Enable job alerts via email!

Security Analyst - GRC/Audit

Fruition IT

United Kingdom

Remote

GBP 60,000 - 80,000

Full time

Yesterday
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Start fresh or import an existing resume

Job summary

Join a leading company as a Contract Security Analyst focusing on governance, risk management, and compliance efforts. This role involves conducting assessments and aligning security controls with best practices like NIST CSF v2.0. Ideal for those with audit expertise and strong stakeholder skills.

Qualifications

  • Proven experience in security auditing, GRC, or control assurance roles.
  • Strong knowledge of security control frameworks (NIST CSF, ISO 27001, CIS).
  • Broad technical understanding of cloud (especially AWS), infrastructure, and applications.

Responsibilities

  • Conducting audit style assessments across various platforms and environments.
  • Performing gap analysis against updated policies and frameworks.
  • Documenting findings in structured, actionable reports.

Skills

Security auditing
Stakeholder management
Communication

Tools

Splunk
Crowdstrike
Kubernetes

Job description

Contract Security Analyst - GRC / Audit

6 months | Remote (UK) | Outside IR35

We're looking for an experienced Security Analyst with an audit first mindset to support a group wide review of security controls across business critical systems, infrastructure, and applications. This work forms part of a broader programme to align with NIST CSF v2.0.

You'll be reviewing the design and effectiveness of security controls, conducting evidence based assessments, and identifying risks where controls are missing or ineffective.

Delivery Areas:

  • Conducting audit style assessments across SaaS platforms, bespoke applications, infrastructure, and cloud environments
  • Evaluating current controls against updated policies and frameworks (NIST CSF v2.0)
  • Performing gap analysis to assess how fit for purpose current controls are
  • Identifying control gaps or legacy issues, and documenting findings in structured, actionable reports
  • Working with stakeholders to define and track mitigation and remediation plans
  • Identify control gaps, legacy issues, and areas of non-compliance.
  • Applying professional scepticism to uncover blind spots and validate that controls are genuinely in place and effective
Requirements:
  • Proven experience in security auditing, GRC, or control assurance roles
  • Strong knowledge of security control frameworks (e.g. NIST CSF, ISO 27001, CIS)
  • Comfortable performing control testing, evidence gathering, and reporting against compliance requirements
  • Broad technical understanding across cloud (especially AWS), infrastructure, and applications
  • Excellent stakeholder management and communication skills
  • Exposure to tools like Splunk, Crowdstrike, MITRE ATT&CK, Kubernetes (nice to have)

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.