Security GRC Analyst (UK Remote), Newcastle upon Tyne
Client: Turnitin, LLC
Location: Newcastle upon Tyne, United Kingdom
Job Category: Other
EU work permit required: Yes
Job Reference: 709d5ef48efc
Job Views: 6
Posted: 24.04.2025
Expiry Date: 08.06.2025
Job Description
Turnitin is seeking an experienced Security GRC Analyst to join our Security & Compliance team. The Sr Security GRC Analyst will be responsible for ensuring that our information and cloud systems comply with relevant regulatory frameworks, industry standards, and internal policies. They will collaborate with various departments, monitor compliance, conduct assessments, and support initiatives to identify and mitigate risks.
We are looking for someone with strong analytical ability, attention to detail, effective communication, compliance experience, and a willingness to learn. This role requires hands-on work, critical thinking, and the ability to find new solutions for compliance.
This role reports to the GRC Information Security Manager.
Responsibilities
- Maintain compliance tracking capabilities to ensure adherence to Turnitin’s security program and standards such as NIST CSF, NIST 800-53, SOC 2, TX-RAMP, and PCI DSS.
- Conduct risk and compliance assessments, audits, and evaluations to identify gaps.
- Lead preparation and audit activities for SOC 2 Type 2 compliance.
- Collaborate with internal teams and external auditors for reviews.
- Respond to security questionnaires from customers in collaboration with sales and support teams.
- Support Third-Party Risk Management (TPRM) Program and conduct third-party risk assessments.
- Complete user access reviews.
- Administer the GRC platform.
- Develop and document security policies, standards, and processes.
- Provide security awareness and phishing training to employees and promote a culture of security and compliance.
- Coordinate phishing testing.
- Work with DevOps, IT, Legal, Engineering, People Team, and other departments to integrate security controls and policies.
- Suggest improvements and automation for team processes.
Qualifications
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- 3+ years of experience in Information Security or Cybersecurity Compliance.
- Professional certifications such as CCSK, AWS Cloud Practitioner, or similar.
- Familiarity with cybersecurity frameworks and standards like NIST, SOC 2, TX-RAMP, PCI DSS.
- Knowledge of risk management and security best practices.
- Experience with security controls assessment, risk mitigation, and audits.
- Understanding of AWS Cloud Infrastructure security.
- Experience with security impact analysis for system changes.
- Experience with security reviews and risk assessments to ensure compliance.
- Experience conducting third-party risk assessments.
- Contract review experience related to security requirements.
- Highly organized and proactive, capable of managing multiple responsibilities.
Preferred Skills
- Experience with SOC 2 audits or NIST authorizations.
- Experience with Jira and Confluence.
- Hands-on experience with Wiz, KnowBe4, Hyperproof.
- Knowledge of security assessment of cloud services (AWS).
- Entry-level cybersecurity certifications such as Security+, GSEC, or CISSP.
Additional Information
Turnitin offers a comprehensive Total Rewards package, including competitive pay, health and wellness programs, generous time off, and a remote-centric culture that supports purpose and accountability. We value diversity and inclusion, and our mission is to ensure the integrity of global education and improve learning outcomes.