About the Role
We are seeking an experienced Information Security & GRC Analyst to join our team on a 12-month fixed-term contract, providing maternity leave cover.
Reporting to the GRC Manager, you will play a key role in maintaining and continually improving the organisation's Information Security Management System (ISMS), supporting regulatory and compliance requirements, managing information security risks, and ensuring the business remains operationally resilient.
This is a broad information security and GRC position, combining ISO 27001 governance, risk management, audit and compliance, information security operations, business continuity and process improvement.
The successful candidate will be comfortable working across business and technology teams, managing multiple priorities and translating security and compliance requirements into practical business processes and controls.
Key Responsibilities
Information Security, Governance & Compliance
- Support the effective operation and continual improvement of the organisation's ISMS, aligned with ISO 27001:2022 and relevant regulatory and industry requirements.
- Maintain and develop information security policies, procedures, standards, risk registers and control documentation.
- Coordinate and support internal and external information security and compliance audits, ensuring appropriate evidence and documentation are available.
- Track audit findings, corrective actions and remediation activities through to completion.
- Conduct and support information security risk assessments, including identifying risks, evaluating controls and developing appropriate mitigation plans.
- Monitor and report on compliance with information security policies, procedures and control requirements.
- Support compliance with relevant frameworks and legislation, including ISO 27001, NIS2, PCI-DSS, GDPR and other applicable requirements.
- Support third-party and supplier security assessments, including the identification and management of information security risks associated with key service providers.
Security & Risk
- Support the investigation, management and reporting of information security incidents, vulnerabilities and control issues.
- Assist with the review and follow-up of vulnerability assessments and penetration testing, working with technical teams to ensure findings are appropriately remediated.
- Maintain organisational information security and technology risk registers and monitor risk treatment activities.
- Support risk assessments for new projects, business services, technology changes and other initiatives.
- Monitor and report on the organisation's overall security and risk posture.
- Support the identification and management of threats such as phishing, social engineering and other malicious activity.
- Work closely with relevant stakeholders on data protection, privacy and personal data handling requirements.
Business Continuity & Operational Resilience
- Support the organisation's Business Continuity and Disaster Recovery (BCDR) programme.
- Assist with Business Impact Analysis activities and the review of critical business services and dependencies.
- Coordinate and support BCP/DR testing, including scenario exercises and remediation of identified gaps.
- Monitor progress against resilience and recovery actions and provide appropriate reporting to management.
Continuous Improvement & Automation
- Identify opportunities to improve information security, governance and operational processes.
- Design and implement practical process improvements to increase efficiency, control effectiveness and operational resilience.
- Support the digitisation and automation of manual processes and reporting.
- Identify opportunities to use technology, data analytics and AI-enabled solutions to improve security, risk management and compliance activities.
- Develop management information, dashboards and reports to provide clear visibility of risk, compliance and performance.
- Challenge inefficient or duplicated processes and recommend improvements.
About You
We are looking for an information security professional with a strong GRC and ISO 27001 background, together with an understanding of wider IT and cybersecurity environments.
You will ideally have:
- At least 3 years' experience in information security, GRC, IT risk, compliance or a similar role.
- Strong practical knowledge of ISO 27001, preferably including experience operating or improving an ISMS.
- Experience supporting or coordinating internal and external audits.
- Experience in information security risk assessment, risk treatment and control management.
- Knowledge of third-party/vendor risk management.
- Experience with information security policies, procedures and control frameworks.
- Understanding of NIS2, PCI-DSS and GDPR or other relevant regulatory requirements.
- Experience with business continuity, disaster recovery or operational resilience would be advantageous.
- An understanding of vulnerability management, penetration testing and technical security controls.
- Good understanding of IT environments, including networks, systems, applications and access controls.
- Strong Microsoft Office skills, particularly Excel, with experience in reporting, data analysis or process automation desirable.
- Strong written and verbal communication skills, with the ability to work effectively with both technical and non-technical stakeholders.
- Excellent organisational skills and the ability to manage multiple priorities independently.
Desirable Experience
The following would be advantageous:
- ISO 27001 Lead Implementer or Lead Auditor certification.
- CISA, CISM, CISSP or another relevant security/GRC qualification.
- Experience with ITIL or service management.
- Experience with DORA, NIS2 or other financial/technology-sector regulations.
- Experience with GRC, ISMS or security management platforms.
- Experience with Power BI, SQL, VBA, Python or other data/automation tools.
- Experience working within a regulated or highly controlled environment.
What We Offer
This is an excellent opportunity for an experienced information security professional to join an established organisation on a 12-month fixed-term contract, gaining broad exposure across information security governance, risk, compliance, audit, operational resilience and continuous improvement.
You will have the opportunity to work closely with stakeholders across the organisation and make a tangible contribution to the effectiveness and maturity of the company's information security and GRC environment.
