Now recruiting reviewers

Join the Assessment Board and grade the next generation of GRC.

Assessment Board members review submissions made by mentees on the grcmentor application. You bring the practitioner judgement; we bring the workflow, the rubric and the candidates.

Remote & asynchronous NICE-aligned work roles 4–6 hrs per month
What the board does

Review real submissions, not exam papers

Mentees complete simulated enterprise engagements inside our application. Board members assess the evidence they produce against the rubric for their work role.

01

Assess submitted work

Policies, risk registers, audit workpapers, DPIAs and continuity plans, submitted through the platform queue.

02

Grade against the rubric

Score with anchored criteria, leave written feedback, and decide whether the mentee has met the standard for the role.

03

Keep the bar calibrated

Join periodic calibration sessions so grading stays consistent across reviewers and cohorts.

Open positions

Reviewer roles

Each reviewer role maps to a NICE work role. Apply for the one your day job qualifies you to judge.

Policy & Governance Analyst
OG-PLA-001
Drafts, reviews and publishes cybersecurity and data-privacy policy; owns the policy register and the governance document set.
Compliance Manager
OG-AUD-001
Owns regulatory obligations, control mapping and compliance status reporting; runs internal compliance assessments.
Information Security Auditor
OG-AUD-002
Plans and performs control testing; owns workpaper standards, evidence quality and audit readiness.
Cyber Risk Manager
OG-RIS-001
Owns the risk framework, scoring anchors, treatment decisions and the risk register review cycle.
Vendor / Third-Party Risk Analyst
OG-SCRM-001
Owns supplier assessment, sub-processor governance and third-party contractual security terms.
Business Continuity & Resilience Analyst
OG-MAP-001
Owns business impact analysis, RTO/RPO determination and ICT continuity documentation.
Security Awareness & Training Specialist
OG-CUR-001
Owns awareness content, delivery quality, knowledge assessment and training evidence.
Incident Response & Crisis Manager (GRC)
PD-IRM-001
Owns incident procedure design, exercise facilitation and post-incident learning.
Cybersecurity Program Manager
OG-PMA-001
Owns programme roadmaps, charters, resourcing and delivery governance.
Data Protection Officer
OG-PRI-001
Statutory privacy role; owns RoPA, DPIA disposition, lawful basis and supervisory-authority interface.

All positions are voluntary board appointments, reviewed every 12 months.

Application

Apply to join the board

Tell us who you are and which reviewer position you want. We verify your background against the work role, then invite you to a calibration walkthrough.

Minimum three years in the discipline you apply to review.
A LinkedIn profile we can match to your stated experience.
Capacity for roughly five submissions a month.

Enter your email above first.

We use these details only to assess your board application.