Hybrid Security Assurance Analyst — ISO/NIST & GRC

Caraffi

Reading

Hybrid

GBP 60,000 - 85,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Caraffi, a global retail organisation, is seeking a Security Assurance Analyst to join its Cyber Security function in Reading or Dublin on a hybrid basis (2 days a week). The role supports a major technology transformation and helps strengthen enterprise security posture.

You’ll deliver security assurance across projects and third‑party suppliers, ensuring controls, documentation and governance are applied, coordinating testing, and maintaining risk management tools and repositories.

Qualifications

  • Minimum 3 years’ experience in an information security role with a focus on assurance.
  • Experience supporting security accreditation programmes (ISO 27001, PCI, Cyber Essentials).
  • Understanding of GDPR, PCI and how regulations influence project requirements.

Responsibilities

  • Support the assurance team in conducting project security reviews across major technology initiatives
  • Maintain key assurance repositories including supplier registers and project assurance lists
  • Coordinate penetration testing logistics and ensure required documentation is completed to the right standard
  • Validate that security controls are implemented and compliant prior to go-live
  • Support third-party assurance reviews for new and existing suppliers
  • Populate and maintain the Third-Party Risk Management tool, ensuring data accuracy and completeness
  • Collate and track third-party documentation (SOC, PCI, ISO 27001 etc.) and flag outdated reports
  • Work with the Risk Management team to ensure third-party risks are accurately reflected in the GRC platform
  • Contribute to continuous improvement of security assurance processes and governance

Skills

GRC platforms
TPRM modules
Security by design
Penetration testing
Remediation guidance
ISO 27001
NIST
GDPR
PCI DSS
Stakeholder communications
Agile delivery
Waterfall delivery

Tools

Power BI
OneTrust

Job description

Caraffi, a global retail organisation, is seeking a Security Assurance Analyst to join its Cyber Security function in Reading or Dublin on a hybrid basis (2 days a week). The role supports a major technology transformation and helps strengthen enterprise security posture.

You’ll deliver security assurance across projects and third‑party suppliers, ensuring controls, documentation and governance are applied, coordinating testing, and maintaining risk management tools and repositories.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Assurance Analyst
Security Assurance Analyst

Caraffi • Reading

Hybrid
GBP 60,000 - 85,000
Hybrid: GRC & Security Assurance Analyst (ISO 27001)
Hybrid: GRC & Security Assurance Analyst (ISO 27001)

Clue Computing Co. • West of England

Hybrid
GBP 60,000 - 70,000
Security Operations Analyst: Threat Detection & Response
Security Operations Analyst: Threat Detection & Response

Caraffi • Reading

On-site
GBP 55,000 - 75,000
GRC Information Security Analyst II — Hybrid
GRC Information Security Analyst II — Hybrid

Checkout.com • Greater London

Hybrid
GBP 70,000 - 110,000
Hybrid working model
Office snacks
Breakfast and lunch options
GRC & Security Risk Analyst | Hybrid (ISO 27001)
GRC & Security Risk Analyst | Hybrid (ISO 27001)

Capgemini • Inverness

Hybrid
GBP 48,000 - 70,000
Senior GRC Analyst — Hybrid, NIS2 & ISO27001 Focus
Senior GRC Analyst — Hybrid, NIS2 & ISO27001 Focus

Euro Garages • Horwich

On-site
GBP 70,000 - 90,000
Discretionary bonus
Hybrid working
Cycle to Work
+2
Hybrid Security Risk Analyst - ISO/NIST Focus
Hybrid Security Risk Analyst - ISO/NIST Focus

Student Loans Company • Glasgow

Hybrid
GBP 38,000 - 45,000
28 days annual leave
8 public holidays
Flexi-time
+5
Hybrid Information Security GRC Analyst: Impact & Compliance
Hybrid Information Security GRC Analyst: Impact & Compliance

Cygnet • Birmingham

Hybrid
GBP 45,000 - 52,000
25 days annual leave
Bank holidays
Fully paid training
+5
Hybrid Information Security GRC Lead | ISO27001 & Risk
Hybrid Information Security GRC Lead | ISO27001 & Risk

RAC • Bradley Stoke

Hybrid
GBP 70,000 - 90,000
Colleague Share Scheme
Car salary sacrifice scheme (EV)
25 days annual leave
+4
Hybrid InfoSec Third-Party Assurance Analyst
Hybrid InfoSec Third-Party Assurance Analyst

Centrica • Windsor

Hybrid
GBP 60,000 - 82,000
15% Employee Energy Allowance
Pension plan
Healthcare – fully funded
+3