Hybrid GRC & Compliance Analyst

Starling

Manchester

Hybrid

GBP 30,000 - 46,000

Full time

10 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid working
Pension scheme
Private medical insurance
Cycle to Work

Job summary

Engine by Starling is seeking a Governance, Risk and Compliance professional to help maintain and mature our program. You’ll work with stakeholders across Engineering, Product and Security Operations to embed controls and ensure regulatory alignment.

The role focuses on ISO 27001, SOC1/2, CSTAR, PCI DSS, audits, evidence collection, and continuous improvement, with hybrid working in Manchester and a supportive benefits package.

Qualifications

  • Minimum 1 year of experience in an information security role.
  • Proven experience in supporting and managing compliance efforts.
  • Strong skills in security metrics and reporting.
  • Experience with audit processes and evidence collection.
  • Proactive, organised, and detail-oriented approach.
  • Experience with GRC software is a plus.

Responsibilities

  • Compliance Management: support day-to-day management of compliance programs (ISO 27001, SOC1, SOC2, CSTAR, PCI DSS/3DS).
  • Audit Support: liaison for auditors, gather evidence, prepare for audits, track remediation.
  • Risk Management: assist in risk assessment and treatment planning.
  • Policy & Procedure Maintenance: update security policies and procedures.
  • Evidence Collection & Review: streamline evidence gathering for audit readiness.
  • Cross-Functional Collaboration: work with Engineering, Product and Security Ops.
  • Continuous Improvement: identify efficiency opportunities in the GRC program.
  • Security Awareness: assist in security training for all employees.
  • Third-Party Risk Assessments: evaluate security posture of vendors.
  • Team-oriented, proactive collaboration.

Skills

Security metrics
Audit processes
Evidence collection
Stakeholder engagement
Detail-oriented

Education

Foundational IT risk / audit certs
ISC2 Cybersecurity (CC)
ISO 27001 Foundation training

Job description

Engine by Starling is seeking a Governance, Risk and Compliance professional to help maintain and mature our program. You’ll work with stakeholders across Engineering, Product and Security Operations to embed controls and ensure regulatory alignment.

The role focuses on ISO 27001, SOC1/2, CSTAR, PCI DSS, audits, evidence collection, and continuous improvement, with hybrid working in Manchester and a supportive benefits package.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid: Junior GRC & Security Compliance Analyst
Hybrid: Junior GRC & Security Compliance Analyst

Starling • Southampton

Hybrid
GBP 40,000 - 65,000
Salary sacrifice
Private Medical Insurance
Life insurance 4x salary
+7
Junior Information Security & GRC Analyst
Junior Information Security & GRC Analyst

Starling • Greater London

Hybrid
GBP 32,000 - 52,000
33 days holiday
Birthday day off
Volunteer time
+5
Junior GRC Analyst: ISO/SOC Audits & Risk (Hybrid)
Junior GRC Analyst: ISO/SOC Audits & Risk (Hybrid)

Starling • Cardiff

Hybrid
GBP 42,000 - 65,000
Private Medical Insurance
Company pension scheme
Life insurance
+1
Junior Information Security & GRC Analyst
Junior Information Security & GRC Analyst

Starling • City Of London

Hybrid
GBP 35,000 - 50,000
33 days holiday
Birthday leave
Enhanced pension
+5
Hybrid London: Senior GRC Analyst — AI-Driven Security
Hybrid London: Senior GRC Analyst — AI-Driven Security

Humankind Global Recruitment • Greater London

Hybrid
GBP 70,000 - 100,000
Hybrid work (2 days in London City)
Junior Information Security Analyst (GRC) - Engine by Starling
Junior Information Security Analyst (GRC) - Engine by Starling

Starling • City Of London

Hybrid
GBP 35,000 - 50,000
33 days holiday
Birthday leave
Enhanced pension
+5
Hybrid Leeds: Cyber GRC Lead - Policy & Risk
Hybrid Leeds: Cyber GRC Lead - Policy & Risk

Elevation Recruitment Group • Leeds

Hybrid
GBP 65,000 - 105,000
Senior Security Analyst - GRC
Senior Security Analyst - GRC

Humankind Global Recruitment • Greater London

Hybrid
GBP 70,000 - 100,000
Hybrid work (2 days in London City)
Hybrid GRC & InfoSec Analyst: ISO27001 & DSPT
Hybrid GRC & InfoSec Analyst: ISO27001 & DSPT

Cygnet Health Care Limited • Birmingham

Hybrid
GBP 45,000 - 52,000
Salary £45,000-£52,000
25 days annual leave
Training
+5
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000