Security GRC Analyst

Clue Computing Co.

West of England

Hybrid

GBP 60,000 - 70,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Clue Computing Co. is seeking a Security Governance, Risk and Compliance Analyst to maintain the ISO 27001 ISMS, manage the risk register and lead customer security assurance.

The role collaborates with CISO, DevSecOps and IT Operations to coordinate evidence, incidents and supplier assessments. The successful candidate will work across UK public sector accounts, coordinate governance cadences, and ensure evidence is complete and audit-ready, with hybrid work from the Bristol office two days per

Qualifications

  • Experience maintaining ISO 27001:2022 and ISMS governance.
  • Ability to run risk registers, audits, and evidence management.
  • Experience leading customer security assurance and due diligence.
  • Familiarity with CCS, G-Cloud 15, and NCSC frameworks preferred.
  • Knowledge of data protection and UK GDPR basics.

Responsibilities

  • Administer and maintain the ISMS documentation, policies and exception logs.
  • Lead risk register updates, risk reviews and treatment plans.
  • Coordinate customer security assurance, evidence packs and due diligence responses.
  • Oversee incident management, including notifications and post-incident reviews.
  • Coordinate third-party risk management and supplier assurance processes.
  • Support governance rhythms: weekly/fortnightly/ monthly reporting.

Skills

ISO 27001 ISMS
Risk management
Customer assurance
Incident management
Technical literacy
Clear English comms

Education

ISO 27001 Lead Implementer/Auditor

Job description

Role specifics
  • Salary range: £60,000 – 70,000
  • Reporting to: Chief Information Officer
  • Key stakeholders: Platform and Development, Product, Sales and Onboarding, IT Operations, Legal Counsel and DPO, People team, our managed security operations provider, customer security and assurance teams
  • Organisational Framework Level: Level 3 – Professional Specialist
  • Eligible to obtain UK security clearance (SC). UK-based.
  • Minimum requirement of 2 days per week in our Bristol office
About you/ Job Summary

As a Security Governance, Risk and Compliance Analyst, you keep our information security management system current, evidenced and moving. Clue supplies software to UK public sector, Sports and law enforcement, and those customers expect us to show, not just say, that our controls work. You will administer our ISO 27001 ISMS day to day, maintain the risk register, lead customer security assurance, run the supplier assessment cycle and coordinate the record-keeping and communications when an incident occurs. The CISO leads the security function, sets direction, and holds accountability; the Security Engineering team and IT own the technical controls. Your job is to do the work between them intelligently: know where every piece of evidence lives, what we have promised each customer, what is due next, and who needs chasing.

At Clue we are actively adopting AI to improve our products and workflows. You will bring curiosity and a willingness to use AI tools to work faster and more accurately, while knowing where they should not be trusted.

