it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

27 jobs found

Email me jobs like this
Refine Search
Current Search
analyst senior grc analyst
Senior Technology Governance, Risk & Compliance (GRC) Specialist
Yorkshire Water Bradford, Yorkshire
Senior Technology Governance, Risk & Compliance (GRC) Specialist Hello! Thanks for stopping by. Let us tell you about all the great reasons to join us here at Yorkshire Water: We offer a competitive salary, depending on experience £51,563 - £64,474 (band 4a) Annual incentive related bonus (£1000 maximum bonus opportunity for the performance year) Attractive pension scheme (up to 12% company contribution) Development opportunities in line with the Senior Technology GRC Specialist progression plan 25 days annual leave plus bank holidays - plus 2 extra wellness days! Life assurance cover of 4 times pensionable salary A great benefits package - choose from health cash plan scheme, critical illness insurance, dental insurance, life assurance flex and partner cover. Retail savings scheme Online GP service, cycle to work scheme, gym membership discounts and many more! Location: This role will initially be based in Bradford but we're moving our office to Leeds Valley Park in September 2026, so you'll be based there in the future - Hybrid Working Work type: Permanent. 37 hours per week, Monday - Friday. We have an exciting opportunity for a Senior Technology GRC Specialist to join the Information & Cyber Security team at Yorkshire Water and be a part of helping Yorkshire Water to provide the best service to our customers. Could this be you? What we do Everyone has an idea of what a water company does. Here in Yorkshire, we make sure that over 5.4 million people living in the region and the millions of people who visit our region each year, can rely on our services, and have clean and safe drinking water on tap and that their wastewater is taken away. But for us, it's so much more than this. We look after communities, protect the environment, and plan to look after Yorkshire's water, today, tomorrow 24/7, 365 days a year. We provide essential water and wastewater services to every corner of the Yorkshire region, and play a key role in the region's health, wellbeing, and prosperity. New environmental legislation, unprecedented levels of investment and changing expectations from customers means that this is an exciting time to discover opportunities within the water industry. Information & Cyber Security team are a key part of how we plan to meet the changing expectations of customers and regulators. Where you fit in As our Senior Technology GRC Specialist you will Lead, mentor and develop Technology GRC analysts and junior team members, ensuring the team has the skills, knowledge and capabilities required to deliver effective governance, risk and compliance activities. Champion the value of governance, risk and compliance at management level, driving cultural change and embedding best-practice GRC principles across the organisation. Support the management and continual improvement of the Technology GRC and Risk Management Frameworks, ensuring alignment with regulatory requirements, industry standards and business objectives. Build and maintain effective relationships with senior leaders, business units, auditors, regulators, vendors and external agencies to support Technology governance, risk and compliance outcomes. Lead Technology compliance monitoring, controls testing and assurance activities, managing audits, findings, remediation plans, policy exemptions and ongoing compliance obligations. Conduct and facilitate Technology risk assessments, audits and reviews, maintaining risk registers, evaluating controls and providing proportionate recommendations to mitigate risk and strengthen resilience. Provide expert advice, guidance and training on Technology governance, risk and compliance matters, enabling informed decision-making and increasing organisational awareness. Develop, implement, maintain and assure Technology policies, standards and procedures, ensuring they remain effective, compliant and aligned with recognised frameworks and best practice. Support Technology incident investigations and regulatory reporting requirements, coordinating with stakeholders and data owners to ensure incidents are effectively managed and resolved in accordance with legal and company obligations. Manage Technology GRC reporting, metrics, KPIs and KRIs, while driving continuous improvement, influencing stakeholders, supporting commercial objectives and fostering strong collaboration across the organisation. What skills & qualifications you will need Certification in information technology, Computer Science, Information Systems or a related discipline, or equivalent demonstrable industry experience. Proven experience in Technology Governance, Risk and Compliance, with at least three years operating in a senior specialist or leadership role. Strong track record of partnering with senior leaders and stakeholders to provide expert advice, guidance and training on governance, risk and compliance matters. Comprehensive knowledge of recognised Technology GRC frameworks, standards and methodologies, including COBIT, ITIL, ISO 27001, NIST and GDPR. Highly developed influencing, negotiation and stakeholder management skills, with the ability to build credibility, drive engagement and inspire positive change. Excellent analytical, problem-solving and decision-making capabilities, with experience identifying, assessing and mitigating Technology risks through practical