Governance, Risk & Compliance (GRC) Analyst

Dunelm

Leicester

Hybrid

GBP 45,000 - 65,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Dunelm is seeking an experienced Governance, Risk & Compliance (GRC) Analyst to join our Information Security team in the UK. You will strengthen cyber security governance, risk and compliance capabilities while aligning with regulatory requirements and business objectives.

Working with technology, retail operations, finance, legal and HR, you will drive governance improvements, support regulatory compliance, and embed security into daily processes.

Qualifications

  • Experience in GRC, information security or cyber security.
  • Able to develop and maintain governance documentation with accuracy.
  • Strong stakeholder management and written communication skills.
  • Experience supporting audits and regulatory compliance activities.

Responsibilities

  • Develop and maintain cyber security governance, risk and compliance capabilities.
  • Coordinate third‑party security assurance and supplier risk management.
  • Support risk assessments, risk lifecycle activities and executive reporting.
  • Produce governance documentation, policies and standards.
  • Embed security governance across business functions and projects.

Skills

Governance & risk
Cyber security
Stakeholder management
Regulatory compliance
Policy writing
Security metrics reporting

Tools

LogicGate
OneTrust
Archer
AuditBoard

Job description

Overview

Home. There’s no place like it.

And there’s no feeling like helping people create the joy of feeling truly at home. At Dunelm, that’s what we do. We’re the UK's number one choice for homewares because we make home life lovelier for our customers. And we’ve crafted a workplace that feels just as welcoming – where you can bring your ideas, be yourself, and feel right at home.

Work your way, together

We're a hybrid business, which means you'll have flexibility alongside time together with your team. In this role, you can expect minimum 1 day per week in our Leicester office.

We are seeking an experienced Governance, Risk & Compliance (GRC) Analyst to join our Information Security team within a FTSE 250 retail organisation. This role is responsible for developing, implementing and continually improving the organisation's cyber security governance, risk and compliance capabilities, ensuring alignment with business objectives, regulatory obligations and industry best practice.

Working collaboratively across technology, digital, retail operations, finance, legal, procurement, HR and other business functions, you will help strengthen the organisation's cyber security maturity, support regulatory compliance and embed security into everyday business processes.

The successful candidate will have a strong understanding of cyber security frameworks, governance principles and risk management, combined with excellent stakeholder management and communication skills.

Join our Cyber Security Team and be at the forefront of protecting our business. You’ll contribute to safeguarding our operations and drive positive change and in a business where you can build a long-term career that always promises to challenge and excite.

What you'll be doing
Governance & Compliance:
  • Develop, maintain and continually improve our Information Security Management System.
  • Support and maintain compliance with:
    • PCI DSS eCommerce and Card present payment channels.
    • NIST Cyber Security Framework (CSF) 2.0
    • UK Data Protection Act 2018 and relevant EU data privacy legislation.
    • Other relevant regulatory and industry requirements such as Provision 29, Cyber Essentials and Cyber Essentials Plus.
  • Support evidence collection for compliance activities.
  • Monitor emerging legislation and regulatory changes, assessing business impact.
  • Support the implementation of security governance across all business functions.
Risk Management:
  • Administer the Cyber Security risk register toolset.
  • Facilitate cyber risk assessments across projects, business initiatives and operational services.
  • Support risk owners throughout the cyber security risk lifecycle.
  • Enhance risk reporting for senior leadership and executive committees.
Third Party Risk Management:
  • Oversee the supplier cyber security assurance process.
  • Conduct security assessments of suppliers, partners and third parties.
  • Help to highlight supply chain risks and recommend appropriate mitigation.
  • Track supplier security due diligence.
  • Monitor ongoing supplier compliance throughout the contract lifecycle.
Security Governance:
  • Develop and maintain Information Security policies, standards, procedures and supporting guidance.
  • Ensure documentation remains current, aligned with business objectives and regulatory requirements.
  • Support governance forums and security steering committees.
  • Produce reports for senior management and executive stakeholders.
  • Assist in maintaining security exceptions and risk acceptance processes.
Security Awareness & Culture:
  • Help develop cyber security awareness programmes.
  • Contribute to phishing simulations and awareness campaigns.
  • Review effectiveness of these measures through reporting and behavioural metrics.
  • Promote a positive security culture across stores, support centres and digital teams.
  • Support onboarding and annual security training programmes.
Metrics & Continuous Improvement:
  • Develop governance and compliance KPIs and KRIs.
  • Administer metrics addressing:
    • Compliance status
    • Audit findings
    • Risk posture
    • Third-party assurance
    • Policy compliance
    • Security awareness completion
    • Security maturity
  • Benchmark organisational maturity against recognised frameworks.
  • Drive continual improvement initiatives across governance and compliance processes.
Business Partnership:
  • Act as a trusted advisor to business stakeholders.
  • Work closely with relevant stakeholders across the business.
  • Provide pragmatic security advice supporting business innovation while managing cyber risk.
  • Support projects by embedding security governance from inception.
What we'll look for in you

