GRC Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The GRC Analyst (Technology and Cyber Risk) will sit within the second line of defence and is responsible for assisting the Cyber Risk Lead in identifying, assessing, and monitoring cyber and technology-related risks across key JD systems, applications, cloud environments, and third-party services. This role requires collaboration with IT, information security, internal audit, and business stakeholders to ensure technology and cyber risks are effectively managed and aligned with regulatory requirements and industry best practices across JD Sports., Technology and Cyber Risk Management
- Identify, assess, and document technology and cyber risks across IT infrastructure, applications, and cloud environments.
- Perform technology and cyber risk assessments for key JD systems, applications or initiatives.
- Maintain and update the technology risk register, including risk treatment plans and tracking remediation activities.
- Support the development and enhancement of JD Technology Risk Management Framework aligned to standards such as NIST.
- Assess technology risk associated with vendors, suppliers, and third parties.
- Monitor ongoing third-party risk and ensure appropriate mitigation actions are being followed.
Risk Reporting & Stakeholder Engagement
- Prepare clear and concise technology risk reports, dashboards, and metrics for management and governance forums.
- Communicate complex technical risks in business-friendly language.
- Collaborate with IT, Information Security, and business teams to embed a strong risk-aware culture
- Maintain GRC tooling, dashboards and metrics relating to technology and cyber risks.
- Present findings and recommendations with clarity and confidence, supporting informed risk-based decision making.
Audit Support & Stakeholder Management
- Support the Cyber Risk Lead with internal and external auditors during IT audit cycles, coordinating evidence requests, facilitating walkthrough and managing the audit relationship professionally around technology and cyber risk management.
- Support preparation for inspections and audits, ensuring documentation and evidence packs are accurate, complete and audit-ready where required.
- Build effective working relationships and support cross-functional collaboration with other teams and functions such as Technology, Internal Controls, Internal Audit, Enterprise Risk, Legal and Procurement.
Continuous Improvement
- Identify opportunities to improve the efficiency and effectiveness for technology and cyber risk assessments and risk management including automation, tooling and methodology enhancements.
- Support enhancements of GRC policies, standards and procedures relating to technology risk and control.
- Stay current with changes to relevant regulatory requirements, audit standards and industry best practice.
Requirements
- 3 to 5 years of demonstrable experience in end to end technology and risk management or GRC function within a fast-paced and complex organisation.
- Strong understanding of technology risk concepts, including cloud security, network security, application risk and third-party risk.
- Strong written and verbal communication skills, with the ability to produce clear and concise technology and cyber risk assessment reports.
- Strong stakeholder management and communication skills.
- Familiarity with frameworks such as NIST CSF.
- Ability to identify control weaknesses, articulate risk impact and develop actionable remediation recommendations.
- Organised and methodical approach to workload management, with the ability to manage multiple priorities and deadlines.
Desirable
- Relevant professional certifications such as CISM, CRISC, CISSP or equivalent.
- Familiarity with audit frameworks and standards including NIST and ISO27001
- Experience in a retail, e-commerce or large global enterprise environments, supporting GRC management or support activities.
- Familiarity with GRC tooling platforms such as AuditBoard or similar.
Behaviours & Competencies
- Independence and objectivity: Operates with integrity and professional scepticism, providing impartial assurance regardless of organisational pressure.
- Analytical thinking: Applies a structured, evidence-based approach testing.
- Stakeholder engagement: Builds credible and effective working relationships with first line teams, auditors and senior stakeholders.
- Attention to detail: Maintains a high standard of accuracy in technology and cyber risk management and assessments.
- Continuous improvement: Seeks opportunities to improve processes and outcomes.
Benefits & conditions
Pulled from the full job description
- Employee discount, We know our colleagues work tirelessly to make JD Sports the success it is today and in turn, we offer them some amazing benefits including staff Discount On JD Group and other brands within the organisation and personal development opportunities to learn and develop at work.
About the company
Established in 1981 with a single store in the Northwest of England, the JD Group is a leading omni-channel retailer of Sports Fashion, Outdoors and Gyms with our colleagues working in stores across several retail fascias in many markets around the world.
JD Sports Fashion Plc was listed on the London Stock Exchange in 1996 and has been a FTSE100 publicly quoted company since 2019 and continues to grow in the UK and internationally.
We want to be the leading global omnichannel retailer in the sports and outdoor industry. To be a part of this successful company and help us to achieve this you will have the desire to ingrain our strategic goals of being a people-led, innovative and customer-focused organisation which provides operational excellence whilst identifying new areas of growth as part of our day to day objectives.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on uk.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
What Are The Top Skills Required For Azure Developers?
Résumé-Driven Development: How IT trends affect the job market for software developers
Data Engineer Salary UK