InfoSec GRC Analyst: Flexible Work & Risk Governance

University of Glasgow

Glasgow

Hybrid

GBP 41,000 - 46,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

41 days leave for full time staff
Pension package
Flexible working arrangements
Health and wellbeing support

Job summary

The Governance Risk and Compliance Analyst at the University of Glasgow will provide analytical expertise to inform the Cyber Risk and Assurance Manager and the Information Security Team. The role supports the deployment of the Information Security Control Framework and delivers analytical reporting for policy, governance, strategy and risk awareness.

Responsibilities include maintaining a catalogue of risks and controls, supporting audits and funding-related information security requests, and

Qualifications

  • A degree or equivalent professional qualification with broad management experience.
  • Knowledge of GDPR and governance/assurance best practices.
  • Experience with information security risk governance and reporting.
  • Proficiency with Office 365 and analytical tools.

Responsibilities

  • Innovate and support development of information security risks, policies and frameworks.
  • Develop risk governance frameworks and influence stakeholders to adopt them.
  • Manage information security controls, risk registers, audits, and action trackers with accountable stakeholders.
  • Provide regular reporting suitable for senior stakeholders (PowerPoint emphasis).
  • Analyse data to determine risk status and report findings with extensive use of Excel.
  • Analyse security monitoring data to relate controls, incidents and vulnerabilities for transparency.
  • Review legal documents to identify risk states and inform stakeholders.
  • Coordinate Risk Management forums and meeting cadences (O365).
  • Partner with Information Security teams to report risk status accurately.
  • Collaborate with Information Services and other departments to improve information security risks.
  • Support the Risk and Assurance Manager in internal and external communications.
  • Liaise with internal/external partners to ensure requirements are understood and tested.
  • Assist growth of Information Security team through procurement processes.
  • Support all activities pertaining to Information Security Risk Governance & Compliance.

Skills

Attention to detail
Interpersonal skills
Independent and team work
Discretion and diplomacy
Prioritise and problem-solve
Numeracy
Data analysis
Stakeholder influencing
Power BI
Excel
Office 365
Ivanti
Tableau
Splunk
Security risk analytics
Communications in risk governance

Education

Degree or postgraduate qualification
Knowledge of GDPR (risk & legislative frameworks)

Tools

Office 365
Power BI
Excel
Ivanti
Tableau
Splunk

Job description

The Governance Risk and Compliance Analyst at the University of Glasgow will provide analytical expertise to inform the Cyber Risk and Assurance Manager and the Information Security Team. The role supports the deployment of the Information Security Control Framework and delivers analytical reporting for policy, governance, strategy and risk awareness.

Responsibilities include maintaining a catalogue of risks and controls, supporting audits and funding-related information security requests, and

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance Risk and Compliance Analyst
Governance Risk and Compliance Analyst

University of Glasgow • Glasgow

Hybrid
GBP 41,000 - 46,000
41 days leave for full time staff
Pension package
Flexible working arrangements
+1
Lead GRC Security Analyst: ISO 27001 & AI Risk
Lead GRC Security Analyst: ISO 27001 & AI Risk

Cirrus Logic • City of Edinburgh

Hybrid
GBP 90,000 - 130,000
Hybrid work
Information Security Risk & Governance Lead
Information Security Risk & Governance Lead

Capita • Glasgow

On-site
GBP 65,000 - 90,000
GRC & Security Risk Analyst | Hybrid (ISO 27001)
GRC & Security Risk Analyst | Hybrid (ISO 27001)

Capgemini • Inverness

Hybrid
GBP 48,000 - 70,000
Security, Risk & Compliance Analyst | GRC & Policy
Security, Risk & Compliance Analyst | GRC & Policy

Smart Communications. • England

Hybrid
GBP 40,000 - 65,000
Extensive health insurance
Income protection
Life assurance
+4
Information Security & Governance Analyst (Hybrid)
Information Security & Governance Analyst (Hybrid)

Unviersity of Liverpool - The Academy • Liverpool

Hybrid
GBP 35,000 - 52,000
Pension scheme
Hybrid working model
30 days holiday plus 6 closure days
Information Security Governance & Risk Analyst
Information Security Governance & Risk Analyst

Made4Tech Global • Greater Manchester

On-site
GBP 50,000 - 75,000
GRC Information Security Analyst II - Risk & Compliance Lead
GRC Information Security Analyst II - Risk & Compliance Lead

Checkout Ltd • Greater London

Hybrid
GBP 50,000 - 70,000
Snacks and meals provided
Collaborative work environment
Hybrid Security Risk Analyst - ISO/NIST Focus
Hybrid Security Risk Analyst - ISO/NIST Focus

Student Loans Company • Glasgow

Hybrid
GBP 38,000 - 45,000
28 days annual leave
8 public holidays
Flexi-time
+5
Cyber Governance & Risk Advisor (GRC Specialist)
Cyber Governance & Risk Advisor (GRC Specialist)

Cyber UK • Greater London, Woking, Manchester

Hybrid
GBP 50,000 - 70,000
Well-being initiatives including Mental Health Champions
Professional community support
Inclusive and diverse workplace