Senior GRC Analyst

Broster Buchanan

Bolton

On-site

GBP 111,000 - 166,000

Full time

11 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Broster Buchanan is seeking a Senior GRC Analyst Contractor to lead governance, risk and compliance initiatives for a growing organisation in a fast-paced environment.

You will work with senior stakeholders to strengthen security governance, support NIS2 and PCI DSS readiness, and drive ISO 27001 aligned ISMS activities across the business.

Qualifications

  • 5+ years in Information Security Governance, Risk & Compliance.
  • Experience supporting regulatory audits and certifications.
  • Strong background in information security risk assessment and ISMS maintenance.
  • Practical knowledge of ISO 27001, NIST CSF, NIS2 and PCI DSS.

Responsibilities

  • Support and enhance information security governance framework.
  • Maintain risk, audit and remediation processes and reporting.
  • Coordinate evidence collection for audits and remediation tracking.
  • Contribute to ISMS, policy governance and control assurance.
  • Lead security awareness and training campaigns.

Skills

Information Security Governance
Risk assessment
ISMS
NIS2
ISO 27001
PCI DSS
CISSP
CISM
CRISC
PCI DSS 4.x
NIST CSF

Tools

NIST CSF
PCI DSS 4.x
ISMS frameworks

Job description

Senior GRC Analyst Contractor | Governance, Risk & Compliance | NIS2 | PCI DSS | ISO 27001

An exciting opportunity has arisen for an experienced Senior GRC Analyst to join a growing organisation on a fixed term contract basis, supporting a range of strategic information security, governance, risk and compliance initiatives.

Working closely with senior stakeholders across technology and business functions, you will play a key role in strengthening security governance, improving audit readiness, and supporting compliance with industry and regulatory frameworks including NIS2, PCI DSS and ISO 27001.

This is a hands‑on delivery‑focused role suited to an experienced GRC professional who is comfortable operating independently, managing multiple workstreams, and delivering practical, risk‑based outcomes in a fast‑paced environment.

Key Responsibilities
  • Support and enhance the organisation's information security governance framework
  • Maintain and improve risk, audit and remediation processes
  • Produce clear and concise governance reporting for senior stakeholders
  • Ensure security controls, risks, policies and assurance activities remain aligned
NIS2 Audit Readiness
  • Support NIS2 compliance and audit preparation activities
  • Review control effectiveness and regulatory requirements
  • Coordinate evidence collection and validation
  • Track audit findings and remediation plans through to completion
Project Security Risk Assessments
  • Conduct information security risk assessments for projects, technology changes and business initiatives
  • Identify risks relating to cloud services, infrastructure, suppliers, identity management and data processing
  • Recommend practical security controls and remediation actions
ISMS & Policy Governance
  • Support ongoing maintenance and improvement of an ISO 27001‑aligned ISMS
  • Review and update security policies, standards and procedures
  • Coordinate policy reviews, approvals and governance activities
  • Perform control assurance and effectiveness reviews
Security Awareness & Culture
  • Support security awareness and cyber education programmes
  • Coordinate mandatory training campaigns and phishing simulations
  • Develop targeted awareness content based on emerging threats and organisational risks
  • Monitor effectiveness and participation metrics
PCI DSS Compliance
  • Support PCI DSS compliance activities and assessments
  • Coordinate evidence collection and control validation
  • Assist with gap analysis, remediation planning and action tracking
  • Support engagement with external assessors and auditors
Third-Party Risk Management
  • Conduct supplier security reviews and due diligence assessments
  • Evaluate third-party controls, certifications and risk posture
  • Collaborate with internal stakeholders to manage supplier-related risks
Skills & Experience

You'll bring strong information security governance and compliance experience, along with the confidence to engage stakeholders at all levels.

  • 5+ years' experience in Information Security Governance, Risk & Compliance
  • Experience supporting regulatory, certification or external audits
  • Strong background in information security risk assessment
  • Experience maintaining and improving ISMS frameworks
  • Practical knowledge of ISO 27001, NIST CSF, NIS2, PCI DSS or similar frameworks
  • Experience coordinating evidence, audits and remediation activities across multiple stakeholders
  • Experience supporting NIS2 implementation or audit readiness programmes
  • Detailed knowledge of PCI DSS 4.x
  • ISO 27001 implementation or audit experience
  • Security awareness programme delivery experience
  • Third-party risk management experience
  • Experience within retail, payments, critical infrastructure or multinational organisations
  • Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor or PCI Professional
Why Apply?

This is an opportunity to take ownership of key governance and compliance workstreams, influence security decision-making, and contribute to high-profile regulatory and assurance programmes within a complex organisation.

You'll work alongside experienced security and business leaders while helping drive meaningful improvements across governance, risk and compliance practices.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
GRC Analyst - Cyber Security
GRC Analyst - Cyber Security

TEC Partners Limited • Enfield

On-site
GBP 50,000 - 60,000
Fully remote
IT GRC Senior Analyst
IT GRC Senior Analyst

Nigel Wright Recruitment • Newcastle upon Tyne

Hybrid
GBP 70,000 - 90,000
Hybrid work policy
IT Information Security Analyst - Compliance
IT Information Security Analyst - Compliance

Adecco • West Midlands

Hybrid
GBP 45,000 - 55,000
Senior Information Security (GRC) Specialist
Senior Information Security (GRC) Specialist

La Fosse • Greater London

Hybrid
GBP 81,000 - 99,000
Pension
Benefits
Information Security Officer
Information Security Officer

Maxwell Bond • Reading

Hybrid
GBP 55,000 - 57,000
GRC Specialist
GRC Specialist

Oliver Bernard • United Kingdom

On-site
GBP 85,000 - 130,000
Information Security Specialist (GRC)
Information Security Specialist (GRC)

La Fosse Associates • Greater London

Hybrid
GBP 54,000 - 90,000
Pension
Governance, Risk & Compliance (GRC) Consultant
Governance, Risk & Compliance (GRC) Consultant

Low Carbon Contracts Company • City Of London

Hybrid
GBP 111,000 - 148,000
Governance, Risk & Compliance (GRC) Consultant
Governance, Risk & Compliance (GRC) Consultant

Low Carbon Contracts Company • Greater London

On-site
GBP 111,000 - 148,000