Key Accountabilities
ISMS and certification
  • Administer the information security policy, set: review schedule, publication and acknowledgement records, with the CISO approving changes.
  • Maintain ISO 27001:2022 certification: statement of applicability, evidence library, internal audit scheduling and external audit coordination.
  • Work with IT to maintain security accreditations such as Cyber Essentials Plus and our ISO accreditations, plus the evidence set for the NCSC Cyber Assessment Framework where customers require it.
  • Maintain the security exceptions register, tracking time-limited approvals and named risk sponsors.
  • Pen-test and crisis simulation exercise management and coordination, alongside the CISO.
Risk management
  • Maintain the risk register and apply the scoring model set by the CISO. Keep entries current, sponsored and treated.
  • Prepare and coordinate the monthly risk register review with executive risk sponsors, and track treatment plans to closure.
  • Draft register entries from audit findings, incident lessons, threat assessments and customer requirements, for CISO review, each with a proposed owner.
  • Maintain the list of security-related product roadmap requests and coordinate prioritisation between the CISO and Product.
Customer assurance and contractual compliance
  • Lead customer security assurance: draft questionnaire responses, assemble evidence packs and handle due diligence requests, drawing technical input from the DevSecOps Engineer and IT Operations.
  • Maintain the single record of every security commitment made to a customer.
  • Carry out compliance checks of customer environments before go-live and report the results to the CISO for sign-off.
  • Track our obligations under CCS framework security schedules and G-Cloud 15 Call-Off Schedule 9A, and maintain the evidence for each.
  • Produce customer-facing assurance reporting, including the monthly vulnerability report within five working days of month end.
Security operations governance
  • Coordinate the day-to-day relationship with our managed security operations provider: track service levels, prepare monthly service reviews and maintain the detection improvement backlog.
  • Track vulnerability remediation against contractual windows, record exceptions and report performance.
  • Maintain the protective monitoring standard and the logging and monitoring evidence an assurance review will test.
  • Keep a record of threat intelligence intake from NCSC and other sources, and of the actions taken.
Incident management
  • Act as incident coordinator: convene the response channel, keep the record, apply the severity matrix and escalation path without discretion, and track actions to closure. The CISO chairs incidents and coordinates Clue response.
  • Prepare and track customer and regulatory notifications, including any contractual out of hours customer notification and the UK GDPR 72-hour ICO window, with Legal and the DPO.
  • Maintain the incident register, organise post-incident reviews and track corrective actions.
  • Maintain the annualcrisis exercise plan and organise the exercises.
Third-party risk management
  • Operate the supplier assurance process and platform: onboard, tier and reassess suppliers on a risk-based cycle.
  • Keep a named executive sponsor recorded for each material supplier and chase their review obligations.
People, access and awareness
  • Draft security awareness and training requirements and assure delivery with the People team.
  • Support the People Director with the vetting policy and collect the evidence that personnel security controls operate.
  • Collect and check access governance evidence: review schedules, privileged access records and joiner, mover and leaver records.
  • Support the Security Champions network with process guidance.
Governance and reporting
  • Organise the governance cadence: weekly security governance, fortnightly Security Steering Group, monthly risk review and quarterly Information Security Management Forum. Agendas, papers, minutes and actions.
  • Draft sponsor and board-level reporting for the CISO, sourced and consistent across documents.
  • Track every security action to a named owner and a date, and report status without spin.
Key role measures
  • ISO 27001 certification maintained with no major nonconformities; audit findings closed within agreed date
  • Risk register currency: every entry reviewed within its cycle, sponsored, and with a live treatment plan
  • Customer assurance turnaround: questionnaires and evidence requests answered within agreed SLAs with no unsupported commitments
  • Vulnerability remediation reported accurately against contractual windows, with exceptions recorded
  • Incident notifications made within contractual and regulatory windows; post-incident actions closed
  • Supplier coverage: all material suppliers tiered, assessed and sponsored
Experience and skills
Our ideal candidate would have experience in the following areas:
Information security management
  • Working within an ISO 27001 ISMS through certification or surveillance audits, ideally in a SaaS organisation.
  • Maintaining a risk register and working with senior risk owners to keep entries current and treated.
  • Keeping exceptions, policies and evidence to an audit-ready standard.
Customer and public sector assurance
  • Responding to customer security questionnaires and due diligence, ideally for UK public sector customers.
  • Working knowledge of CCS framework security schedules, G-Cloud Schedule 9A, Cyber Essentials Plus and the NCSC Cyber Assessment Framework.
  • Good understanding of data protection and UK GDPR, including Articles 28 and 33.
Supplier and service governance
  • Tracking a managed service or supplier against contract and service levels and preparing service reviews.
  • Third-party risk management, including experience of a TPRM platform (desirable).
Incident management
  • Coordinating security incidents, keeping records and preparing customer or regulatory notifications.
Technical literacy
  • Enough understanding of cloud, SIEM and vulnerability management to read a service report or scan output and ask the right questions. You will not be writing detection rules.
Communication and ways of working
  • Clear, precise written English. Your reports and evidence will be read by customers, auditors and executives.
  • Organised and self-directed, able to keep several governance cycles moving in parallel and chase others to dates politely and persistently.
Qualifications
  • ISO 27001 Lead Implementer or Lead Auditor, CISM, CRISC, CISMP or equivalent (desirable).
Diversity, Equity and Inclusion

If you're excited about this role but your experience doesn't align perfectly, we encourage you to apply anyway and tell us more about yourself. You may be just the right candidate for this or other roles.

We believe that seeing the world from all sorts of angles makes life better for all. We want you to know that the things that make you an individual, like your identity, age, ethnicity, religion, ability and background, are things that we choose to celebrate and support.

We are a scale-up company, and as we continue to grow, we are passionate that having a diverse, inclusive and authentic workplace will remain at our core. We are creating an inclusive environment where our people can thrive.

Our values are aligned and at the heart of everything we do. We are respectful, united, rigorous, relentless and ethical.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Lead
Cyber Security Lead

Chambers & Partners • Greater London

Hybrid
GBP 90,000 - 130,000
Quality Assurance Analyst
Quality Assurance Analyst

Clue Software • West of England

On-site
GBP 45,000 - 55,000
Security Analyst
Security Analyst

Peaple Talent • West of England

Hybrid
GBP 45,000 - 50,000
25 days annual leave
Pension scheme: 5% employee + 4% employer
Investment in certifications
Information Assurance Technical Security Specialist
Information Assurance Technical Security Specialist

Thales • Crawley

On-site
GBP 60,000 - 90,000
Private medical insurance
Pension contribution
Relocation support
+2
Director, Cyber Hygiene and Metrics Engineering Lead
Director, Cyber Hygiene and Metrics Engineering Lead

CLS Group • Greater London

Hybrid
GBP 120,000 - 180,000
Hybrid working 2 days in office
Private medical
Life insurance
+3
Information Security Manager
Information Security Manager

Recognise Bank • Greater London

Hybrid
GBP 90,000 - 100,000
Competitive Time Off
Work From Anywhere
Hybrid Working
+4
Information Security Specialist
Information Security Specialist

deciphex • Kidlington, Exeter

On-site
GBP 70,000 - 110,000
Cyber Security Manager
Cyber Security Manager

LLOYD'S REGISTER INTERNATIONAL • Greater London

Hybrid
GBP 73,000 - 80,000
35 hour working week
28 days holiday + bank holidays
Excellent pension scheme
+1
Information Assurance Technical Security Specialist
Information Assurance Technical Security Specialist

Thales • West of England

On-site
GBP 70,000 - 90,000
Market leading training
Private healthcare
Relocation support
Software Developer - C#
Software Developer - C#

Clue Software • United Kingdom

Hybrid
GBP 40,000 - 60,000
25 days annual leave
Enhanced workplace Pension scheme
Life Insurance
+2