Enable job alerts via email!

Governance, Risk and Compliance Analyst

Vista

London

On-site

GBP 40,000 - 70,000

Full time

13 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Vista is looking for a dedicated Governance, Risk and Compliance Analyst to enhance compliance with regulatory standards and manage IT risk across the organization. This role will involve collaboration with various teams to uphold security controls and ensure adherence to GRC practices.

Qualifications

  • 2-3 years of experience in GRC or Information Security.
  • Knowledge of frameworks like GDPR, ISO 27001, NIST CSF.
  • Certifications like ISO27001 Lead Implementer or CRISC are a plus.

Responsibilities

  • Maintain and improve the Information Security Management System (ISMS).
  • Conduct audits and risk assessments.
  • Collaborate with teams on privacy standards and compliance.

Skills

Risk Management
Compliance
Information Security

Education

Bachelor’s degree in Information Security

Tools

GRC Platforms (e.g., OneTrust)

Job description

Join to apply for the Governance, Risk and Compliance Analyst role at Vista.

Job Profile
We are seeking a dedicated and detail-oriented Governance, Risk and Compliance (GRC) Analyst to join our team. In this role, you will ensure compliance with regulatory obligations, align with frameworks and security standards, and manage IT risk across the organization and supply chain. You will collaborate with cross-functional teams and work closely with external vendors, auditors, and clients to embed GRC practices, maintain security controls, and ensure adherence to frameworks and policies.

Your Responsibilities

  • Maintain and improve our Information Security Management System (ISMS).
  • Monitor compliance with security frameworks.
  • Support the IT and Information Security policy lifecycle.
  • Maintain the IT Security risk register.
  • Manage risk and track risk mitigation across teams.
  • Conduct security reviews and risk assessments of suppliers and partners.
  • Complete audits for clients and coordinate with audit teams.
  • Audit internal processes for compliance.
  • Work with the Privacy Analyst on DPIAs, RoPAs, and data subject workflows.
  • Maintain the GRC platform and security awareness training platform.
  • Assist in creating and maintaining metrics on control effectiveness and maturity.
  • Stay updated on relevant frameworks and regulatory requirements.

Required Skills, Qualifications, and Experience

  • Bachelor’s degree in Information Security or related field; relevant certifications (e.g., ISO27001 Lead Implementer, CIPP, CRISC) are a plus.
  • At least 2-3 years of experience in GRC, Information Security, or related fields.
  • Experience with GRC platforms like OneTrust is advantageous.
  • Knowledge of risk management methodologies and frameworks such as CIS 8.0, ISO 27001, NIST CSF, GDPR, NIS2.
  • Experience with audits, privacy breach investigations, and legal/regulatory interpretation.
  • Ability to guide teams on privacy standards and compliance.
  • Exposure to cloud environments and AI systems risk controls is a bonus.
  • Strong understanding of privacy laws like GDPR, CCPA.
Seniority level
  • Associate
Employment type
  • Full-time
Job function
  • Information Technology
Industries
  • Airlines and Aviation
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Governance, Risk & Compliance Consultant

Jago Consultants

Worthing null

Remote

Remote

GBP 50,000 - 80,000

Full time

2 days ago
Be an early applicant

Governance, Risk and Compliance Analyst

Vista Global

London null

On-site

On-site

GBP 45,000 - 65,000

Full time

14 days ago

Governance, Risk and Compliance Analyst

VistaJet

London null

On-site

On-site

GBP 45,000 - 70,000

Full time

15 days ago

Governance, Risk, and Compliance Analyst ( GRC, Remote)

Sword

null null

Remote

Remote

GBP 40,000 - 80,000

Full time

30+ days ago