Security GRC Analyst

Clue

West of England

Hybrid

GBP 60,000 - 70,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Clue is seeking a Security Governance, Risk and Compliance Analyst to maintain our ISO 27001 ISMS, manage the risk register, and coordinate customer security assurance and incident responses. You will work between the CISO, DevSecOps, and IT Operations to ensure evidence, obligations and governance are current.

You will help drive risk-based decision making, oversee supplier assessments, and ensure regulatory and contractual security requirements are met while embracing AI tools appropriately.

Qualifications

  • Experience working within an ISO 27001 ISMS, ideally in a SaaS organisation.
  • Maintaining a risk register and treatment plans with senior risk owners.
  • Responding to customer security questionnaires and due diligence.
  • Coordinating incident response and regulatory notifications.
  • Managing third-party risk and supplier assurance processes.

Responsibilities

  • Administer the information security policy and ISMS documentation.
  • Maintain ISO 27001:2022 certification and related evidence.
  • Lead customer security assurance and due diligence responses.
  • Coordinate risk register reviews and risk treatment with sponsors.
  • Oversee incident coordination, notifications and post-incident actions.
  • Manage third-party risk assessments and supplier reviews.
  • Maintain governance cadence across security forums and reporting.

Skills

Information security
Customer assurance
Third-party governance
Incident management
Technical literacy
Communication

Education

ISO27001 Lead Implementer/Lead Auditor, CISM, CRISC, CISMP or equivalent

Tools

TPRM platform

Job description

Role specifics
  • Salary range: £60,000 - 70,000
  • Reporting to: Chief Information Officer
  • Key stakeholders: Platform and Development, Product, Sales and Onboarding, IT Operations, Legal Counsel and DPO, People team, our managed security operations provider, customer security and assurance teams
  • Organisational Framework Level: Level 3 - Professional Specialist
  • Eligible to obtain UK security clearance (SC). UK-based.
  • Minimum requirement of 2 days per week in our Bristol office
About you/ Job Summary

As a Security Governance, Risk and Compliance Analyst, you keep our information security management system current, evidenced and moving. Clue supplies software to UK public sector, Sports and law enforcement, and those customers expect us to show, not just say, that our controls work. You will administer our ISO 27001 ISMS day to day, maintain the risk register, lead customer security assurance, run the supplier assessment cycle and coordinate the record-keeping and communications when an incident occurs. The CISO leads the security function, sets direction, and holds accountability; the Security Engineering team and IT own the technical controls. Your job is to do the work between them intelligently: know where every piece of evidence lives, what we have promised each customer, what is due next, and who needs chasing.

At Clue we are actively adopting AI to improve our products and workflows. You will bring curiosity and a willingness to use AI tools to work faster and more accurately, while knowing where they should not be trusted.

