Information Security GRC Analyst (UK-based)

PCI Pal

Greater London

Hybrid

GBP 55,000 - 75,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

25 days holiday
Insurance cover
EV scheme
Work from anywhere 2 weeks/year
Wellbeing & rewards hub
Training & development
Team events

Job summary

PCI Pal is seeking an Information Security GRC Analyst (UK-based) to strengthen its central Information Security function by delivering governance, risk and compliance analysis across audit, assurance, control management and strategic change. The role turns requirements, evidence, risks and delivery updates into accurate, traceable information that supports timely decisions by the GRC Lead and CISO.

The role works in close partnership with the Information Security Project Manager to track

Qualifications

  • Experience in GRC, information security compliance, risk management or assurance.
  • Familiar with PCI DSS, ISO 27001, SOC 2 or NIST CSF and applying requirements.
  • Ability to review policies, audit reports and evidence and translate findings.
  • Strong organization to track plans, risks, dependencies and status.
  • Excellent written and verbal communication for stakeholders.
  • Experience in PCI DSS Level 1 environments or regulated tech/cloud settings.
  • Qualification in information security, risk, audit, compliance or delivery.

Responsibilities

  • Audit & Assurance: support audits, coordination, evidence reviews and reporting.
  • Program Tracking: track initiatives, maintain trackers and update owners.
  • Risk & Remediation: link risks to controls, monitor remediation and closure.
  • AI Governance: support AI governance, validate AI outputs and improvements.

Skills

GRC experience
Information security
Audit & assurance
Policy review
Stakeholder comms
Evidence and tracking

Education

Information security qualification

Tools

Drata
Jira
ServiceNow GRC
Archer
OneTrust

Job description

Information Security GRC Analyst (UK-based)

The GRC Analyst strengthens PCI Pal's central Information Security function by providing structured governance, risk and compliance analysis across audit, assurance, control management and strategic change. The role turns requirements, evidence, risks and delivery updates into accurate, traceable information that supports timely decisions by the GRC Lead and CISO.

The role works in close partnership with the Information Security Project Manager to track ongoing and strategic initiatives, maintain clear ownership and delivery visibility, and provide concise, evidence-based updates. It remains a GRC role: the Analyst provides assurance, analysis and tracking, while the Project Manager retains responsibility for project governance, planning and delivery coordination.