and effective controls. Strong communication, presentation, organisational and project management skills, with the ability to explain complex technical and compliance concepts to a wide range of audiences and manage competing priorities effectively. Demonstrates high levels of professionalism, integrity and discretion, alongside a proactive, innovative mindset and the ability to adapt to evolving technologies, risks and regulatory requirements. You will also benefit from having Experience operating in a strategic and/or operational leadership role within a commercial and/or highly regulated environment, with the ability to balance business objectives and regulatory obligations. Demonstrable experience in Technology and Information Security incident management and investigations, including working within established governance and reporting frameworks. Good understanding of General Data Protection Regulation (GDPR) requirements, with practical experience of working alongside legal, audit and compliance teams to ensure regulatory adherence. Proven experience conducting Technology compliance reviews and audits, alongside strong stakeholder, vendor and third-party management and negotiation skills. Although we operate 24 hours a day, 365 days a year, it's important to us that we support flexible working patterns and job share options (when we can), to help you make the best of both your work and home life. We know that juggling childcare responsibilities or getting that ideal work/life balance isn't always easy! Do we sound like your cup of tea? If you've got experience as a Senior Technology GRC Specialist and want to help us deliver great service for our customers whilst looking after the environment, then be sure to apply today to find out what a career with Yorkshire Water can offer you. If successful for the role, you will be required to undergo pre-employment checks that will include a Basic Disclosure Check, carried out through a Third-Party Company, prior to commencing employment. Depending on the role, you may also be required to go through the security vetting process for either a Counter Terrorist Check or Security Check clearance. All our roles are subject to a medical questionnaire, and further medicals when required. We are committed to removing barriers and ensuring our recruitment process is accessible to everyone. We offer a range of adjustments to make your application experience as comfortable and straightforward as possible. If you have an accessibility need, disability, or condition that requires changes to the recruitment process, please include this information in your application. We will then discuss any reasonable adjustments required. Kelda Group reserve the right to close this position before the published closing date, should the need occur. We therefore advise that you complete and submit your application as soon as possible.
18/07/2026
Full time
Senior Technology Governance, Risk & Compliance (GRC) Specialist Hello! Thanks for stopping by. Let us tell you about all the great reasons to join us here at Yorkshire Water: We offer a competitive salary, depending on experience £51,563 - £64,474 (band 4a) Annual incentive related bonus (£1000 maximum bonus opportunity for the performance year) Attractive pension scheme (up to 12% company contribution) Development opportunities in line with the Senior Technology GRC Specialist progression plan 25 days annual leave plus bank holidays - plus 2 extra wellness days! Life assurance cover of 4 times pensionable salary A great benefits package - choose from health cash plan scheme, critical illness insurance, dental insurance, life assurance flex and partner cover. Retail savings scheme Online GP service, cycle to work scheme, gym membership discounts and many more! Location: This role will initially be based in Bradford but we're moving our office to Leeds Valley Park in September 2026, so you'll be based there in the future - Hybrid Working Work type: Permanent. 37 hours per week, Monday - Friday. We have an exciting opportunity for a Senior Technology GRC Specialist to join the Information & Cyber Security team at Yorkshire Water and be a part of helping Yorkshire Water to provide the best service to our customers. Could this be you? What we do Everyone has an idea of what a water company does. Here in Yorkshire, we make sure that over 5.4 million people living in the region and the millions of people who visit our region each year, can rely on our services, and have clean and safe drinking water on tap and that their wastewater is taken away. But for us, it's so much more than this. We look after communities, protect the environment, and plan to look after Yorkshire's water, today, tomorrow 24/7, 365 days a year. We provide essential water and wastewater services to every corner of the Yorkshire region, and play a key role in the region's health, wellbeing, and prosperity. New environmental legislation, unprecedented levels of investment and changing expectations from customers means that this is an exciting time to discover opportunities within the water industry. Information & Cyber Security team are a key part of how we plan to meet the changing expectations of customers and regulators. Where you fit in As our Senior Technology GRC Specialist you will Lead, mentor and develop Technology GRC analysts and junior team members, ensuring the team has the skills, knowledge and capabilities required to deliver effective governance, risk and compliance activities. Champion the value of governance, risk and compliance