InfoSec Governance, Risk and Compliance Analyst

Leonardo SpA

Basildon

On-site

GBP 38,000 - 52,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid working
Pension scheme
Mental health support
Training & development via Coursera/LL

Job summary

Leonardo UK is seeking a Governance, Risk and Compliance Analyst to support the Information Security team in maintaining clear standards, assessing risk and providing assurance that controls are evidenced and reviewed across the business.

You will work across multiple business areas, with hybrid working, and potential travel between sites. The role requires experience in information security governance, risk and compliance and familiarity with MoD/UK security policies.

Qualifications

  • Experience in information security governance, risk and compliance.
  • Knowledge of security control frameworks and risk management practices.
  • Understanding of cyber and information risk frameworks and methodologies.
  • Understanding of MoD and UK government security policy and frameworks.
  • Familiarity with security standards, policies, control frameworks or risk management artefacts.
  • Practical understanding of risk assessment, residual risk, risk acceptance and non-compliance management.
  • Experience supporting audits, assurance reviews, control testing or compliance reporting.
  • Ability to review evidence and assess whether security controls are clearly described and appropriately supported.
  • Professional security qualification such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or willingness to work towards one.
  • Knowledge of governance tooling, dashboards, data analysis or automation would be beneficial.

Responsibilities

  • Support the Head of Governance, Risk and Compliance with day-to-day information security governance, risk and compliance workload.
  • Assist with maintaining security standards, control mappings and assurance processes.
  • Support reviews of security management and assurance plans to ensure controls are described, evidenced and aligned to the standard.
  • Conduct or support risk assessments where security controls are not implemented, including documenting the risk position and supporting review.
  • Conduct audit and assurance activity across Leonardo UK systems and services.
  • Help track non-compliances, remediation activity and risk acceptance decisions.
  • Work with delivery teams, system owners and security specialists to gather evidence and support proportionate security governance.
  • Contribute to compliance, risk and assurance reporting for the Information Security function.
  • Support continual improvement of the Information Security Operating Model, including better use of data, tooling and automation.

Skills

Info security governance
Risk assessment
Compliance management
Security audits
Stakeholder engagement
Data analysis
Security frameworks
Security qualifications
Goverance tooling

Job description

Job Description

Leonardo UK operates in a complex security, regulatory and defence environment. As a Governance, Risk and Compliance Analyst, you will support the Information Security team in maintaining clear standards, assessing risk and providing assurance that security controls are understood, evidenced and reviewed across the business. The role will work across multiple business areas and may require travel between Leonardo UK sites, with hybrid working supported where appropriate.

Your impact

What you will do as Governance, Risk and Compliance Analyst:

  • Support the Head of Governance, Risk and Compliance with the day-to-day information security governance, risk and compliance workload.
  • Assist with maintaining security standards, control mappings and assurance processes.
  • Support reviews of security management and assurance plans to help ensure controls are properly described, evidenced and aligned to the agreed standard.
  • Conduct or support risk assessments where security controls are not implemented, including documenting the risk position and supporting appropriate review.
  • Conduct audit and assurance activity across Leonardo UK systems and services.
  • Help track non-compliances, remediation activity and risk acceptance decisions.
  • Work with delivery teams, system owners and security specialists to gather evidence and support proportionate security governance.
  • Contribute to compliance, risk and assurance reporting for the Information Security function.
  • Support continual improvement of the Information Security Operating Model, including better use of data, tooling and automation.
What you\'ll bring

You will bring experience or strong working knowledge of information security governance, risk and compliance. You should be comfortable working with security standards, control frameworks, risk records and assurance evidence in a regulated environment.

Essential experience and skills
  • Experience in information security, cyber risk, compliance, assurance or audit.
  • Knowledge of security control frameworks and risk management practices.
  • Understanding of cyber and information risk frameworks and methodologies.
  • Understanding of MoD and other UK government security policy and frameworks.
  • Familiarity with security standards, policies, control frameworks or risk management artefacts.
  • Practical understanding of risk assessment, residual risk, risk acceptance and non-compliance management.
  • Experience supporting audits, assurance reviews, control testing or compliance reporting.
  • Ability to review evidence and assess whether security controls are clearly described and appropriately supported.
  • Experience working with technical and non-technical stakeholders to gather information and support risk or assurance activity.
  • Professional security qualification such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or willingness to work towards one.
  • Knowledge of governance tooling, dashboards, data analysis or automation would be beneficial.

This is not an exhaustive list, and we are keen to hear from you even if you might not have experience in all the above. The most important skill is a good attitude and willingness to learn.

Security Clearance

This role is subject to pre-employment screening in line with the UK Government\'s Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). For more information and guidance please visit: https://careers.uk.leonardo.com/gb/en/security-and-vetting

Why join us

At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work-life balance. Whether you\'re looking to grow professionally, care for your health, or plan for the future, we\'re here to help you thrive.