Key Accountabilities
ISMS and certification
  • Administer the information security policy, set: review schedule, publication and acknowledgement records, with the CISO approving changes.
  • Maintain ISO 27001:2022 certification: statement of applicability, evidence library, internal audit scheduling and external audit coordination.
  • Work with IT to maintain security accreditations such as Cyber Essentials Plus and our ISO accreditations, plus the evidence set for the NCSC Cyber Assessment Framework where customers require it.
  • Maintain the security exceptions register, tracking time-limited approvals and named risk sponsors.
  • Pen-test and crisis simulation exercise management and coordination, alongside the CISO.
Risk management
  • Maintain the risk register and apply the scoring model set by the CISO. Keep entries current, sponsored and treated.
  • Prepare and coordinate the monthly risk register review with executive risk sponsors, and track treatment plans to closure.
  • Draft register entries from audit findings, incident lessons, threat assessments and customer requirements, for CISO review, each with a proposed owner.
  • Maintain the list of security-related product roadmap requests and coordinate prioritisation between the CISO and Product.
Customer assurance and contractual compliance
  • Lead customer security assurance: draft questionnaire responses, assemble evidence packs and handle due diligence requests, drawing technical input from the DevSecOps Engineer and IT Operations.
  • Maintain the single record of every security commitment made to a customer.
  • Carry out compliance checks of customer environments before go-live and report the results to the CISO for sign-off.
  • Track our obligations under CCS framework security schedules and G-Cloud 15 Call-Off Schedule 9A, and maintain the evidence for each.
  • Produce customer-facing assurance reporting, including the monthly vulnerability report within five working days of month end.
Security operations governance
  • Coordinate the day-to-day relationship with our managed security operations provider: track service levels, prepare monthly service reviews and maintain the detection improvement backlog.
  • Track vulnerability remediation against contractual windows, record exceptions and report performance.
  • Maintain the protective monitoring standard and the logging and monitoring evidence an assurance review will test.
  • Keep a record of threat intelligence intake from NCSC and other sources, and of the actions taken.
Incident management
  • Act as incident coordinator: convene the response channel, keep the record, apply the severity matrix and escalation path without discretion, and track actions to closure. The CISO chairs incidents and coordinates Clue response.
  • Prepare and track customer and regulatory notifications, including any contractual out of hours customer notification and the UK GDPR 72-hour ICO window, with Legal and the DPO.
  • Maintain the incident register, organise post-incident reviews and track corrective actions.
  • Maintain the annualcrisis exercise plan and organise the exercises.
Third-party risk management
  • Operate the supplier assurance process and platform: onboard, tier and reassess suppliers on a risk-based cycle.
  • Keep a named executive sponsor recorded for each material supplier and chase their review obligations.
People, access and awareness
  • Draft security awareness and training requirements and assure delivery with the People team.
  • Support the People Director with the vetting policy and collect the evidence that personnel security controls operate.
  • Collect and check access governance evidence: review schedules, privileged access records and joiner, mover and leaver records.
  • Support the Security Champions network with process guidance.
Governance and reporting
  • Organise the governance cadence: weekly security governance, fortnightly Security Steering Group, monthly risk review and quarterly Information Security Management Forum. Agendas, papers, minutes and actions.
  • Draft sponsor and board-level reporting for the CISO, sourced and consistent across documents.
  • Track every security action to a named owner and a date, and report status without spin.
Key role measures
  • ISO 27001 certification maintained with no major nonconformities; audit findings closed within agreed date
  • Risk register currency: every entry reviewed within its cycle, sponsored, and with a live treatment plan
  • Customer assurance turnaround: questionnaires and evidence requests answered within agreed SLAs with no unsupported commitments
  • Vulnerability remediation reported accurately against contractual windows, with exceptions recorded
  • Incident notifications made within contractual and regulatory windows; post-incident actions closed
  • Supplier coverage: all material suppliers tiered, assessed and sponsored
Experience and skills
Our ideal candidate would have experience in the following areas
Information security management
  • Working within an ISO 27001 ISMS through certification or surveillance audits, ideally in a SaaS organisation.
  • Maintaining a risk register and working with senior risk owners to keep entries current and treated.
  • Keeping exceptions, policies and evidence to an audit-ready standard.
Customer and public sector assurance
  • Responding to customer security questionnaires and due diligence, ideally for UK public sector customers.
  • Working knowledge of CCS framework security schedules, G-Cloud Schedule 9A, Cyber Essentials Plus and the NCSC Cyber Assessment Framework.
  • Good understanding of data protection and UK GDPR, including Articles 28 and 33.
Supplier and service governance
  • Tracking a managed service or supplier against contract and service levels and preparing service reviews.
  • Third-party risk management, including experience of a TPRM platform (desirable).
Incident management
  • Coordinating security incidents, keeping records and preparing customer or regulatory notifications.
Technical literacy
  • Enough understanding of cloud, SIEM and vulnerability management to read a service report or scan output and ask the right questions. You will not be writing detection rules.
Communication and ways of working
  • Clear, precise written English. Your reports and evidence will be read by customers, auditors and executives.
  • Organised and self-directed, able to keep several governance cycles moving in parallel and chase others to dates politely and persistently.
Qualifications
  • ISO 27001 Lead Implementer or Lead Auditor, CISM, CRISC, CISMP or equivalent (desirable).
Diversity, Equity and Inclusion

If you're excited about this role but your experience doesn't align perfectly, we encourage you to apply anyway and tell us more about yourself. You may be just the right candidate for this or other roles.

We believe that seeing the world from all sorts of angles makes life better for all. We want you to know that the things that make you an individual, like your identity, age, ethnicity, religion, ability and background, are things that we choose to celebrate and support.

We are a scale-up company, and as we continue to grow, we are passionate that having a diverse, inclusive and authentic workplace will remain at our core. We are creating an inclusive environment where our people can thrive.

Our values are aligned and at the heart of everything we do. We are respectful, united, rigorous, relentless and ethical.

Department Operations Locations Bristol Remote status Hybrid

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

Peaple Talent • West of England

Hybrid
GBP 45,000 - 50,000
25 days annual leave
Pension scheme: 5% employee + 4% employer
Investment in certifications
Quality Assurance Analyst
Quality Assurance Analyst

Clue Software • West of England

On-site
GBP 45,000 - 55,000
Cyber Security Manager
Cyber Security Manager

Applied Computing • City Of London

On-site
GBP 70,000 - 100,000
Information Security Specialist
Information Security Specialist

deciphex • Kidlington, Exeter

On-site
GBP 70,000 - 110,000
Cyber Security Manager
Cyber Security Manager

LLOYD'S REGISTER INTERNATIONAL • Greater London

Hybrid
GBP 73,000 - 80,000
35 hour working week
28 days holiday + bank holidays
Excellent pension scheme
+1
Security Analyst
Security Analyst

Doherty Associates • City Of London

On-site
GBP 35,000 - 52,000
Performance bonus
34 days annual leave
Private medical insurance
+2
Security Governance Risk & Compliance Officer
Security Governance Risk & Compliance Officer

Rowden • Bristol

Hybrid
GBP 50,000 - 60,000
Manager - Cyber Security Specialist
Manager - Cyber Security Specialist

Squarcle • West of England

On-site
GBP 65,000 - 90,000
26 days annual leave
Private medical insurance
NOW Pensions
+1
Assurance Specialist
Assurance Specialist

City Recruitment Associates • City Of London

On-site
GBP 55,000 - 90,000
Lead Security Analyst
Lead Security Analyst

Made Tech Limited • United Kingdom

On-site
GBP 90,000 - 120,000