GRC Analyst (Security Governance & Configuration)

Sword Group

Aberdeen City

On-site

GBP 40,000 - 60,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Personalised Career Development
Flexible working arrangements
Generous annual leave allowance

Job summary

A leading technology solutions provider in the UK is seeking a GRC Analyst to enhance governance, risk, and compliance practices. This hands-on role involves shaping secure configuration and change management across a major energy program. You'll develop and document management plans, ensure clarity in roles, and communicate security policies effectively. Ideal candidates will have experience with cyber security standards and strong documentation skills. The position offers flexible working and a comprehensive benefits package.

Qualifications

  • Experience with cyber security standards such as ISO 27001 or NIST frameworks.
  • Ability to produce clear, structured, and usable documentation.
  • Strong skills in translating technical concepts into business-friendly language.

Responsibilities

  • Develop and document a Configuration Management Plan aligned with standards.
  • Define roles and responsibilities across the 2nd Line of Defence.
  • Support the rollout of configuration management processes and communication.
  • Document security policy principles for clarity and guidance.

Skills

Experience with cyber security standards like ISO 27001
Understanding of secure configuration principles
Experience writing policies and governance documentation
Strong documentation skills
Ability to understand and map process flows
Strong communication skills
Collaboration with cross-functional teams

Job description

Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving transformational change within our clients. We use proven technology, specialist teams and domain expertise to build solid technical foundations across platforms, data, and business applications. We have a passion for using technology to solve business problems, working in partnership with our clients to help in achieving their goals.

About The Role

As a GRC Analyst, you'll play a key role in strengthening governance, risk, and compliance practices across a major energy network programme. This is a hands‑on role where you'll help shape how secure configuration and change management are defined, documented, and embedded across the organisation. You'll be working at the intersection of cyber security, governance, and business change—translating complex security standards into clear, practical processes that teams can understand and adopt. From developing configuration management plans aligned to recognised standards, through to supporting rollout and communication across the business, your work will directly influence how security is applied in real‑world operations. You'll collaborate closely with security, change, and business teams, ensuring that governance processes are not only well‑designed, but effectively implemented and understood. This is an opportunity to contribute to a high‑impact programme, bringing structure, clarity, and consistency to critical security practices.

As a GRC Analyst, You Will
  • Develop and document a Configuration Management Plan aligned to recognised standards such as NIST.
  • Define and document roles and responsibilities across the 2nd Line of Defence, ensuring clarity and accountability.
  • Support the rollout of configuration management processes, including communication, stakeholder engagement, and adoption.
  • Document secure configuration policy principles, translating technical requirements into clear, accessible guidance.
  • Review, refine, and communicate security policies to ensure alignment with organisational and regulatory expectations.
  • Gather and interpret configuration compliance reports from monitoring tools to support governance activities.
  • Enhance change management processes, including contributing to Change Advisory Board (CAB) inputs.
  • Work closely with business change and communications teams to embed new processes effectively.
  • Simplify complex security concepts into practical guidance for non‑technical stakeholders.
  • Maintain clear, structured documentation that supports ongoing governance and audit requirements.
Requirements
  • Experience working with cyber security standards such as ISO 27001 or NIST frameworks (e.g. NIST 800‑53).
  • Understanding of secure configuration principles and cyber security policy development.
  • Experience writing policies, procedures, or governance documentation within a security context.
  • Strong documentation skills, with the ability to produce clear, structured, and usable outputs.
  • Ability to understand and map process flows, including defining roles and responsibilities (e.g. RACI models).
  • Strong communication skills, with the ability to translate technical concepts into business‑friendly language.
  • Experience collaborating with cross‑functional teams, including security, change, and communications.
It Would Be Great If You Also Had
  • Experience developing or implementing a Configuration Management Plan.
  • Exposure to governance within large‑scale transformation or regulated environments.
  • Familiarity with compliance reporting and monitoring tools.
  • Experience supporting change management processes or governance forums such as CAB.
Benefits

At Sword, our core values and culture are based on caring about our people, investing in training and career development, and building inclusive teams where we are all encouraged to contribute to achieve success. We offer comprehensive benefits designed to support your professional development and enhance your overall quality of life. In addition to a competitive salary, here's what you can expect as part of our benefits package:

  • Personalised Career Development: We create a development plan customised to your goals and aspirations, with a range of learning and development opportunities within a culture that encourages growth.
  • Flexible working: Flexible work arrangements to support your work‑life balance. We can't promise to always be able to meet every request, however, are keen to discuss your individual preferences to make it work where we can.
  • A Fantastic Benefits Package: This includes generous annual leave allowance, enhanced family‑friendly benefits, pension scheme, access to private health, well‑being, and insurance schemes.

At Sword we are dedicated to fostering a diverse and inclusive workplace and are proud to be an equal opportunities employer, ensuring that all applicants receive fair and equal consideration for employment, regardless of whether they meet every requirement. If you don't tick all the boxes but feel you have some of the relevant skills and experience we're looking for, please do consider applying and highlight your transferable skills and experience. We embrace diversity in all its forms, valuing individuals regardless of age, disability, gender identity or reassignment, marital or civil partner status, pregnancy or maternity status, race, colour, nationality, ethnic or national origin, religion or belief, sex, or sexual orientation. Your perspective and potential are important to us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk & Compliance Consultant
Governance, Risk & Compliance Consultant

Cyber Fraud Centre • Glasgow

On-site
GBP 50,000 - 75,000
Personalised Career Development
Flexible working arrangements
Generous annual leave allowance
+1
Senior Information Management Analyst
Senior Information Management Analyst

Sword Group • Aberdeen City

On-site
GBP 60,000 - 85,000
Career development
Flexible working
Private health
Project Coordinator
Project Coordinator

Sword Group • Aberdeen City

Hybrid
GBP 28,000 - 36,000
Personalised Career Development
Flexible working
Comprehensive benefits package
Project Coordinator
Project Coordinator

Sword Group • Bellshill

On-site
GBP 30,000 - 42,000
Flexible working
Excellent benefits package
Career development
Network Consulting Engineer
Network Consulting Engineer

Sword Group • Aberdeen City

On-site
GBP 50,000 - 80,000
Personalised Career Development
Flexible working
Generous annual leave
+3
Senior Project Manager
Senior Project Manager

Sword Group • Aberdeen City

On-site
GBP 65,000 - 90,000
Competitive Salary
Career Development
Flexible Working
+1
Senior Project Manager
Senior Project Manager

Cyber Fraud Centre • Aberdeen City

Hybrid
GBP 65,000 - 90,000
Network Consulting Engineer
Network Consulting Engineer

Sword Group • Bristol

On-site
GBP 65,000 - 90,000
Personalised career development
Flexible working arrangements
Comprehensive benefits package
Test & Validation Analyst
Test & Validation Analyst

Sword Group • Glasgow

Hybrid
GBP 35,000 - 55,000
Personalised Career Development
Flexible working
Generous annual leave allowance
+1
(OT) Operational Technology Security Consultant
(OT) Operational Technology Security Consultant

Sword Group • Aberdeen City

On-site
GBP 70,000 - 90,000
Personalized career development
Flexible working arrangements
Generous annual leave allowance
+3