Junior Information Security & GRC Analyst

Starling Bank

London

Hybrid

NOK 528,000 - 818,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

33 days holiday
Birthday leave
Pension scheme
Life insurance
Private Medical Insurance
Perkbox membership
EV leasing

Job summary

Engine by Starling is seeking a governance, risk & compliance professional to help mature our GRC program. You will engage with stakeholders across engineering, product and security to ensure adherence to security standards and regulatory requirements.

The role emphasises hands-on implementation, audit coordination, and continuous improvement, with hybrid working across offices, and a focus on building trust with clients and partners.

Qualifications

  • Minimum 1 year of experience in an information security role.
  • Proven experience in supporting and managing compliance efforts.
  • Strong skills in security metrics and reporting.
  • Experience with audit processes and evidence collection.

Responsibilities

  • Compliance Management: support day-to-day management of compliance programs (ISO 27001, SOC1, SOC2, CSTAR, PCI DSS/3DS).
  • Audit Support: liaise with auditors, gather evidence, track remediation of findings.
  • Risk Management: assist in risk assessments and in developing risk treatment plans.
  • Policy & Procedure Maintenance: update security policies and procedures to stay current.
  • Evidence Collection & Review: streamline evidence gathering for frameworks to ensure audit readiness.
  • Cross‑Functional Collaboration: work with Engineering, Product and Security Operations teams to embed controls.
  • Continuous Improvement: identify opportunities to improve the GRC program and related processes.
  • Security Awareness: assist in delivering security training for all employees.
  • Third‑Party Risk Assessments: evaluate vendor security posture to meet standards.

Skills

Compliance management
Audit support
Risk assessment
Policy development
Evidence collection
Cross-functional collaboration
Security awareness
GRC software
Attention to detail

Job description

Engine by Starling is seeking a governance, risk & compliance professional to help mature our GRC program. You will engage with stakeholders across engineering, product and security to ensure adherence to security standards and regulatory requirements.

The role emphasises hands-on implementation, audit coordination, and continuous improvement, with hybrid working across offices, and a focus on building trust with clients and partners.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Junior Information Security Analyst (GRC) - Engine by Starling
Junior Information Security Analyst (GRC) - Engine by Starling

Starling Bank • London

Hybrid
NOK 528,000 - 818,000
33 days holiday
Birthday leave
Pension scheme
+4
Global Programs Manager – Operations & Governance
Global Programs Manager – Operations & Governance

Starling Bank • London

Hybrid
NOK 755,000 - 1,132,000
33 days holiday (incl. public holidays
Birthday leave
Buy/sell extra days
+10
Incident Response Analyst - 24/7 Security Ops
Incident Response Analyst - 24/7 Security Ops

Starling Bank • London

Hybrid
NOK 887,000 - 1,331,000
25 days holiday
Birthday leave
Volunteer time
+4
Cyber GRC Controls SME
Cyber GRC Controls SME

Allscreens Nationwide Ltd • London

Hybrid
NOK 1,522,000 - 2,107,000
Hybrid working
Head of Information Security and Privacy
Head of Information Security and Privacy

Morgan Law • London

Hybrid
NOK 1,141,000 - 1,902,000
Hybrid work
Competitive benefits
GRC Intern: Risk, Compliance & Security (Hybrid/Remote)
GRC Intern: Risk, Compliance & Security (Hybrid/Remote)

BCM One , Inc. • London

Hybrid
NOK 170,000 - 255,000
Security Consultant in Oslo - GRC, ISO, NIS2, GDPR
Security Consultant in Oslo - GRC, ISO, NIS2, GDPR

Tenth Revolution Group • Oslo

On-site
NOK 1,200,000 - 1,800,000
Junior InfoSec Analyst: Risk & Threat Monitoring
Junior InfoSec Analyst: Risk & Threat Monitoring

SteelAxis • Svalbard

On-site
NOK 150,000 - 204,000
Head of InfoSec & Privacy - ISO 27001 & Governance Lead
Head of InfoSec & Privacy - ISO 27001 & Governance Lead

Morgan Law • London

Hybrid
NOK 1,141,000 - 1,902,000
Hybrid work
Competitive benefits
Remote Information Security Analyst: Protect & Grow
Remote Information Security Analyst: Protect & Grow

CoreStruct Solutions • Bergen

Hybrid
NOK 124,000 - 168,000