at management level, driving cultural change and embedding best-practice GRC principles across the organisation. Support the management and continual improvement of the Technology GRC and Risk Management Frameworks, ensuring alignment with regulatory requirements, industry standards and business objectives. Build and maintain effective relationships with senior leaders, business units, auditors, regulators, vendors and external agencies to support Technology governance, risk and compliance outcomes. Lead Technology compliance monitoring, controls testing and assurance activities, managing audits, findings, remediation plans, policy exemptions and ongoing compliance obligations. Conduct and facilitate Technology risk assessments, audits and reviews, maintaining risk registers, evaluating controls and providing proportionate recommendations to mitigate risk and strengthen resilience. Provide expert advice, guidance and training on Technology governance, risk and compliance matters, enabling informed decision-making and increasing organisational awareness. Develop, implement, maintain and assure Technology policies, standards and procedures, ensuring they remain effective, compliant and aligned with recognised frameworks and best practice. Support Technology incident investigations and regulatory reporting requirements, coordinating with stakeholders and data owners to ensure incidents are effectively managed and resolved in accordance with legal and company obligations. Manage Technology GRC reporting, metrics, KPIs and KRIs, while driving continuous improvement, influencing stakeholders, supporting commercial objectives and fostering strong collaboration across the organisation. What skills & qualifications you will need Certification in information technology, Computer Science, Information Systems or a related discipline, or equivalent demonstrable industry experience. Proven experience in Technology Governance, Risk and Compliance, with at least three years operating in a senior specialist or leadership role. Strong track record of partnering with senior leaders and stakeholders to provide expert advice, guidance and training on governance, risk and compliance matters. Comprehensive knowledge of recognised Technology GRC frameworks, standards and methodologies, including COBIT, ITIL, ISO 27001, NIST and GDPR. Highly developed influencing, negotiation and stakeholder management skills, with the ability to build credibility, drive engagement and inspire positive change. Excellent analytical, problem-solving and decision-making capabilities, with experience identifying, assessing and mitigating Technology risks through practical and effective controls. Strong communication, presentation, organisational and project management skills, with the ability to explain complex technical and compliance concepts to a wide range of audiences and manage competing priorities effectively. Demonstrates high levels of professionalism, integrity and discretion, alongside a proactive, innovative mindset and the ability to adapt to evolving technologies, risks and regulatory requirements. You will also benefit from having Experience operating in a strategic and/or operational leadership role within a commercial and/or highly regulated environment, with the ability to balance business objectives and regulatory obligations. Demonstrable experience in Technology and Information Security incident management and investigations, including working within established governance and reporting frameworks. Good understanding of General Data Protection Regulation (GDPR) requirements, with practical experience of working alongside legal, audit and compliance teams to ensure regulatory adherence. Proven experience conducting Technology compliance reviews and audits, alongside strong stakeholder, vendor and third-party management and negotiation skills. Although we operate 24 hours a day, 365 days a year, it's important to us that we support flexible working patterns and job share options (when we can), to help you make the best of both your work and home life. We know that juggling childcare responsibilities or getting that ideal work/life balance isn't always easy! Do we sound like your cup of tea? If you've got experience as a Senior Technology GRC Specialist and want to help us deliver great service for our customers whilst looking after the environment, then be sure to apply today to find out what a career with Yorkshire Water can offer you. If successful for the role, you will be required to undergo pre-employment checks that will include a Basic Disclosure Check, carried out through a Third-Party Company, prior to commencing employment. Depending on the role, you may also be required to go through the security vetting process for either a Counter Terrorist Check or Security Check clearance. All our roles are subject to a medical questionnaire, and further medicals when required. We are committed to removing barriers and ensuring our recruitment process is accessible to everyone. We offer a range of adjustments to make your application experience as comfortable and straightforward as possible. If you have an accessibility need, disability, or condition that requires changes to the recruitment process, please include this information in your application. We will then discuss any reasonable adjustments required. Kelda Group reserve the right to close this position before the published closing date, should the need occur. We therefore advise that you complete and submit your application as soon as possible.
