Turn this role into an interview — a resume and cover letter built around what this employer wants.
Cygnet is seeking an experienced Information Security GRC Analyst to join our team on a full-time, permanent basis. The role is hybrid, 40 hours across 5 days, with travel to central offices for monthly team meetings.
You will support the delivery and continual improvement of the organisation’s GRC framework, providing governance, risk management, regulatory compliance, audit and assurance activities across the security function.
Helping others improve and turn their lives around – there’s no better feeling. It’s what we do for thousands of people at more than 150 sites across the UK. Be a part of it.
Cygnet have a fantastic opportunity for an experienced Information Security GRC Analyst to join our team.
Joining our team on a full time, permanent basis, you will work 40hrs across 5 days. This is a hybrid role, working remotely you must be able to travel to one of our central offices inline with a monthly team meeting.
At Cygnet, our perks go way beyond pension schemes and excellent professional development.
You’ll also enjoy shopping, travel and leisure discounts – as well as a range of healthcare and financial benefits – to support you to be happy both in and out of work.
So if you care about making a difference – every day – we want to hear from you.
The Information Security GRC Analyst will support the delivery and continual improvement of the organisation’s Information Security Governance, Risk and Compliance (GRC) framework.
Working within the Information Security function, the postholder will provide practical support and subject matter expertise across information security governance, risk management, regulatory compliance, audit and assurance activities.
The role will have particular responsibility for supporting the management of information security risks, maintaining security governance documentation and evidence, coordinating internal and external audit activity, monitoring compliance against relevant security frameworks and supporting the organisation’s wider security awareness programme.
The postholder will work closely with colleagues across Digital Services, Information Governance, Procurement, Risk, Internal Audit and other business functions, as well as third‑party suppliers and external auditors.
The role will support the organisation’s compliance and assurance obligations, including the NHS Data Security and Protection Toolkit (DSPT), Cyber Essentials Plus and ISO/IEC 27001, alongside other applicable regulatory, contractual and organisational requirements.
Please note, successful candidates will be required to undergo an enhanced DBS check.