GRC Analyst

Ncsc
Manchester, UK
9 days ago
Apply on www.apply4u.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Cyber Security Security Information and Event Management Devsecops

Job description

A large, well-established public sector organisation in Manchester is looking for an Analyst to join their Information Security team on a permanent basis.This is a broad and genuinely interesting security role blending security architecture, compliance, policy development, risk management and stakeholder engagement. If you want a role where you’re shaping how security is done rather than just maintaining it, this is worth a look.What you’ll be doing:Designing and maintaining security architectures aligned with NCSC guidance and sector best practice. Leading internal security audits and contributing to external assurance including Cyber Essentials. Writing and maintaining information security policies and standards. Conducting risk assessments and managing the security risk register. Supporting third-party security risk management. Delivering security awareness training across the organisation. Working across IT, data protection, legal and operational teams to embed security at every

Requirements

level.What they’re looking for:A proven background in an operational security role, Security Architect, Security Analyst or Compliance Lead.Strong knowledge of GDPR, ISO 27001, Cyber Essentials Plus and NCSC CAF.An industry-recognised certification such as CISSP, CISM, ISO 27001 Lead Implementer or equivalent.Experience writing and implementing security policies, conducting audits and working with IT teams to improve controls.Familiarity with DevSecOps, SIEM tooling, or higher education / public sector environments is desirable but not essential. #J-18808-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.apply4u.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all