GRC Analyst

IMT Resourcing Solutions

Cheltenham

On-site

GBP 42,000 - 58,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

IMT Resourcing Solutions in Cheltenham is seeking an experienced GRC Analyst to support information security governance, risk and compliance activities for an established organisation. You will work with technical and business teams to assess risk, maintain controls and support ongoing compliance.

The role emphasises ISO 27001 and NIST frameworks, with cloud security tooling from Microsoft (Purview, Sentinel, 365/Azure) and collaboration with auditors and stakeholders across IT and operations.

Qualifications

  • GRC or information security experience.
  • Strong knowledge of ISO 27001.
  • Experience with NIST CSF.
  • Experience supporting audits and compliance activities.
  • Ability to engage with technical and business stakeholders.
  • ISO 27001 Lead Implementer/Auditor or equivalent is a plus.

Responsibilities

  • Support ISO 27001 ISMS, maintain policies, controls and evidence.
  • Work with ISO 27001, NIST CSF and CIS Controls.
  • Conduct and maintain information security risk assessments.
  • Manage security risks, controls, actions and remediation plans.
  • Support internal and external security audits and assessments.
  • Review existing security controls and identify improvements.
  • Maintain security policies, standards, procedures and governance docs.
  • Support third-party and supplier security assessments.
  • Track compliance against relevant security frameworks and requirements.
  • Collaborate with technical teams to ensure controls are implemented.
  • Produce security reporting, metrics and governance information.

Skills

GRC
InfoSec
Risk Management
Policy Governance
Stakeholder Management

Tools

Microsoft Purview
Microsoft Sentinel
Azure Security

Job description

We’re looking for an experienced GRC Analyst to support an established organisation with its information security governance, risk and compliance activity.

This is a hands-on role suited to someone with strong knowledge of security frameworks including ISO 27001 and NIST, who can work with technical and business teams to assess risk, maintain controls and support ongoing compliance.

Microsoft security experience would be particularly useful, especially across the wider Microsoft 365 and Azure security ecosystem.

The Role

You’ll work closely with security, technology and wider business stakeholders, with responsibilities including:

  • Supporting the organisation’s ISO 27001 ISMS, including maintaining policies, controls and supporting evidence
  • Working with security frameworks including ISO 27001, NIST CSF and CIS Controls
  • Conducting and maintaining information security risk assessments
  • Managing security risks, controls, actions and remediation plans
  • Supporting internal and external security audits and assessments
  • Reviewing existing security controls and identifying areas for improvement
  • Maintaining security policies, standards, procedures and governance documentation
  • Supporting third-party and supplier security assessments
  • Tracking compliance against relevant security frameworks and organisational requirements
  • Working with technical teams to ensure security controls are implemented effectively
  • Producing security reporting, metrics and governance information for stakeholders
What We’re Looking For
You’ll ideally have:
  • Strong commercial experience within GRC, Information Security or Cyber Security
  • Good working knowledge of ISO 27001
  • Experience working with NIST, ideally NIST CSF
  • Practical experience of security risk management and control assessments
  • Experience supporting security audits and compliance activity
  • Strong understanding of security policies, governance and assurance
  • Experience working with technical and non-technical stakeholders
  • The ability to take ownership of GRC activity rather than purely providing administrative support

Experience with Microsoft security tooling would be highly desirable, particularly:

  • Microsoft Purview
  • Microsoft Sentinel
  • Microsoft 365 and Azure security/compliance controls

Relevant certifications such as ISO 27001 Lead Implementer/Auditor, CISM, CRISC, CISSP or equivalent would be beneficial but aren't essential.

  • Contract: Initial 6 months
  • Extension: Strong possibility of extension
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
GRC Analyst: ISO 27001, NIST & Microsoft Security Risk
GRC Analyst: ISO 27001, NIST & Microsoft Security Risk

IMT Resourcing Solutions • Cheltenham

On-site
GBP 42,000 - 58,000
Information Security Governance & Risk Analyst
Information Security Governance & Risk Analyst

Made4Tech Global • Greater Manchester

On-site
GBP 50,000 - 75,000
Information Security & Compliance Lead (GRC)
Information Security & Compliance Lead (GRC)

Tank Recruitment • Oxford

Hybrid
GBP 70,000 - 110,000
Senior Security Analyst - GRC
Senior Security Analyst - GRC

Humankind Global Recruitment • Greater London

Hybrid
GBP 70,000 - 100,000
Hybrid work (2 days in London City)
GRC Analyst
GRC Analyst

G.Digital • Manchester

On-site
GBP 45,000 - 65,000
Information Security GRC Specialist
Information Security GRC Specialist

Morson Edge (Financial Services) • Greater London

Hybrid
GBP 90,000 - 120,000
Governance, Risk & Compliance Lead
Governance, Risk & Compliance Lead

Elevation Recruitment Group • Leeds

Hybrid
GBP 65,000 - 105,000
Information Security Analyst - Tech b/g - Know GRC - Local to Hull - £55k
Information Security Analyst - Tech b/g - Know GRC - Local to Hull - £55k

LT Harper - Cyber Security Recruitment • Kingston upon Hull

Hybrid
GBP 50,000 - 55,000
Senior Cyber GRC Specialist – Technical Controls
Senior Cyber GRC Specialist – Technical Controls

air-recruitment • Greater London

Hybrid
GBP 108,000 - 132,000