Enable job alerts via email!

Security GRC Analyst (UK Remote)

TN United Kingdom

Leeds

Remote

GBP 45,000 - 70,000

Full time

3 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a skilled Security GRC Analyst to join their dynamic Security & Compliance team. This role involves ensuring compliance with various regulatory frameworks and industry standards while collaborating with multiple departments to identify and mitigate risks. The ideal candidate will possess strong analytical abilities, attention to detail, and effective communication skills, making a significant impact on the organization’s security posture. If you are passionate about compliance and security and thrive in a collaborative environment, this is an exciting opportunity for you to grow and contribute.

Qualifications

  • 3+ years in Information Security or Cybersecurity Compliance.
  • Familiarity with NIST, SOC 2, TX-RAMP, and PCI DSS.

Responsibilities

  • Conduct risk and compliance assessments and audits.
  • Maintain compliance tracking capabilities for security standards.
  • Collaborate with internal teams for audit and compliance reviews.

Skills

Analytical Skills
Attention to Detail
Effective Communication
Risk Management
Compliance Experience
Critical Thinking

Education

Bachelor’s degree in Computer Science
Professional certification (CCSK, AWS)

Tools

Jira
Confluence
Wiz
KnowBe4
Hyperproof

Job description

Social network you want to login/join with:

Turnitin is seeking an experienced Security GRC Analyst to join our Security & Compliance team. The Sr Security GRC Analyst will be responsible for ensuring that our information and cloud systems comply with relevant regulatory frameworks, industry standards, and internal policies. They will also collaborate with various departments, monitor compliance, conduct assessments, and support initiatives to identify and mitigate risks.

We are looking for someone who brings strong analytical ability, attention to detail, effective communication, compliance experience, and the willingness to continuously learn. This role requires hands-on work, critical thinking, and the ability to find new solutions for compliance.

This role reports to the GRC Information Security Manager.

Responsibilities:
  • Maintain compliance tracking capabilities to help ensure adherence with Turnitin’s security program and industry standards such as NIST CSF, NIST 800-53, SOC 2, TX-RAMP, and PCI DSS.
  • Conduct risk and compliance assessments, audits, and risk evaluations to identify potential risks and compliance gaps.
  • Lead preparation and audit activities required to maintain our SOC 2 Type 2.
  • Collaborate with internal teams and external auditors for audit and compliance reviews.
  • Collaborate with sales and customer support teams to respond to security questionnaires and security posture questions from customers.
  • Support TPRM Program and conduct third-party risk assessments.
  • Complete user access reviews.
  • Administration of GRC platform.
  • Participate in the development and documentation of security policies, standards, and processes to align with the company's information security strategy.
  • Provide security awareness and phishing training for employees and promote a culture of security and compliance.
  • Coordinate phishing testing.
  • Collaborate with DevOps, IT, Legal, Engineering, People Team, and other departments to ensure security controls and policy requirements are integrated into systems and business processes.
  • Provide input on ways to improve and automate team processes.
Qualifications:
  • Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent experience).
  • 3+ years of experience in a role related to Information Security or Cybersecurity Compliance.
  • Professional certification such as CCSK, AWS Cloud Practitioner, or other related industry certification.
  • Familiarity with cybersecurity frameworks and regulatory standards such as NIST, SOC 2, TX-RAMP, and PCI DSS.
  • Familiarity with risk management and security best practices.
  • Experience with assessing security controls, risk mitigation strategies, and audit procedures.
  • Understanding of concepts related to AWS Cloud Infrastructure and security.
  • Experience conducting security impact analysis for system changes.
  • Experience conducting periodic internal security reviews or risk assessments to ensure compliance procedures and technical configurations are followed.
  • Experience conducting third-party risk assessments.
  • Contract review experience for security requirements.
  • Highly organized and proactive individual capable of managing multiple responsibilities and delivering results.
Preferred Skills:
  • Experience running SOC 2 audits or NIST-based authorizations.
  • Experience using Jira and Confluence for project and task management.
  • Hands-on experience with Wiz, KnowBe4, and Hyperproof.
  • Experience conducting third-party risk assessments.
  • Knowledge of security assessment of cloud technology and services (AWS).
  • Entry-level cybersecurity certifications such as Security+, GIAC GSEC, or ISC2 Certified in Cybersecurity.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.