Security Compliance Analyst - GRC, Audits & Trust

Certinia

Harrogate

On-site

GBP 52,000 - 70,000

Full time

9 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Certinia is seeking a Security Compliance Analyst to support enterprise-wide security compliance and customer trust initiatives. You will work with IT, Legal, and Privacy to assist audits, governance reviews, and third‑party risk management, reporting to the Head of Information Security.

You will help respond to security questionnaires, maintain approved responses, and assist with customer conversations about security in our products, while aligning with frameworks like ISO 27001, SOC 1/2, and

Qualifications

  • 2+ years of information security experience, in particular Governance, Risk & Compliance (GRC) or IT audit background.
  • Experience implementing or auditing information security programs based on ISO 27001, SOC 1, SOC 2, FedRAMP, or similar.
  • Bachelor’s Degree or equivalent work experience in Computer Science, Engineering, Accounting, or related field.
  • Strong written and spoken communication skills, with ability to tailor messages for audiences including legal, IT, security, sales, or customer success.

Responsibilities

  • Support Customer Trust program, including security questionnaires and RFx responses.
  • Maintain the database of standard responses in Responsive and support the Certinia Proposal Manager as applicable.
  • Assist with customer calls to highlight security within products.
  • Support audits and readiness initiatives across frameworks such as SOC 1, SOC 2, ISO 27001, ISO 42001, FedRAMP.
  • Monitor remediation efforts with stakeholders across geographies and time zones.
  • Document gap analysis in work programs and track remediation progress.
  • Support the creation, review, and maintenance of information security policies, standards, procedures, and guidelines.
  • Maintain enterprise-wide security controls library and map controls to frameworks.
  • Works with Legal to support security language aligned to the company's commitments.
  • Performs third-party security risk assessments for scheduled annual assessments and onboarding of new vendors.
  • Maintains inventory of vendors for risk management within Whistic, ensuring up-to-date information and audit-ready documentation.
  • Supports and tracks remediation required for any non-compliance issues identified.

Skills

GRC experience
Customer-facing communication
Written communication
Global teams across time zones

Education

Bachelor’s Degree or equivalent in CS/Engineering/Accounting

Tools

ISO 27001
SOC 1
SOC 2
FedRAMP
CSA CAIQ / VSA / SIG Lite

Job description

Certinia is seeking a Security Compliance Analyst to support enterprise-wide security compliance and customer trust initiatives. You will work with IT, Legal, and Privacy to assist audits, governance reviews, and third‑party risk management, reporting to the Head of Information Security.

You will help respond to security questionnaires, maintain approved responses, and assist with customer conversations about security in our products, while aligning with frameworks like ISO 27001, SOC 1/2, and

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security & Compliance Analyst for SaaS Trust
Security & Compliance Analyst for SaaS Trust

Certinia • Harrogate

On-site
GBP 65,000 - 90,000
Security Compliance Analyst-UK
Security Compliance Analyst-UK

Certinia • Harrogate

On-site
GBP 52,000 - 70,000
Security GRC Analyst (ISO 27001 & Risk)
Security GRC Analyst (ISO 27001 & Risk)

Clue • West of England

Hybrid
GBP 60,000 - 70,000
Security, Risk & Compliance Analyst | GRC & Policy
Security, Risk & Compliance Analyst | GRC & Policy

Smart Communications. • England

Hybrid
GBP 40,000 - 65,000
Extensive health insurance
Income protection
Life assurance
+4
Security GRC Manager - AI-Driven Trust & Compliance
Security GRC Manager - AI-Driven Trust & Compliance

Humaans • Greater London

On-site
GBP 70,000 - 90,000
Market-leading compensation
25 days paid time off
Share options
+3
IT Compliance Analyst — PCI & SOX Focus in IT Security
IT Compliance Analyst — PCI & SOX Focus in IT Security

Fleetcor Europe LTD • Swindon

On-site
GBP 45,000 - 65,000
25 days’ annual leave plus 8 bankhols
Option to buy or sell up to 5 days of
Pension scheme with 3–5% contributions
+3
ISMS & GRC Analyst — Security Compliance & Risk
ISMS & GRC Analyst — Security Compliance & Risk

Clue Software • West of England

On-site
GBP 65,000 - 90,000
GRC & InfoSec Analyst: Audit & Compliance
GRC & InfoSec Analyst: Audit & Compliance

Crypto Pro Network • Greater London

Hybrid
GBP 70,000 - 100,000
Competitive salary package
Unlimited holidays
Private healthcare benefits
+4
IT Security Analyst — GRC & Awareness (Hybrid)
IT Security Analyst — GRC & Awareness (Hybrid)

Bimplus • Leatherhead

On-site
GBP 48,000 - 60,000
26 days holiday + bank holidays
8% pension employer contribution
Training budgets
+2
Remote Cyber Security Compliance Analyst
Remote Cyber Security Compliance Analyst

Jobgether • United Kingdom

Hybrid
GBP 34,000 - 47,000
Competitive salary
Remote work flexibility
Total rewards package
+2