> Markdown version of [/jobs/ext/1123842-grc-analyst](https://www.wearedevelopers.com/jobs/ext/1123842-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - **Company:** JDSPORTS - **Location:** Unsworth, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Information Technology Audit, Network Security, Cloud Platform System, Cyber Threat Analysis, Information Technology - **Published:** July 2, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=a1c2753157f79c66 ## About the Role * 3 to 5 years of demonstrable experience in end to end technology and risk management or GRC function within a fast-paced and complex organisation. * Strong understanding of technology risk concepts, including cloud security, network security, application risk and third-party risk. * Strong written and verbal communication skills, with the ability to produce clear and concise technology and cyber risk assessment reports. * Strong stakeholder management and communication skills. * Familiarity with frameworks such as NIST CSF. * Ability to identify control weaknesses, articulate risk impact and develop actionable remediation recommendations. * Organised and methodical approach to workload management, with the ability to manage multiple priorities and deadlines. Desirable * Relevant professional certifications such as CISM, CRISC, CISSP or equivalent. * Familiarity with audit frameworks and standards including NIST and ISO27001 * Experience in a retail, e-commerce or large global enterprise environments, supporting GRC management or support activities. * Familiarity with GRC tooling platforms such as AuditBoard or similar. Behaviours & Competencies * Independence and objectivity: Operates with integrity and professional scepticism, providing impartial assurance regardless of organisational pressure. * Analytical thinking: Applies a structured, evidence-based approach testing. * Stakeholder engagement: Builds credible and effective working relationships with first line teams, auditors and senior stakeholders. * Attention to detail: Maintains a high standard of accuracy in technology and cyber risk management and assessments. * Continuous improvement: Seeks opportunities to improve processes and outcomes. ## Description The GRC Analyst (Technology and Cyber Risk) will sit within the second line of defence and is responsible for assisting the Cyber Risk Lead in identifying, assessing, and monitoring cyber and technology-related risks across key JD systems, applications, cloud environments, and third-party services. This role requires collaboration with IT, information security, internal audit, and business stakeholders to ensure technology and cyber risks are effectively managed and aligned with regulatory requirements and industry best practices across JD Sports., Technology and Cyber Risk Management * Identify, assess, and document technology and cyber risks across IT infrastructure, applications, and cloud environments. * Perform technology and cyber risk assessments for key JD systems, applications or initiatives. * Maintain and update the technology risk register, including risk treatment plans and tracking remediation activities. * Support the development and enhancement of JD Technology Risk Management Framework aligned to standards such as NIST. * Assess technology risk associated with vendors, suppliers, and third parties. * Monitor ongoing third-party risk and ensure appropriate mitigation actions are being followed. Risk Reporting & Stakeholder Engagement * Prepare clear and concise technology risk reports, dashboards, and metrics for management and governance forums. * Communicate complex technical risks in business-friendly language. * Collaborate with IT, Information Security, and business teams to embed a strong risk-aware culture * Maintain GRC tooling, dashboards and metrics relating to technology and cyber risks. * Present findings and recommendations with clarity and confidence, supporting informed risk-based decision making. Audit Support & Stakeholder Management * Support the Cyber Risk Lead with internal and external auditors during IT audit cycles, coordinating evidence requests, facilitating walkthrough and managing the audit relationship professionally around technology and cyber risk management. * Support preparation for inspections and audits, ensuring documentation and evidence packs are accurate, complete and audit-ready where required. * Build effective working relationships and support cross-functional collaboration with other teams and functions such as Technology, Internal Controls, Internal Audit, Enterprise Risk, Legal and Procurement. Continuous Improvement * Identify opportunities to improve the efficiency and effectiveness for technology and cyber risk assessments and risk management including automation, tooling and methodology enhancements. * Support enhancements of GRC policies, standards and procedures relating to technology risk and control. * Stay current with changes to relevant regulatory requirements, audit standards and industry best practice. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cloud Vendor Lock-In - Is it just a new version of the Database Abstraction Layers?](https://www.wearedevelopers.com/videos/1185-cloud-vendor-lock-in-is-it-just-a-new-version-of-the-database-abstraction-layers) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Hosting a modern justice system](https://www.wearedevelopers.com/videos/332-hosting-a-modern-justice-system) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023)