Rodeo
Get started

Mundipharma

IT GRC Specialist

Cambridge
Posted about 23 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

IT GRC Specialist

Location: Cambridge, Hybrid
Department: IT
Job type: Full Time

Join us and make a difference when it matters most! At Mundipharma, we are proud of the work we do to bring innovative treatments to patients. We challenge ourselves constantly to deliver more for patients, healthcare professionals, our partners, and our employees.

The Team

The IT Governance, Risk & Compliance (GRC) Specialist will join the IT team at Mundipharma ensuring the organisation understands its key risks and manages them appropriately in line with its risk appetite, while maintaining effective governance, controls, and oversight. Translating requirements into practical, proportionate controls embedded across business and technology processes, and ensures suitable evidence is maintained to demonstrate compliance and control effectiveness.

Role and Responsibilities

  • Lead the end-to-end IT risk management practice, ensuring legal obligations are met and enterprise risks are detailed, owned, mitigated, and clearly communicated to leadership.
  • AI Governance & Risk Management - Establish and oversee AI risk frameworks, ensuring the responsible, transparent, and compliant use of AI technologies across all organizational use cases.
  • Policy Framework & Governance: Maintain and review IT policies, partnering with department heads to identify documentation gaps, execute review cycles, and drive continuous policy improvement.
  • Conduct regular audits of internal IT processes to verify compliance with governance frameworks and implement structured remediation plans.
  • Act as the primary point of contact for internal and external IT audits, coordinating with system owners to deliver consistent responses while minimizing operational disruption.
  • Identify, track, and remediate potential audit risks and control weaknesses proactively to prevent formal audit findings.
  • Build and sustain strong working relationships with internal audit teams to ensure ongoing alignment between IT operations and enterprise governance goals.
  • Manage and administer IT governance, security, and policy training programs across IT and the wider business via the Global Learning Management System (LMS).
  • Support the development of engaging training content and deliver regular compliance reporting against key performance indicators.
  • Maintain macro- and micro-level risk reporting for IT leadership while collaborating with global training and compliance teams to adopt best practices.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

What you’ll bring

  • University or Master’s degree in IT (or related field), backed by proven experience managing risks within an IT organisation.
  • Previous experience in an IT Governance, Risk & Compliance (GRC) related position in the Pharmaceutical industry would be advantageous but other industries would be considered.
  • Deep understanding of audit operations and a track record of successfully managing responses to both internal and external audits.
  • Sound knowledge of core GRC practices and industry frameworks, such as ISO 27001, ISO 9001, ITIL, and COBIT.
  • Document & Quality Control - Expertise in quality management principles, policy governance, and administering Document Management Systems.
  • Experience using GRC platforms like Vanta (preferred) and creating SCORM-compliant training content with Articulate would be advantageous.
  • Practical experience implementing ITIL processes and collaborating directly with cybersecurity teams to mitigate risk.
  • Excellent negotiation and global stakeholder relationship-building skills with the ability to influence management-level stakeholders in a global environment.
  • Process-Driven Improvement: Strong process mindset with a proven ability to spot improvement opportunities and lead them through to completion.
  • Agile & Collaborative Mindset - Adaptable, solution-focused team player who enjoys learning new skills and driving a positive impact across the business.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

What we offer in return

  • Flexible benefits package
  • Opportunities for learning & development through our varied programme
  • Collaborative, inclusive work environment

Diversity and inclusion

Building an inclusive environment where people can thrive, grow and achieve their full potential is a priority. We believe this isn’t just the right thing, but also the smart thing to do. We are on a journey and will seek to move forward together through education and awareness to build a culture that welcomes and celebrates diversity and uniqueness. We will create a workplace environment where everyone can, every day, bring their authentic selves and is treated with dignity and respect.

About Mundipharma

Mundipharma is a global healthcare company focusing on customers across Africa, Asia Pacific, Canada, Europe, Latin America, and the Middle East. Mundipharma is dedicated to bringing innovative treatments to patients in the areas of pain management, infectious disease as well as other severe and debilitating disease areas. Their guiding principles, centered around Integrity and Patient-Centricity, are at the heart of everything they do. For more information visit www.mundipharma.com.

Join our talent pool

If you’re not sure this role is right for you but you’re keen to hear about future opportunities at Mundipharma, join our talent community and be the first to hear about new roles.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

IT Risk Management
AI Governance
Policy Framework Governance
Internal and External Auditing
ISO 27001
ISO 9001
ITIL
COBIT
Quality Management
Document Management Systems
Vanta
Articulate
Stakeholder Management
Compliance Reporting
Cybersecurity Risk Mitigation
Process Improvement

Location

Cambridge, England, United Kingdom

Sign up to applySee more jobs like this