> Markdown version of [/jobs/ext/3266102-senior-grc-analyst](https://www.wearedevelopers.com/jobs/ext/3266102-senior-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior GRC Analyst - **Company:** Eg Group - **Location:** Horwich, UK - **Experience:** Expert - **Salary:** £70,000.0 - £80,000.0 - **Contract:** Temporary contract - **Skills:** Cyber Security, Phishing, Information Technology Security Auditing, Information Security Management System, Cyber Threat Analysis, RSA Archer Platform - **Published:** September 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8dee5fae5a859b10 ## About the Role * Significant practical experience in Information Security Governance, Risk and Compliance at Senior Analyst, Consultant, or equivalent level. * Demonstrable experience supporting regulatory, certification, or external security audit readiness, including evidence coordination and remediation management. * Hands-on experience with ISO 27001-aligned Information Security Management Systems and information security policy and control governance. * Experience conducting project and technology security risk assessments and assessing control design and operating effectiveness. * Strong analytical and evidence-management skills, with the ability to translate regulatory and framework requirements into practical actions. * Confident communication and stakeholder management skills, with the ability to engage technical and non-technical stakeholders and present to governance forums. * A pragmatic and business-focused approach, with the confidence to challenge weak controls, incomplete evidence, or unclear ownership. * Relevant qualifications such as CISM, CRISC, CISSP, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor would be advantageous, as would experience with NIS2, GRC platforms, or GDPR. ## Description Cumberland Farms is looking for an experienced Senior GRC Analyst to join our Information Security team. Reporting to the Head of Information Security, you will provide specialist support across a range of information security governance, risk, and compliance workstreams. The role will have a particular focus on NIS2 audit readiness, security risk assessments, ISMS and policy governance, cyber risk management, control assurance, and security awareness. You will work closely with stakeholders across Technology, Legal, Data Protection, Finance, HR, Project Delivery, and wider business operations, taking ownership of defined workstreams and delivering clear, practical, and audit-ready outcomes. This is a hands-on, delivery-focused opportunity for an experienced GRC professional who can work independently, manage competing priorities, and bring structure and momentum to complex information security activities., * Support NIS2 audit readiness by coordinating evidence, conducting readiness reviews, and tracking remediation activity. * Conduct proportionate security risk assessments across projects, systems, and technology changes, identifying risks and recommending practical controls. * Support the maintenance and continuous improvement of the ISO 27001-aligned Information Security Management System (ISMS). * Review and maintain information security policies, standards, procedures, and control frameworks to ensure they remain current and aligned to business requirements. * Assess the design and operating effectiveness of security controls, identifying gaps and tracking improvement actions through to completion. * Maintain the cyber risk register, ensuring risks, treatments, actions, ownership, and review dates remain accurate and up to date. * Coordinate audit findings, remediation activity, assurance evidence, and third-party security assessments, while supporting security awareness and phishing simulation campaigns. * Produce GRC reporting and metrics for senior stakeholders and governance forums, while continuously improving GRC processes, templates, and guidance. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Data Analyst Salary Germany](https://www.wearedevelopers.com/magazine/277-data-analyst-salary-germany)