GRC Analyst

IMT Resourcing Solutions
Cheltenham, UK
3 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Microsoft Windows Microsoft Azure Cyber Security Microsoft Security Essentials Information Security Management System Microsoft Sentinel CIS Benchmarks

Job description

You’ll work closely with security, technology and wider business stakeholders, with responsibilities including:

  • Supporting the organisation’s ISO 27001 ISMS, including maintaining policies, controls and supporting evidence
  • Working with security frameworks including ISO 27001, NIST CSF and CIS Controls
  • Conducting and maintaining information security risk assessments
  • Managing security risks, controls, actions and remediation plans
  • Supporting internal and external security audits and assessments
  • Reviewing existing security controls and identifying areas for improvement
  • Maintaining security policies, standards, procedures and governance documentation
  • Supporting third-party and supplier security assessments
  • Tracking compliance against relevant security frameworks and organisational requirements
  • Working with technical teams to ensure security controls are implemented effectively
  • Producing security reporting, metrics and governance information for stakeholders

Requirements

This is a hands-on role suited to someone with strong knowledge of security frameworks including ISO 27001 and NIST, who can work with technical and business teams to assess risk, maintain controls and support ongoing compliance.

Microsoft security experience would be particularly useful, especially across the wider Microsoft 365 and Azure security ecosystem., * Strong commercial experience within GRC, Information Security or Cyber Security

  • Good working knowledge of ISO 27001
  • Experience working with NIST, ideally NIST CSF
  • Practical experience of security risk management and control assessments
  • Experience supporting security audits and compliance activity
  • Strong understanding of security policies, governance and assurance
  • Experience working with technical and non-technical stakeholders
  • The ability to take ownership of GRC activity rather than purely providing administrative support

Experience with Microsoft security tooling would be highly desirable, particularly:

  • Microsoft Purview
  • Microsoft Sentinel
  • Microsoft 365 and Azure security/compliance controls

Relevant certifications such as ISO 27001 Lead Implementer/Auditor, CISM, CRISC, CISSP or equivalent would be beneficial but aren’t essential.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin ¡ World Congress 2022

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea ¡ World Congress 2022

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula ¡ LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ World Congress 2022

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi ¡ World Congress 2022

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn ¡ World Congress 2023

Videos

See all

Related articles

See all