Lead Analyst - Data Products & Integrity, Compliance Data Enablement
7360-Janssen-Cilag Limited Legal Entity High Wycombe, Buckinghamshire
Company Overview At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at Job Summary Legal & Compliance / Health Care Compliance. Lead Analyst - Data Products & Integrity, Compliance Data Enablement, located in New Brunswick, NJ or other J&J location in the Americas, EMEA or ASPAC. Reporting to the Senior Manager, Compliance Data Enablement. Responsibilities Design, build, and maintain curated, reusable datasets and data products for the global HCC data ecosystem, including transparency reporting. Design and implement data quality controls within data products to improve completeness, accuracy, consistency, and timeliness. Proactively identify root causes of data quality issues and partner with process and system owners to prevent recurring defects. Contribute to the data product lifecycle, including intake, design, delivery, maintenance, issue management, and continuous improvement. Structure data for analytics, audit, compliance monitoring, reporting, and business consumption. Support ad hoc data requests, rapid insights, PoCs, and pilots by providing fit for purpose data assets and practical guidance. Participate in a Data Concierge model to triage incoming data requests, provide rapid insights, or route needs into structured data product development. Partner with analytics, strategic enablement, technology, regional HCC, and reporting teams to co develop data products and respond to changing business, compliance, and regulatory needs. Enable business users through structured, reusable data assets, clear documentation, and practical guidance on appropriate data use. Support data catalogue development and data discoverability by maintaining metadata, definitions, lineage, and usage documentation. Ensure data products align with data governance standards, privacy expectations, access controls, and approved ways of working. Identify data process gaps, risks, and improvement opportunities across the HCC data ecosystem. Qualifications & Requirements Minimum 6 years of professional experience, preferably in pharmaceutical, medical device, health care, compliance, data, or analytics environments. Experience with transaction systems, data products, analytics datasets, external reporting, or compliance monitoring, with a focus on accuracy, usability, and compliance with local and global standards. High integrity, ethical judgement, Credo-based decision making. Strong attention to detail, problem solving, analytical thinking. Stakeholder partnership, cross functional teaming, user focused enablement. Results driven, adaptable, and committed to continuous improvement and learning. Tools and Analytics SQL, Python, Alteryx, data profiling, modern analytics/reporting tools such as Power BI, Tableau, Qlik Sense, AWS, MS Fabric, Databricks, or similar platforms. Data Products and Modelling Ability to design reusable data products, structure data for analytics, reporting, and compliance use cases, and manage ownership, purpose, quality expectations, and lifecycle. Data Governance and Quality Knowledge of data ownership, stewardship, metadata, catalogues, access controls, documentation, validation, anomaly detection, and quality metrics. Root Cause and Improvement Ability to investigate data issues, identify causes, and implement sustainable controls with process and system owners. Business Translation and Communication Ability to translate business, compliance, reporting, and analytics needs into practical data solutions and explain data concepts clearly to global stakeholders. Location and Travel New Brunswick, NJ, or another J&J location in the Americas, EMEA or ASPAC. Up to 5% domestic and/or international travel may be required. Required Skills Communication Complaints Investigation Compliance Management Corporate Governance Critical Thinking Data Reporting Detail Oriented Governance Risk and Compliance (GRC) Platforms Healthcare Industry Health Care Regulation Internal Auditing Legal Services Medical Compliance Organizing Problem Solving Process Improvements Preferred Skills Communication Complaints Investigation Compliance Management Corporate Governance Critical Thinking Data Reporting Detail Oriented Governance Risk and Compliance (GRC) Platforms Healthcare Industry Health Care Regulation Internal Auditing Legal Services Medical Compliance Organizing Problem Solving Process Improvements
17/07/2026
Full time
Company Overview At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at Job Summary Legal & Compliance / Health Care Compliance. Lead Analyst - Data Products & Integrity, Compliance Data Enablement, located in New Brunswick, NJ or other J&J location in the Americas, EMEA or ASPAC. Reporting to the Senior Manager, Compliance Data Enablement. Responsibilities Design, build, and maintain curated, reusable datasets and data products for the global HCC data ecosystem, including transparency reporting. Design and implement data quality controls within data products to improve completeness, accuracy, consistency, and timeliness. Proactively identify root causes of data quality issues and partner with process and system owners to prevent recurring defects. Contribute to the data product lifecycle, including intake, design, delivery, maintenance, issue management, and continuous improvement. Structure data for analytics, audit, compliance monitoring, reporting, and business consumption. Support ad hoc data