Turn this role into an interview — a resume and cover letter built around what this employer wants.
Gresham is seeking a GRC Analyst to manage client information security responses, maintain evidence repositories, and coordinate ESG assessments. The role ensures accuracy, timeliness, and alignment with SOC/ISO and CSP requirements across product lines.
You will support audits, risk registers, and security reporting, drawing on knowledge of frameworks such as ISO27001, SOC 1/2, NIST CSF, and SWIFT CSP, while engaging with cross-functional teams in a regulated financial services tech environment.
Gresham is a global financial services technology company specialising in enterprise data automation. We help financial institutions ensure that their operational, regulatory and management data is complete, accurate, timely and fully auditable — particularly within complex environments where data is distributed across multiple systems.
Our solutions automate data controls, reconciliations, workflows and exception management, enabling clients to reduce operational risk, strengthen data governance and enhance confidence in reporting across highly regulated environments. Serving both buy-side and sell-side organisations worldwide, Gresham partners with clients to deliver trusted, transparent and resilient data operations.
The GRC (Governance, Risk & Compliance) Analyst is responsible for managing and responding to client-initiated information security due diligence requests, including vendor security questionnaires (VSQs), request for proposal (RFP) security schedules, and ESG-related assessments. Operating as part of the Information Security function and reporting directly to the Information Security Manager, the post-holder serves as a point of coordination between Gresham’s security, legal, and commercial teams and its clients’ procurement and risk functions.
As a financial services technology provider operating in highly regulated environments, Gresham’s clients subject the business to rigorous third-party risk assessments covering data security, operational resilience, access controls, and increasingly, ESG and sustainability criteria. The GRC Analyst ensures these assessments are completed accurately, consistently, and within agreed timescales, thereby directly supporting client acquisition, retention, and the organisation’s broader information security governance framework.
Note: Gresham’s product portfolio — which includes Control Cloud, Connect Cloud, Opus EDM, Prime EDM, and Pulse Data — spans multiple certification regimes, and different products and deployment contexts carry distinct assurance obligations. Candidates are not expected to hold deep expertise across all frameworks, but should demonstrate an ability to navigate and respond to client questions that reference these standards in combination.
At Gresham, we are committed to building a diverse and inclusive workforce that reflects the communities we serve. We actively encourage applications from individuals of all backgrounds and are dedicated to providing a workplace where everyone feels valued, respected and supported.
We make employment decisions based on merit, skills and potential, and do not discriminate based on any protected characteristic. We are also committed to making reasonable adjustments throughout the recruitment process and employment lifecycle.