Senior GRC Analyst

Euro Garages

Horwich

On-site

GBP 70,000 - 90,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this recruiter — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Discretionary bonus
Hybrid working
Cycle to Work
Car Scheme
Enhanced leave

Job summary

Cumberland Farms is seeking an experienced Senior GRC Analyst to join our Information Security team in Horwich. You will provide specialist support across governance, risk, and compliance, focusing on NIS2 readiness, risk assessments, ISMS, and policy governance.

Reports to Head of Information Security. This is a hands‑on, delivery‑focused role requiring independence, prioritisation, and the ability to work with diverse stakeholders across the business.

Qualifications

  • Extensive experience in Information Security GRC at senior level.
  • Proven track record supporting regulatory audits and remediation management.
  • Hands-on with ISO 27001 ISMS and policy governance.
  • Experience with NIS2, GDPR or similar frameworks.
  • Strong stakeholder management and communication skills.

Responsibilities

  • Support NIS2 audit readiness by coordinating evidence, reviews, and remediation tracking.
  • Conduct security risk assessments across projects and systems, proposing practical controls.
  • Support maintenance and improvement of the ISMS aligned to ISO 27001.
  • Review and maintain security policies, standards, and control frameworks.
  • Assess design and operation of controls and track improvements to completion.
  • Maintain cyber risk register with accurate risks, treatments, and owners.
  • Coordinate audit findings, remediation, evidence, and third‑party assessments.
  • Produce GRC reporting and metrics for senior stakeholders.

Skills

GRC governance
Security risk assessments
Regulatory compliance
NIS2 readiness
ISMS
Policy governance
Audit readiness
Stakeholder management
cyber risk management

Education

CISM
CRISC
CISSP
ISO 27001 Lead Implementer
ISO 27001 Lead Auditor

Tools

GRC platforms
ISO standards knowledge

Job description

Select how often (in days) to receive an alert:

Role: Senior GRC Analyst
Location: Horwich, BL6 6JW
Contract: Full-Time Hours / Fixed Term – 6 months

Company: EG Group

About the Role:

Cumberland Farms is looking for an experienced Senior GRC Analyst to join our Information Security team. Reporting to the Head of Information Security, you will provide specialist support across a range of information security governance, risk, and compliance workstreams.

The role will have a particular focus on NIS2 audit readiness, security risk assessments, ISMS and policy governance, cyber risk management, control assurance, and security awareness. You will work closely with stakeholders across Technology, Legal, Data Protection, Finance, HR, Project Delivery, and wider business operations, taking ownership of defined workstreams and delivering clear, practical, and audit-ready outcomes.

This is a hands-on, delivery-focused opportunity for an experienced GRC professional who can work independently, manage competing priorities, and bring structure and momentum to complex information security activities.

Why Join Cumberland Farms?

  • Discretionary performance-based bonus scheme
  • Grow your career – gain accredited qualifications, apprenticeships, and progression opportunities within a global organisation
  • Hybrid working – up to 2 days per week (dependent on role and business needs)
  • Salary Sacrifice Schemes – Cycle to Work and Car Scheme available
  • Enhanced Maternity & Paternity leave
  • Generous annual leave entitlement
  • Annual leave buy back scheme – purchase up to 5 additional days
  • Discounted gym membership – stay healthy and save on fitness costs
  • One paid volunteering day per year
  • Wellbeing facilities – space to relax and recharge
  • Free secure on-site parking
  • Dress Down Fridays
  • Free VDU eye test

What you’ll be doing:

  • Support NIS2 audit readiness by coordinating evidence, conducting readiness reviews, and tracking remediation activity.
  • Conduct proportionate security risk assessments across projects, systems, and technology changes, identifying risks and recommending practical controls.
  • Support the maintenance and continuous improvement of the ISO 27001-aligned Information Security Management System (ISMS).
  • Review and maintain information security policies, standards, procedures, and control frameworks to ensure they remain current and aligned to business requirements.
  • Assess the design and operating effectiveness of security controls, identifying gaps and tracking improvement actions through to completion.
  • Maintain the cyber risk register, ensuring risks, treatments, actions, ownership, and review dates remain accurate and up to date.
  • Coordinate audit findings, remediation activity, assurance evidence, and third-party security assessments, while supporting security awareness and phishing simulation campaigns.
  • Produce GRC reporting and metrics for senior stakeholders and governance forums, while continuously improving GRC processes, templates, and guidance.

