> Markdown version of [/jobs/ext/2143318-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2143318-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - **Company:** Capgemini - **Location:** Inverness, UK (Remote available) - **Salary:** £44,520.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Software Vulnerability Management, Vulnerability Analysis - **Published:** August 20, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5847551758 ## About the Role * Experience working within a Cyber Security Governance, Risk & Compliance (GRC) environment. * Good understanding of security risk management frameworks and methodologies. * Experience supporting security governance, compliance, assurance, audit, or risk management activities. * Familiarity with security standards, certifications, and compliance frameworks, including: + ISO 27001 + Cyber Essentials Plus + GDPR + NIST Cyber Security Framework + ITIL * Strong analytical, reporting, documentation, communication and organisational skills. Desirable * Relevant cyber security qualifications or willingness to work towards industry-recognised certifications (e.g. ISO 27001, Security+, ISC2 CC). We are a Disability Confident Employer ## Description The Governance, Risk, Compliance (GRC) and Vulnerability Assessment Analyst supports the account's cyber security governance, risk management, compliance, assurance, and vulnerability management activities within a complex and highly regulated environment. This role contributes to ensuring that security controls, processes, and governance frameworks are effective, auditable, and aligned to industry standards including ISO 27001, Cyber Essentials Plus, GDPR, NIST, and contractual security obligations. The Analyst provides security oversight, assurance, and risk-based guidance across projects, operational services, and technology changes while supporting secure-by-design principles through governance and design review activities. Working closely with technical and business stakeholders, the successful candidate will help identify, assess, manage, and report security risks appropriately, while supporting continual improvement initiatives that enhance the overall security posture of the account. If you are successfully offered this position, you will go through a series of pre-employment checks, including identity, nationality (single or dual) or immigration status, employment history going back 3 continuous years, and unspent criminal record check (known as Disclosure and Barring Service) Hybrid working Preston or Inverness: The places that you work from day to day will vary according to your role, your needs, and those of the business; it will be a blend of Company offices, client sites, and your home; noting that you will be unable to work at home 100% of the time., * Support the maintenance and continuous improvement of the Cyber Security Governance Framework, ensuring alignment with organisational, client, and regulatory requirements. * Assist with security risk management activities, including risk identification, assessment, treatment, acceptance tracking, and ongoing monitoring. * Support the development, review, and maintenance of security policies, standards, and procedures aligned to ISO 27001, Cyber Essentials Plus, GDPR, and contractual obligations. * Conduct security assurance reviews and control assessments to identify compliance gaps, risks, and opportunities for improvement. * Produce security reporting and metrics covering risk, compliance, audit, incident, and vulnerability management activities for internal and client stakeholders. You can bring your whole self to work. At Capgemini building an inclusive future is part of everyday life and will be part of your working reality. We have built a representative and welcoming environment, for everyone. ## Related Videos - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [What is the real price of one successful line of code?](https://www.wearedevelopers.com/videos/1921-what-is-the-real-price-of-one-successful-line-of-code) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)