  • Time to Recharge: Enjoy generous leave with the opportunity to accrue up to 12 additional flexi-days each year.
  • Secure your Future: Benefit from our award-winning pension scheme with up to 15% employer contribution.
  • Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks championing inclusion and diversity (Enable, Pride, Equalise, Armed Forces, Carers, Wellbeing and Ethnicity).
  • Rewarding Performance: All employees at management level and below are eligible for our bonus scheme.
  • Never Stop Learning: Free access to 4,000+ online courses via Coursera and LinkedIn Learning.
  • Refer a friend: Receive a financial reward through our referral programme.
  • Tailored Perks: Spend up to £500 annually on flexible benefits including private healthcare, dental, family cover, tech & lifestyle discounts, gym memberships and more.
  • Flexible working: Flexible hours with hybrid working options. For part time opportunities, please talk to us about what might be possible for this role.

For a full list of our company benefits please visit our website.

Leonardo UK operates a grade-based salary framework with broad bands. The salary range shown reflects the approved grade band for this role, or a narrower hiring range published within that band, and is benchmarked against the external market. Exceptions above the standard range are managed through governance controls to protect internal equity.

Leonardo is a global leader in Aerospace, Defence, and Security. Headquartered in Italy, we employ over 53,000 people worldwide including 8,500 across 9 sites in the UK. Our employees are not just part of a team-they are key contributors to shaping innovation, advancing technology, and enhancing global safety.

At Leonardo we are committed to building an inclusive, accessible, and welcoming workplace. We believe that a diverse workforce sparks creativity, drives innovation, and leads to better outcomes for our people and our customers. If you have any accessibility requirements to support you during the recruitment process, just let us know.

Be part of something bigger - apply now!

Primary Location

Primary Location: GB - Basildon

Additional Locations

Additional Locations: GB - Bristol - Coldharbour Lane, GB - Edinburgh, GB - Lincoln, GB - London, GB - Luton - Cap. Green 300, GB - Newcastle, GB - Southampton, GB - Yeovil - Lysander Rd

Contract Type

Contract Type: Permanent

Hybrid Working

Hybrid Working: Hybrid

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head of Governance, Risk and Compliance (Information Security)
Head of Governance, Risk and Compliance (Information Security)

Leonardo • London Colney

Hybrid
GBP 90,000 - 130,000
Generous leave
Pension scheme
Mental health support
+5
Head of Governance, Risk and Compliance (Information Security)
Head of Governance, Risk and Compliance (Information Security)

Leonardo • Newcastle upon Tyne

Hybrid
GBP 90,000 - 140,000
Time to Recharge: up to 12 flexi-days
Employer pension up to 15%
Mental health support
+2
Head of Governance, Risk and Compliance (Information Security)
Head of Governance, Risk and Compliance (Information Security)

Leonardo • Yeovil

Hybrid
GBP 90,000 - 150,000
Time to Recharge
Pension scheme with employer contrib.
Mental health support
+4
Head of Governance, Risk and Compliance (Information Security)
Head of Governance, Risk and Compliance (Information Security)

Leonardo • Basildon

Hybrid
GBP 90,000 - 130,000
Hybrid working
Bonus scheme
Private healthcare
+3
Head of Governance, Risk and Compliance (Information Security)
Head of Governance, Risk and Compliance (Information Security)

Leonardo • Lincoln

Hybrid
GBP 100,000 - 140,000
Time to Recharge
Pension scheme
Wellbeing support
+2
Head of Governance, Risk and Compliance (Information Security)
Head of Governance, Risk and Compliance (Information Security)

慨正橡扯 • Yeovil

Hybrid
GBP 90,000 - 125,000
Hybrid working
Pension scheme
Mental health support
+3
Head of Governance, Risk and Compliance (Information Security)
Head of Governance, Risk and Compliance (Information Security)

Leonardo • Southampton

On-site
GBP 90,000 - 125,000
Time to Recharge
Pension up to 15% employer contrib.
Mental health support
+4
IT Security Officer (highly classified systems)
IT Security Officer (highly classified systems)

Leonardo • Lincoln

Hybrid
GBP 70,000 - 110,000
Flexi-days
Pension (up to 15% employer)
Mental health support
+5
Head of Governance, Risk and Compliance (Information Security)
Head of Governance, Risk and Compliance (Information Security)

Leonardo S.p.A. • Basildon

Hybrid
GBP 90,000 - 130,000
Hybrid working
Pension scheme
Learning & development
+2
IT Security Officer (highly classified systems)
IT Security Officer (highly classified systems)

Leonardo • Yeovil

Hybrid
GBP 65,000 - 90,000
Time to Recharge
Pension scheme
Flexible working
+2