This list is not exhaustive and may be added to or amended from time to time.

What we’re looking for:

  • Significant practical experience in Information Security Governance, Risk and Compliance at Senior Analyst, Consultant, or equivalent level.
  • Demonstrable experience supporting regulatory, certification, or external security audit readiness, including evidence coordination and remediation management.
  • Hands‑on experience with ISO 27001-aligned Information Security Management Systems and information security policy and control governance.
  • Experience conducting project and technology security risk assessments and assessing control design and operating effectiveness.
  • Strong analytical and evidence-management skills, with the ability to translate regulatory and framework requirements into practical actions.
  • Confident communication and stakeholder management skills, with the ability to engage technical and non-technical stakeholders and present to governance forums.
  • A pragmatic and business-focused approach, with the confidence to challenge weak controls, incomplete evidence, or unclear ownership.
  • Relevant qualifications such as CISM, CRISC, CISSP, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor would be advantageous, as would experience with NIS2, GRC platforms, or GDPR.

Who is Cumberland Farms?

Cumberland Farms has a proud heritage dating back to 1939 and today is part of a global retail organization serving customers and communities across multiple markets including the U.S., U.K., Germany and Benelux. With operations spanning convenience retail, foodservice, fuel, and other retail formats, our business is supported by a broad network of stores, sites, distribution operations, and support teams.

As our global organization transitions under the Cumberland Farms brand, our businesses, including those historically operating as EG Group, are coming together with shared values, capabilities, and a commitment to delivering exceptional experiences for our customers and colleagues.

Together, we are building on the strength and heritage of our businesses while creating a more connected global organization with a clear strategic direction and a continued focus on supporting our customers, colleagues, and communities across all the markets we serve.

Please note - the successful applicant will be subject to a DBS check which will be funded by EG Group.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Project Manager
Project Manager

Euro Garages • United Kingdom

Remote
GBP 50,000 - 65,000
Discretionary bonus
Hybrid working
Cycle to Work
+7
Senior GRC Analyst — Hybrid, NIS2 & ISO27001 Focus
Senior GRC Analyst — Hybrid, NIS2 & ISO27001 Focus

Euro Garages • Horwich

On-site
GBP 70,000 - 90,000
Discretionary bonus
Hybrid working
Cycle to Work
+2
Assistant Financial Controller
Assistant Financial Controller

Euro Garages • Bolton

Hybrid
GBP 50,000 - 70,000
Hybrid working
Cycle to Work scheme
Car Scheme
+4
PMO Quality and Governance Analyst
PMO Quality and Governance Analyst

Euro Garages • Horwich

Hybrid
GBP 40,000 - 60,000
Hybrid working
Discretionary bonus scheme
Cycle to Work
+6
Assistant Financial Controller
Assistant Financial Controller

Euro Garages • Horwich

Hybrid
GBP 60,000 - 75,000
Hybrid working
Bonus scheme
Career progression
+3
Information Security GRC Analyst
Information Security GRC Analyst

Cygnet • Birmingham

Hybrid
GBP 45,000 - 52,000
25 days annual leave
Bank holidays
Fully paid training
+5
Finance Manager
Finance Manager

EG Group • Horwich

Hybrid
GBP 65,000 - 90,000
Hybrid working – up to 2 days per week
Discretionary performance-based bonus
Cycle to Work scheme
+6
Information Security GRC Analyst
Information Security GRC Analyst

Cygnet Health Care Limited • Birmingham

On-site
GBP 45,000 - 52,000
Salary £45,000-£52,000
25 days annual leave
Training
+5
Credit Controller - German Speaking
Credit Controller - German Speaking

Euro Garages • Horwich

Hybrid
GBP 26,000 - 32,000
Discretionary bonus
Hybrid working
Career progression
+5
Senior GRC / Security Assurance Officer
Senior GRC / Security Assurance Officer

Rowden • West of England

Hybrid
GBP 60,000 - 80,000