public Sector clients where UK Gov. Defence Vetting to such as SC is required, as such you hold or be eligible to hold UK Gov vetting. A valid right to work in the UK.

Our inclusive work environment

Our inclusive work environment prioritises mutual respect, accountability, and continuous learning for all our people. This approach fosters collaboration, well-being, growth, and agility, leading to a more diverse, innovative, and competitive organisation. We are also proud to share that we have a range of Inclusion Networks such as: the Women’s Business Network, Cultural and Ethnicity Network, LGBTQ+ & Allies Network, Neurodiversity Network and the Parent Network.

For more information on Diversity, Equity and Inclusion please click here: Creating Inclusion Together at NTT DATA UK | NTT DATA

Benefits

We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensure that there are continuous growth and development opportunities for our people. We also offer the opportunity to have flexible work options.

You can find more information about NTT DATA UK & Ireland here: NTT DATA UK & Ireland

Equal Opportunities Employer

We are an equal opportunities employer. We believe in the fair treatment of all our employees and commit to promoting equity and diversity in our employment practices. We are also a proud Disability Confident Committed Employer - we are committed to creating a diverse and inclusive workforce. We actively collaborate with individuals who have disabilities and long-term health conditions which have an effect on their ability to do normal daily activities, ensuring that barriers are eliminated when it comes to employment opportunities. In line with our commitment, we guarantee an interview to applicants who declare to us, during the application process, that they have a disability and meet the minimum requirements for the role. If you require any reasonable adjustments during the recruitment process, please let us know. Join us in building a truly diverse and empowered team.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

London, England, United Kingdom

Sign up to applySee more jobs like this