InfoSec GRC - 9 month FTC

Pantheon Ventures Careers · London, Greater London, England, United Kingdom

  • Junior
  • Full-time
  • Posted 2026-09-02
  • Confirmed live on 25 September 2026

Apply at Pantheon Ventures Careers

Job description

Pantheon has been at the forefront of private markets investing for more than 40 years, earning a reputation for an innovative approach to investing in secondaries, co-investments, and primary fund investments, as well as capital formation across commingled funds, evergreen vehicles and customized solutions. Our specialist investment capabilities span multiple strategies across private equity, infrastructure and real assets, and private credit. Through our collaborative and committed culture, we find new ways to solve complex problems together and deliver innovative investment opportunities across private markets. Pantheon currently manages approximately $82.3 billion in AUM across all its strategies, serving more than 750 institutional and 638 private wealth clients worldwide

For further details please visit www.pantheon.com

Purpose of Position

This fixed-term role will provide practical delivery across Pantheon’s cyber and information-security governance, risk and compliance activities. A major priority will be to implement and build out Microsoft Purview Compliance Manager, starting with GDPR, DORA and ISO/IEC 27001, to identify control gaps, align ownership and evidence collection, and establish a sustainable compliance operating model and governed evidence repository. The role will also deliver core GRC activity across cyber-risk management in Resolver, supplier onboarding and assurance through Risk Ledger, third-party risk management, DDQ/ODD responses, audit and regulatory evidence, control testing, remediation tracking and management reporting. The role is intended to increase delivery capacity, improve the quality and reuse of evidence, and leave well-documented, sustainable processes at the end of the fixed term.

Key Responsibilities

• Implement and build out Microsoft Purview Compliance Manager, beginning with GDPR, DORA and ISO/IEC 27001 and extending to other applicable regulations, standards and internal controls.

• Configure assessments, scope organisational boundaries and services, map common controls, assign owners, record implementation and testing status, maintain evidence, and translate gaps into prioritised improvement actions with dates and closure criteria.

• Design and build a governed SharePoint evidence repository with an agreed taxonomy, metadata, naming, versioning, access, retention, approval, review and evidence-validity model.

• Map authoritative and reusable evidence to controls; identify missing, stale, duplicated or contradictory material; and rationalise collection for Compliance Manager, audits, regulatory requests, DDQs and ODDs.

• Administer and develop cyber-risk records in Resolver, supporting consistent risk identification, assessment, ownership, treatment, acceptance, review, escalation and reporting, with a clear audit trail.

• Support end-to-end third-party risk management, including supplier intake, inherent-risk triage, due diligence, Risk Ledger onboarding and administration, evidence review, findings, remediation, exceptions, periodic reassessment and offboarding.

• Coordinate and draft accurate, consistent and client-ready responses to DDQs, ODDs, RFPs, audits and regulatory information requests, using approved sources and engaging Cyber, Risk, Privacy, Legal, Technology and business owners as required.

• Perform control and compliance gap assessments, support control testing, maintain remediation plans, follow up overdue actions and verify evidence before closure.

• Assess proportionate opportunities for automation, continuous monitoring and evidence reuse across Microsoft 365, Azure, Purview, security tooling and GRC platforms, while documenting activities requiring manual assessment.

• Produce concise management information covering compliance status, material cyber risks, supplier-assurance progress, control gaps, overdue actions, evidence health, dependencies and remediation.

• Document procedures, decisions, mappings, ownership and reporting cadences; train relevant users; and deliver a complete, usable handover so the capabilities remain sustainable after the FTC ends.

Knowledge & Experience Required

• Demonstrable hands-on Microsoft Purview Compliance Manager experience, including assessments, controls, improvement actions, ownership, implementation and testing status, evidence and reporting.

• Broad practical GRC experience encompassing cyber-risk management, control assessment, remediation tracking, policy and standards activity, regulatory assurance and audit support.

• Working knowledge of GDPR, DORA and ISO/IEC 27001, with the ability to translate obligations into controls, test procedures, evidence requirements and proportionate remediation.

• Experience of third-party risk management, including supplier due diligence, security evidence review, findings, remediation, exceptions and lifecycle reassessment.

• Experience completing or coordinating DDQs, ODDs, RFPs, audit requests or regulatory evidence submissions, with strong

Prepare for the interview

Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.

More at Pantheon Ventures Careers

All open software jobs