An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Cygnet Health Care Limited in the United Kingdom is seeking an experienced Information Security GRC Analyst to join a permanent, full-time team. The role is hybrid and 40 hours across five days, with travel to a central office for monthly team meetings.
You will support the ISMS development, manage governance and regulatory activities, and progress ISO/IEC 27001 readiness while aligning with NHS DSPT and other standards.
Helping others improve and turn their lives around - there's no better feeling. It's what we do for thousands of people at more than 150 sites across the UK. Be a part of it. Cygnet have a fantastic opportunity for an experienced Information Security GRC Analyst to join our team. Joining our team on a full time, permanent basis, you will work 40hrs across 5 days. This is a hybrid role, working remotely you must be able to travel to one of our central offices inline with a monthly team meeting. At Cygnet, our perks go way beyond pension schemes and excellent professional development. You'll also enjoy shopping, travel and leisure discounts - as well as a range of healthcare and financial benefits - to support you to be happy both in and out of work. So if you care about making a difference - every day - we want to hear from you.
The Information Security GRC Analyst will support the delivery and continual improvement of the organisation's Information Security Governance, Risk and Compliance (GRC) framework. Working within the Information Security function, the postholder will provide practical support and subject matter expertise across information security governance, risk management, regulatory compliance, audit and assurance activities. The role will have particular responsibility for supporting the management of information security risks, maintaining security governance documentation and evidence, coordinating internal and external audit activity, monitoring compliance against relevant security frameworks and supporting the organisation's wider security awareness programme. The postholder will work closely with colleagues across Digital Services, Information Governance, Procurement, Risk, Internal Audit and other business functions, as well as third-party suppliers and external auditors. The role will support the organisation's compliance and assurance obligations, including the NHS Data Security and Protection Toolkit (DSPT), Cyber Essentials Plus and ISO/IEC 27001, alongside other applicable regulatory, contractual and organisational requirements.
Support the Head of Information Security in delivering Cygnet's Information Security strategy and GRC programme. Assist with the development, implementation and continual improvement of the organisation's Information Security Management System (ISMS). Support the roadmap towards ISO/IEC 27001 certification and continued alignment with CE+ and NHS DSPT. Assist in translating regulatory, contractual and security framework requirements into practical controls, actions and improvement plans. Work with stakeholders across Cygnet to embed information security governance into business processes, projects and technology change.
Please note, successful candidates will be required to undergo an enhanced DBS check.
At Cygnet, we've been changing people's lives for more than 30 years - thanks to our wide range of high-quality health services. Our care has our patients and residents at its heart and their wellness as its goal. We're always set on positive, lasting outcomes.