You will need to be a self-starter with ability to work at pace across multiple business levels and with stakeholders across all levels of seniority.

Essential Skills & Experience:
  • Experience in a Governance, Risk & Compliance, Information Security or Cyber Security role.
  • Strong understanding of:
    • Cyber Security Risk
    • NIST Cyber Security Framework (CSF) 2.0
    • PCI DSS
    • UK GDPR and Data Protection Act 2018
  • Experience conducting cyber risk assessments.
  • Experience with third-party security assurance programmes.
  • Experience writing policies, standards and governance documentation.
  • Experience supporting audits and regulatory compliance activities.
  • Experience producing security metrics and executive reporting.
  • Excellent stakeholder management skills.
  • Strong analytical and problem-solving ability.
  • Excellent written and verbal communication skills.
  • Ability to influence stakeholders at all organisational levels.
Desirable Experience:
  • Experience within a FTSE 250 or large enterprise environment.
  • Experience in retail, eCommerce or omnichannel businesses.
  • Familiarity with cloud security.
  • Knowledge of Secure by Design principles.
  • Experience with GRC platforms (e.g. LogicGate, OneTrust, Archer or AuditBoard).
  • Experience supporting security framework certification programmes (e.g. ISO27001).
  • One or more of the following professional Cyber Security certifications is preferred:
    • ISO/IEC 27001 Lead Implementer or Lead Auditor
    • Certified Information Systems Security Professional (CISSP)
    • Certified Information Security Manager (CISM)
    • Certified in Risk and Information Systems Control (CRISC)
    • Certified Information Privacy Professional Europe (CIPP/E)
    • PCI Professional (PCIP)
    • Internal Security Assessor (PCI - ISA)
    • NIST Cyber Security Framework Practitioner
Behaviours/Values

Our shared values of 'act like owners', 'keep listening and learning', 'long term thinking', and 'stronger together' help ensure we are always finding better ways of doing things and spending our time focusing on what’s important.

  • Excellent communication skills
  • Collaboration across all business functions and tech teams
  • Customer focussed
  • Responsible and show integrity
  • Self-motivated, calm persona, attention to detail
  • Ability to deliver under pressureAbility to keep up to date on latest cyber-threats and skills using available study tools, partners, etc
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid GRC & Cyber Security Analyst
Hybrid GRC & Cyber Security Analyst

Dunelm • Leicester

Hybrid
GBP 45,000 - 65,000
Cyber Security Analyst
Cyber Security Analyst

Novia Financial plc • Bath

On-site
GBP 55,000 - 75,000
Cyber Security Compliance Manager
Cyber Security Compliance Manager

Reed Technology • Manchester

Hybrid
GBP 63,000 - 77,000
Cyber Security Governance and Risk Management Principal
Cyber Security Governance and Risk Management Principal

Government Digital Service • Manchester

On-site
GBP 110,000 - 140,000
GRC Analyst - Cyber Security
GRC Analyst - Cyber Security

TEC Partners Limited • Enfield

On-site
GBP 50,000 - 60,000
Fully remote
Cyber Security Governance and Risk Management Principal
Cyber Security Governance and Risk Management Principal

Government Digital Service • Greater London

On-site
GBP 70,000 - 90,000
Principal Cyber Security Governance & Risk Leader
Principal Cyber Security Governance & Risk Leader

Government Digital Service • Greater London

On-site
Principal Cyber Security Governance & Risk Leader
Principal Cyber Security Governance & Risk Leader

Government Digital Service • Manchester

On-site
GBP 110,000 - 140,000
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
Security GRC Analyst
Security GRC Analyst

Clue • West of England

Hybrid
GBP 60,000 - 70,000