Senior GRC Analyst Contractor | Governance, Risk & Compliance | NIS2 | PCI DSS | ISO 27001
An exciting opportunity has arisen for an experienced Senior GRC Analyst to join a growing organisation on a fixed term contract basis, supporting a range of strategic information security, governance, risk and compliance initiatives.
Working closely with senior stakeholders across technology and business functions, you will play a key role in strengthening security governance, improving audit readiness, and supporting compliance with industry and regulatory frameworks including NIS2, PCI DSS and ISO 27001.
This is a hands‑on delivery‑focused role suited to an experienced GRC professional who is comfortable operating independently, managing multiple workstreams, and delivering practical, risk‑based outcomes in a fast‑paced environment.
Key Responsibilities
- Support and enhance the organisation's information security governance framework
- Maintain and improve risk, audit and remediation processes
- Produce clear and concise governance reporting for senior stakeholders
- Ensure security controls, risks, policies and assurance activities remain aligned
NIS2 Audit Readiness
- Support NIS2 compliance and audit preparation activities
- Review control effectiveness and regulatory requirements
- Coordinate evidence collection and validation
- Track audit findings and remediation plans through to completion
Project Security Risk Assessments
- Conduct information security risk assessments for projects, technology changes and business initiatives
- Identify risks relating to cloud services, infrastructure, suppliers, identity management and data processing
- Recommend practical security controls and remediation actions
ISMS & Policy Governance
- Support ongoing maintenance and improvement of an ISO 27001‑aligned ISMS
- Review and update security policies, standards and procedures
- Coordinate policy reviews, approvals and governance activities
- Perform control assurance and effectiveness reviews
Security Awareness & Culture
- Support security awareness and cyber education programmes
- Coordinate mandatory training campaigns and phishing simulations
- Develop targeted awareness content based on emerging threats and organisational risks
- Monitor effectiveness and participation metrics
PCI DSS Compliance
- Support PCI DSS compliance activities and assessments
- Coordinate evidence collection and control validation
- Assist with gap analysis, remediation planning and action tracking
- Support engagement with external assessors and auditors
Third-Party Risk Management
- Conduct supplier security reviews and due diligence assessments
- Evaluate third-party controls, certifications and risk posture
- Collaborate with internal stakeholders to manage supplier-related risks
Skills & Experience
You'll bring strong information security governance and compliance experience, along with the confidence to engage stakeholders at all levels.
- 5+ years' experience in Information Security Governance, Risk & Compliance
- Experience supporting regulatory, certification or external audits
- Strong background in information security risk assessment
- Experience maintaining and improving ISMS frameworks
- Practical knowledge of ISO 27001, NIST CSF, NIS2, PCI DSS or similar frameworks
- Experience coordinating evidence, audits and remediation activities across multiple stakeholders
- Experience supporting NIS2 implementation or audit readiness programmes
- Detailed knowledge of PCI DSS 4.x
- ISO 27001 implementation or audit experience
- Security awareness programme delivery experience
- Third-party risk management experience
- Experience within retail, payments, critical infrastructure or multinational organisations
- Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor or PCI Professional
Why Apply?
This is an opportunity to take ownership of key governance and compliance workstreams, influence security decision-making, and contribute to high-profile regulatory and assurance programmes within a complex organisation.
You'll work alongside experienced security and business leaders while helping drive meaningful improvements across governance, risk and compliance practices.