GRC Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Youâll work closely with security, technology and wider business stakeholders, with responsibilities including:
- Supporting the organisationâs ISO 27001 ISMS, including maintaining policies, controls and supporting evidence
- Working with security frameworks including ISO 27001, NIST CSF and CIS Controls
- Conducting and maintaining information security risk assessments
- Managing security risks, controls, actions and remediation plans
- Supporting internal and external security audits and assessments
- Reviewing existing security controls and identifying areas for improvement
- Maintaining security policies, standards, procedures and governance documentation
- Supporting third-party and supplier security assessments
- Tracking compliance against relevant security frameworks and organisational requirements
- Working with technical teams to ensure security controls are implemented effectively
- Producing security reporting, metrics and governance information for stakeholders
Requirements
This is a hands-on role suited to someone with strong knowledge of security frameworks including ISO 27001 and NIST, who can work with technical and business teams to assess risk, maintain controls and support ongoing compliance.
Microsoft security experience would be particularly useful, especially across the wider Microsoft 365 and Azure security ecosystem., * Strong commercial experience within GRC, Information Security or Cyber Security
- Good working knowledge of ISO 27001
- Experience working with NIST, ideally NIST CSF
- Practical experience of security risk management and control assessments
- Experience supporting security audits and compliance activity
- Strong understanding of security policies, governance and assurance
- Experience working with technical and non-technical stakeholders
- The ability to take ownership of GRC activity rather than purely providing administrative support
Experience with Microsoft security tooling would be highly desirable, particularly:
- Microsoft Purview
- Microsoft Sentinel
- Microsoft 365 and Azure security/compliance controls
Relevant certifications such as ISO 27001 Lead Implementer/Auditor, CISM, CRISC, CISSP or equivalent would be beneficial but arenât essential.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Dev Digest 191: Malware interviews, EU â¤ď¸ Open Source and Skilled Agents
Data Analyst Salary in the UK
IT Salaries in UK