Job requirements
  • Relevant experience in GRC, information security compliance, risk management, internal audit or assurance.
  • Working knowledge of at least one major framework, such as PCI DSS, ISO/IEC 27001, SOC 2 or NIST CSF, with the ability to apply requirements in practice.
  • Experience reviewing policies, audit reports, control narratives and evidence, and translating findings into clear actions.
  • Strong organization and tracking skills, including the ability to maintain plans, actions, risks, dependencies and status reporting across multiple concurrent initiatives.
  • Strong written and verbal communication skills, with the ability to produce concise, accurate updates for operational and senior stakeholders.
  • A collaborative working style and the confidence to challenge incomplete evidence, unclear ownership or unsupported status updates.
  • Experience operating within a PCI DSS Level 1 service provider, regulated technology or cloud services environment.
  • Familiarity with ISO/IEC 42001, ISO 9001, HIPAA/HITECH, Cyber Essentials or related assurance frameworks.
  • Experience using GRC, audit, project tracking or evidence automation platforms, such as Drata, Jira, ServiceNow GRC, Archer or OneTrust.
  • Experience supporting programme governance, PMO reporting or strategic transformation initiatives in partnership with a Project Manager.
  • Experience reviewing AI-generated content, data annotation, quality assurance or AI governance workflows.
  • Relevant qualification or certification in information security, risk, audit, compliance or project delivery.
  • Support the CISO, GRC Lead and wider Information Security team with risk, compliance and control analysis.
  • Maintain governance artefacts including policies, standards, control mappings, risk registers, Statements of Applicability and supporting records.
  • Review security policies, procedures, control narratives and evidence for accuracy, completeness, consistency and alignment with applicable frameworks.
  • Identify control gaps, emerging risks and compliance issues, and provide practical recommendations with clear owners and target dates.
  • Monitor relevant regulatory and industry developments, assess potential business impact and support the controlled update of affected requirements and documentation.
Audit & Assurance
  • Support internal and external audits, certification activity and customer assurance reviews, including evidence coordination, quality review and follow-up.
  • Conduct control assessments, testing and evidence reviews, with clear findings and conclusions reported to the GRC Lead.
  • Maintain audit plans, evidence requests, findings and remediation actions so that progress and closure are fully traceable.
  • Challenge incomplete or unsupported evidence and work with control owners to resolve quality, scope and timing issues.
  • Produce clear assurance reporting for the GRC Lead, CISO and relevant governance forums.
Program Tracking & Strategic Initiatives
  • Work in close partnership with the Information Security Project Manager to track ongoing, planned and strategic departmental initiatives against agreed milestones, dependencies, risks, actions and outcomes.
  • Maintain accurate initiative trackers, action logs and reporting inputs, ensuring updates are supported by evidence and reflect the position agreed with accountable owners.
  • Obtain and consolidate progress updates from Information Security and cross-functional stakeholders, highlighting overdue actions, delivery risks, control impacts and decisions required.
Risk, Findings & Remediation Management
  • Maintain clear linkage between identified risks, control deficiencies, audit findings, remediation work and closure evidence.
  • Coordinate with Information Security Architecture & Engineering, Information Security Operations, Engineering and Product to obtain appropriate technical input rather than independently interpreting technical risk without subject-matter validation.
  • Track remediation progress against risk-based priorities and agreed timescales, escalating blockers, slippage and residual risk to the GRC Lead and Information Security Project Manager as appropriate.
  • Verify that closure evidence addresses the underlying requirement and that accepted risks are documented and approved through the established governance process.
AI Governance & Emerging Risk
  • Support the maintenance of PCI Pal's AI Management System and associated AI governance, risk and assurance activities.
  • Validate AI-assisted or AI-generated GRC outputs, including security questionnaire responses, control mappings and draft analysis, to identify inaccuracies, omissions or misclassification before use.
  • Support AI system and supplier assessments, ensuring conclusions are evidence-based and referred to technical specialists where validation is required.
  • Build effective working relationships with control owners and stakeholders across PCI Pal while maintaining appropriate independence and challenge.
  • Improve GRC processes, templates, evidence standards, automation and reporting so that assurance activity becomes more consistent, efficient and audit-ready.
  • Contribute to the Information Security Target Operating Model and departmental roadmap, providing GRC progress and risk information to the Information Security Project Manager and CISO.
What we offer
  • 25 days holiday, rising to 28 days per annum with length of service
  • Medical, dental and optical insurance cover
  • An exciting and flexible working environment surrounded by friendly and committed co-workers
  • Electric Vehicle Scheme incentive
  • Work from anywhere 2 weeks per year policy
  • Reward, benefits and wellbeing hub (offering support, discounts, cashback and savings)
  • Training and development opportunities
  • Ad-hoc team events, incentives and competitions
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Architecture & Engineering Lead (UK-based)
Information Security Architecture & Engineering Lead (UK-based)

PCI Pal • Greater London

On-site
GBP 120,000 - 160,000
25 days holiday
Medical, dental and optical insurance
Work from anywhere policy
+3
UK Information Security GRC Analyst – Governance, Risk & Assurance
UK Information Security GRC Analyst – Governance, Risk & Assurance

PCI Pal • Greater London

Hybrid
GBP 55,000 - 75,000
25 days holiday
Insurance cover
EV scheme
+4
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
Senior GRC Analyst
Senior GRC Analyst

Broster Buchanan • Bolton

On-site
GBP 111,000 - 166,000
GRC Analyst - Cyber Security
GRC Analyst - Cyber Security

TEC Partners Limited • Enfield

On-site
GBP 50,000 - 60,000
Fully remote
Lead GRC Consultant
Lead GRC Consultant

Cathcart Technology • Easter Howgate

Hybrid
GBP 70,000 - 110,000
Bonus
Share scheme
IT GRC Senior Analyst
IT GRC Senior Analyst

Nigel Wright Recruitment • Newcastle upon Tyne

Hybrid
GBP 70,000 - 90,000
Hybrid work policy
Information Security GRC Manager
Information Security GRC Manager

AJ Bell • Manchester

Hybrid
GBP 65,000 - 85,000
27 days’ holiday
Pension with matched contributions up to 8%
Discretionary bonus and share awards
+3
Information Security Officer
Information Security Officer

Maxwell Bond • Reading

Hybrid
GBP 55,000 - 57,000
Senior Information Security Governance Analyst (VA831)
Senior Information Security Governance Analyst (VA831)

Carey Olsen • Eastleigh

On-site
GBP 70,000 - 90,000
35-hour working week
Training and development support
25 days' holiday (option to buy/sell 5
+4