Information Security GRC Analyst

Cygnet

Birmingham

Hybrid

GBP 45,000 - 52,000

Full time

37 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

25 days annual leave
Bank holidays
Fully paid training
Paid DBS
Discount scheme (800+ retailers)
NHS Discount (Blue Light Card)
Cycle to Work scheme
Opportunities to progress

Job summary

Cygnet is seeking an experienced Information Security GRC Analyst to join our team on a full-time, permanent basis. The role is hybrid, 40 hours across 5 days, with travel to central offices for monthly team meetings.

You will support the delivery and continual improvement of the organisation’s GRC framework, providing governance, risk management, regulatory compliance, audit and assurance activities across the security function.

Qualifications

  • Experience in information security governance, risk management and regulatory compliance.
  • Proven ability to manage audits and assurance activities.
  • Experience supporting NHS DSPT and ISO/IEC 27001 would be advantageous.

Responsibilities

  • Support the Head of Information Security in delivering the GRC programme.
  • Develop and improve the ISMS and security controls.
  • Assist ISO 27001 certification roadmaps and alignment with CE+ and DSPT.
  • Translate regulatory requirements into practical controls and improvement plans.
  • Collaborate with stakeholders across functions and with third parties.

Skills

Information security governance
Risk management
Regulatory compliance
Audit and assurance
GRC tooling

Job description

Helping others improve and turn their lives around – there’s no better feeling. It’s what we do for thousands of people at more than 150 sites across the UK. Be a part of it.

Cygnet have a fantastic opportunity for an experienced Information Security GRC Analyst to join our team.

Joining our team on a full time, permanent basis, you will work 40hrs across 5 days. This is a hybrid role, working remotely you must be able to travel to one of our central offices inline with a monthly team meeting.

At Cygnet, our perks go way beyond pension schemes and excellent professional development.

You’ll also enjoy shopping, travel and leisure discounts – as well as a range of healthcare and financial benefits – to support you to be happy both in and out of work.

So if you care about making a difference – every day – we want to hear from you.

The Role:

The Information Security GRC Analyst will support the delivery and continual improvement of the organisation’s Information Security Governance, Risk and Compliance (GRC) framework.

Working within the Information Security function, the postholder will provide practical support and subject matter expertise across information security governance, risk management, regulatory compliance, audit and assurance activities.

The role will have particular responsibility for supporting the management of information security risks, maintaining security governance documentation and evidence, coordinating internal and external audit activity, monitoring compliance against relevant security frameworks and supporting the organisation’s wider security awareness programme.

The postholder will work closely with colleagues across Digital Services, Information Governance, Procurement, Risk, Internal Audit and other business functions, as well as third‑party suppliers and external auditors.

The role will support the organisation’s compliance and assurance obligations, including the NHS Data Security and Protection Toolkit (DSPT), Cyber Essentials Plus and ISO/IEC 27001, alongside other applicable regulatory, contractual and organisational requirements.

Your Day To Day:
  • Support the Head of Information Security in delivering Cygnet’s Information Security strategy and GRC programme.
  • Assist with the development, implementation and continual improvement of the organisation’s Information Security Management System (ISMS).
  • Support the roadmap towards ISO/IEC 27001 certification and continued alignment with CE+ and NHS DSPT.
  • Assist in translating regulatory, contractual and security framework requirements into practical controls, actions and improvement plans.
  • Work with stakeholders across Cygnet to embed information security governance into business processes, projects and technology change
Why Cygnet? We’ll offer you…
  • Competitive Salary: £45,000 – £52,000pa DOE
  • 25 days annual leave plus Bank holidays
  • Fully paid training
  • Paid DBS
  • Shopping & entertainment discount scheme (over 800 retailers)
  • NHS Discount (Blue Light Card)
  • Cycle to Work scheme
  • Opportunities to progress and develop.

Please note, successful candidates will be required to undergo an enhanced DBS check.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security GRC Analyst
Information Security GRC Analyst

Cygnet Health Care Limited • Birmingham

On-site
GBP 45,000 - 52,000
Salary £45,000-£52,000
25 days annual leave
Training
+5
Cyber Security Analyst
Cyber Security Analyst

AWD online • West of England

Hybrid
GBP 27,000 - 30,000
Training & Development
25 days holiday
Company pension
+6
Information Security GRC Manager
Information Security GRC Manager

AJ Bell • Manchester

Hybrid
GBP 65,000 - 85,000
27 days’ holiday
Pension with matched contributions up to 8%
Discretionary bonus and share awards
+3
Senior Security Engineer
Senior Security Engineer

NCC Group • Greater Manchester

On-site
GBP 80,000 - 105,000
Flexible working
25 days holiday + bank holidays
Medicash & Critical Illness Scheme
+4
Information Governance Coordinator
Information Governance Coordinator

Somerset Bridge • West of England

On-site
GBP 26,000 - 29,000
Hybrid working
25 days annual leave
Discretionary annual bonus
+4
Compliance and Cyber Security Analyst
Compliance and Cyber Security Analyst

Personal Group • Milton Keynes

Hybrid
GBP 54,000 - 66,000
Holiday entitlement
Private medical insurance
Travel insurance
+2
Information Security Officer
Information Security Officer

TyneStack Ltd • Newcastle upon Tyne

Hybrid
GBP 45,000 - 70,000
Hybrid working
Exposure to ISO 27001/NIST in cloud
Regulated financial tech environment
IT Information Security Analyst - Compliance
IT Information Security Analyst - Compliance

Adecco • West Midlands

Hybrid
GBP 45,000 - 55,000
Hybrid Information Security GRC Analyst: Impact & Compliance
Hybrid Information Security GRC Analyst: Impact & Compliance

Cygnet • Birmingham

Hybrid
GBP 45,000 - 52,000
25 days annual leave
Bank holidays
Fully paid training
+5
Information Governance Coordinator
Information Governance Coordinator

Somerset Bridge Group • West of England

Hybrid
GBP 26,000 - 29,000
Hybrid working - 2 days in the office
25 days annual leave
Discretionary annual bonus
+5