Back to jobs
New

InfoSec GRC - 9 month FTC

London, Greater London, England, United Kingdom

Pantheon has been at the forefront of private markets investing for more than 40 years, earning a reputation for an innovative approach to investing in secondaries, co-investments, and primary fund investments, as well as capital formation across commingled funds, evergreen vehicles and customized solutions. Our specialist investment capabilities span multiple strategies across private equity, infrastructure and real assets, and private credit. Through our collaborative and committed culture, we find new ways to solve complex problems together and deliver innovative investment opportunities across private markets. Pantheon currently manages approximately $82.3 billion in AUM across all its strategies, serving more than 750 institutional and 638 private wealth clients worldwide

For further details please visit www.pantheon.com

Purpose of Position

This fixed-term role will provide practical delivery across Pantheon’s cyber and information-security governance, risk and compliance activities. A major priority will be to implement and build out Microsoft Purview Compliance Manager, starting with GDPR, DORA and ISO/IEC 27001, to identify control gaps, align ownership and evidence collection, and establish a sustainable compliance operating model and governed evidence repository. The role will also deliver core GRC activity across cyber-risk management in Resolver, supplier onboarding and assurance through Risk Ledger, third-party risk management, DDQ/ODD responses, audit and regulatory evidence, control testing, remediation tracking and management reporting. The role is intended to increase delivery capacity, improve the quality and reuse of evidence, and leave well-documented, sustainable processes at the end of the fixed term.

Key Responsibilities

  • Implement and build out Microsoft Purview Compliance Manager, beginning with GDPR, DORA and ISO/IEC 27001 and extending to other applicable regulations, standards and internal controls.
  • Configure assessments, scope organisational boundaries and services, map common controls, assign owners, record implementation and testing status, maintain evidence, and translate gaps into prioritised improvement actions with dates and closure criteria.
  • Design and build a governed SharePoint evidence repository with an agreed taxonomy, metadata, naming, versioning, access, retention, approval, review and evidence-validity model.
  • Map authoritative and reusable evidence to controls; identify missing, stale, duplicated or contradictory material; and rationalise collection for Compliance Manager, audits, regulatory requests, DDQs and ODDs.
  • Administer and develop cyber-risk records in Resolver, supporting consistent risk identification, assessment, ownership, treatment, acceptance, review, escalation and reporting, with a clear audit trail.
  • Support end-to-end third-party risk management, including supplier intake, inherent-risk triage, due diligence, Risk Ledger onboarding and administration, evidence review, findings, remediation, exceptions, periodic reassessment and offboarding.
  • Coordinate and draft accurate, consistent and client-ready responses to DDQs, ODDs, RFPs, audits and regulatory information requests, using approved sources and engaging Cyber, Risk, Privacy, Legal, Technology and business owners as required.
  • Perform control and compliance gap assessments, support control testing, maintain remediation plans, follow up overdue actions and verify evidence before closure.
  • Assess proportionate opportunities for automation, continuous monitoring and evidence reuse across Microsoft 365, Azure, Purview, security tooling and GRC platforms, while documenting activities requiring manual assessment.
  • Produce concise management information covering compliance status, material cyber risks, supplier-assurance progress, control gaps, overdue actions, evidence health, dependencies and remediation.
  • Document procedures, decisions, mappings, ownership and reporting cadences; train relevant users; and deliver a complete, usable handover so the capabilities remain sustainable after the FTC ends.

Knowledge & Experience Required 

  • Demonstrable hands-on Microsoft Purview Compliance Manager experience, including assessments, controls, improvement actions, ownership, implementation and testing status, evidence and reporting.
  • Broad practical GRC experience encompassing cyber-risk management, control assessment, remediation tracking, policy and standards activity, regulatory assurance and audit support.
  • Working knowledge of GDPR, DORA and ISO/IEC 27001, with the ability to translate obligations into controls, test procedures, evidence requirements and proportionate remediation.
  • Experience of third-party risk management, including supplier due diligence, security evidence review, findings, remediation, exceptions and lifecycle reassessment.
  • Experience completing or coordinating DDQs, ODDs, RFPs, audit requests or regulatory evidence submissions, with strong attention to accuracy, consistency and approval.
  • Strong evidence-management skills, including control libraries, SharePoint repositories, metadata, version control, access governance, review cycles, source validation and quality assurance.
  • Good working knowledge of Microsoft 365, Purview, Azure and security and compliance capabilities, with sound judgement about automation and manual assurance.
  • Clear written and verbal communication, with the ability to work effectively with Technology, Risk, Privacy, Legal, Procurement, Internal Audit, business owners and senior management.
  • Strong delivery discipline: able to manage a time-bound backlog, prioritise competing deadlines, maintain defensible records and leave complete documentation and a sustainable handover.

Desirable

  • Hands-on experience of Risk Ledger, Resolver or comparable GRC and third-party risk platforms.
  • Experience in regulated financial services, including DORA implementation, regulatory engagement, external assurance or ISO/IEC 27001 certification activity.
  • Experience migrating existing controls, risks, assessments and evidence, and creating custom assessment content where standard templates do not meet business needs.
  • Experience using Power Platform, Microsoft Graph, APIs or other appropriate methods to streamline evidence collection, workflow and reporting.

Fixed term deliverables 

  • First 30 days: confirm the prioritised GRC backlog, stakeholders and RACI; validate Compliance Manager licensing, templates and scope; establish a pilot assessment and evidence-repository design; and review current Resolver, Risk Ledger, TPRM and DDQ/ODD processes and outstanding work.
  • By 60 days: populate the agreed GDPR, DORA and ISO/IEC 27001 assessments; map common controls and available evidence; triage priority gaps; improve evidence quality; and deliver agreed cyber-risk, supplier-assurance and due-diligence actions.
  • By 90 days: operate control testing and review cycles; establish reporting and remediation governance; demonstrate improved Resolver and Risk Ledger data quality and workflow; and embed a repeatable, approved DDQ/ODD evidence process.
  • By the end of the FTC: deliver a functioning and governed Compliance Manager capability and evidence repository, demonstrable improvements across the wider GRC remit, trained owners and a complete handover pack.

This job description is not to be construed as an exhaustive statement of duties, responsibilities, or requirements. You may be required to perform other job-related duties as reasonably requested by your manager.

Pantheon is an Equal Opportunities employer, we are committed to building a diverse and inclusive workforce so if you're excited about this role but your past experience doesn't perfectly align we'd still encourage you to apply.

 

 

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...

Including last and expected bonus, and any other important to mention benefits

Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Pantheon Ventures Careers’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 07/31/2029

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.