Posted onFeb 9, 2026
LocationEdinburgh, Scotland, United Kingdom (On-site)
Employment typeFull-time

Wood Mackenzie is the global leader in analytics, insights and proprietary data across the entire energy and natural resources landscape.


For over 50 years our work has guided the decisions of the world’s most influential energy producers, utilities companies, financial institutions and governments.


Now, with the world’s energy system more complex and interconnected than ever before, sector-specific views are no longer enough. That’s why we’ve redefined what’s possible with Intelligence Connected.


By fusing our unparalleled proprietary data with the sharpest analytical minds, all supercharged by Synoptic AI, we deliver a clear, interconnected view of the entire value chain. Our trusted team of 2,700 experts across 30 countries breaks siloes and connects industries, markets and regions across the globe.


This empowers our customers to identify risk sooner, spot opportunities faster and recalibrate strategy with confidence – whether planning days, weeks, months or decades ahead.


Wood Mackenzie
Intelligence Connected

WoodMac.com

Wood Mackenzie Brand Video

Wood Mackenzie Values

  • Inclusive – we succeed together
  • Trusting – we choose to trust each other
  • Customer committed – we put customers at the heart of our decisions
  • Future Focused – we accelerate change
  • Curious – we turn knowledge into action

Job Description

The role of the GRC Specialist is responsible for the day-to-day execution of governance, risk, and compliance (GRC) activities. This includes preparing for SOC and other audits, collecting and organizing evidence, responding to client/vendor security questionnaires, and maintaining the accuracy of the cyber risk register.

The role works closely with IT, Security Engineering, and business stakeholders to ensure audit requests and client inquiries are addressed promptly and consistently. The Specialist ensures that risks, exceptions, and remediation actions are logged and tracked to completion, providing a strong operational foundation for the Risk & Compliance program.

Key Responsibilities

Audit & Assurance Support:

  • Collect and organize evidence for SOC2 and other internal audits.
  • Track remediation items from audits, ensuring timely closure with responsible teams.
  • Maintain a repository of reusable audit evidence to streamline future cycles.
  • Support the Risk & Compliance Lead in responding to auditor and assessor queries.
  • Client & Vendor Security Questionnaires.
  • Coordinate responses to customer and third-party security questionnaires.
  • Collaborate with technical owners (Engineering, IT, Product) to provide accurate answers.
  • Maintain a knowledge base of pre-approved responses to accelerate RFPs and renewals.
  • Ensure responses are consistent with SOC2 reports and company policy.

Risk Register & Exception Management:

  • Update and maintain the cyber risk register in coordination with the Risk & Compliance Lead.
  • Record new risks, assign owners, and track remediation/progress.
  • Document Policy Exception Risk Acceptance (PERA) approvals and expirations.
  • Ensure risk data is kept current for reporting cycles.

Reporting & Metrics:

  • Contribute data for quarterly risk and compliance dashboards.
  • Provide metrics on questionnaire volumes, audit findings, and remediation timelines.
  • Highlight overdue risks, audit items, or exceptions to the Risk & Compliance Lead.

Experience & Skills

  • Experience in IT audit, compliance, or GRC operations.
  • Familiarity with audit frameworks (SOC2, ISO 27001, GDPR).
  • Strong organizational skills for evidence collection and tracking.
  • Ability to manage multiple concurrent requests and deadlines.
  • Clear written communication for client questionnaires and reports.
  • Experience in SaaS, data analytics, or regulated industries.
  • Exposure to vendor/supplier risk assessments.
  • Experience using GRC platforms (ServiceNow GRC, Archer, or equivalent).

Equal Opportunities

We are an equal opportunities employer. This means we are committed to recruiting the best people regardless of their race, colour, religion, age, sex, national origin, disability or protected veteran status. You can find out more about your rights under the law at www.eeoc.gov 

If you are applying for a role and have a physical or mental disability, we will support you with your application or through the hiring process.  

Wood Mackenzie Inc.

View company profile

Wood Mackenzie is the global leader in data, analytics and insights for the energy and natural resources industry, serving over 3,000 customers with real-time intelligence across the entire energy supply chain.

Similar jobs

You might also be interested in...

MO2w

InfoSec GRC Analyst

MoonPay

London, England, United Kingdom (Hybrid)

TC2d

Information Security GRC Analyst

Tgg Corporation

Liverpool, England, United Kingdom (Hybrid)

£40k – £45k Yearly

RS2w

Cyber security GRC Consultant (Genova, IT, 16129)

Rina S.p.A.

Genova, Genoa, Italy (On-site)

FI4d

Cybersecurity GRC Engineer

Fireblocks

Tel Aviv-Yafo, Tel Aviv District, Israel (On-site)

HP2w

Cybersecurity GRC Tool Analyst

Hewlett Packard Enterprise

Mississauga, Ontario, Canada (Hybrid)

C$114.3k – C$164.3k Yearly