requests, rapid insights, PoCs, and pilots by providing fit for purpose data assets and practical guidance. Participate in a Data Concierge model to triage incoming data requests, provide rapid insights, or route needs into structured data product development. Partner with analytics, strategic enablement, technology, regional HCC, and reporting teams to co develop data products and respond to changing business, compliance, and regulatory needs. Enable business users through structured, reusable data assets, clear documentation, and practical guidance on appropriate data use. Support data catalogue development and data discoverability by maintaining metadata, definitions, lineage, and usage documentation. Ensure data products align with data governance standards, privacy expectations, access controls, and approved ways of working. Identify data process gaps, risks, and improvement opportunities across the HCC data ecosystem. Qualifications & Requirements Minimum 6 years of professional experience, preferably in pharmaceutical, medical device, health care, compliance, data, or analytics environments. Experience with transaction systems, data products, analytics datasets, external reporting, or compliance monitoring, with a focus on accuracy, usability, and compliance with local and global standards. High integrity, ethical judgement, Credo-based decision making. Strong attention to detail, problem solving, analytical thinking. Stakeholder partnership, cross functional teaming, user focused enablement. Results driven, adaptable, and committed to continuous improvement and learning. Tools and Analytics SQL, Python, Alteryx, data profiling, modern analytics/reporting tools such as Power BI, Tableau, Qlik Sense, AWS, MS Fabric, Databricks, or similar platforms. Data Products and Modelling Ability to design reusable data products, structure data for analytics, reporting, and compliance use cases, and manage ownership, purpose, quality expectations, and lifecycle. Data Governance and Quality Knowledge of data ownership, stewardship, metadata, catalogues, access controls, documentation, validation, anomaly detection, and quality metrics. Root Cause and Improvement Ability to investigate data issues, identify causes, and implement sustainable controls with process and system owners. Business Translation and Communication Ability to translate business, compliance, reporting, and analytics needs into practical data solutions and explain data concepts clearly to global stakeholders. Location and Travel New Brunswick, NJ, or another J&J location in the Americas, EMEA or ASPAC. Up to 5% domestic and/or international travel may be required. Required Skills Communication Complaints Investigation Compliance Management Corporate Governance Critical Thinking Data Reporting Detail Oriented Governance Risk and Compliance (GRC) Platforms Healthcare Industry Health Care Regulation Internal Auditing Legal Services Medical Compliance Organizing Problem Solving Process Improvements Preferred Skills Communication Complaints Investigation Compliance Management Corporate Governance Critical Thinking Data Reporting Detail Oriented Governance Risk and Compliance (GRC) Platforms Healthcare Industry Health Care Regulation Internal Auditing Legal Services Medical Compliance Organizing Problem Solving Process Improvements
Governance, Risk & Compliance (GRC) Analyst
Quilter plc Southampton, Hampshire
About the Business Quilter plc is a leading wealth management business, overseeing £141.2billion in customer investments. It offers financial advice, investment platforms, multi asset solutions and discretionary fund management through its Affluent and High Net Worth segments. Position Details Level: 3 Department: COO - Business Risk Location: Southampton, United Kingdom (Hybrid: 2-3 days per week in office) Contract: Permanent Regulated: Non Regulated Role Overview We are looking for a Governance, Risk & Compliance (GRC) Analyst to support the COO Business Risk and Governance team. The role embeds our enterprise and operational risk management frameworks, supports informed decision making and promotes a positive risk culture aligned to the Group COO's SMCR responsibilities. Key Responsibilities Support COO first line of defence colleagues with GRC activity, queries and regulatory requests. Implement, embed and improve Quilter's risk management frameworks. Provide analysis, insight, briefings, reports and presentations for decision making. Track industry, regulatory and internal methodology changes; educate colleagues on key requirements. Identify opportunities to improve processes, increase efficiency, add value and enhance client outcomes. Support change activity in line with risk and governance frameworks. Build effective working relationships across business areas, central functions, 2nd line Risk, Internal Audit and external partners. Support related framework activity, including Supplier Due Diligence, Consumer Duty, Operational Resilience, Business Developed Applications and SMCR. Contribute to quarterly RCSA activity, audit activity, Group Policy Attestation processes and oversight of risk management activity. Provide assurance through testing, reviewing controls and preparing clear reports with recommendations. Produce accurate and insightful reporting for management and governance forums; support GRC metrics, data and reporting. Co ordinate governance processes and committee support (agendas, meeting materials, actions and records). Maintain accurate governance records for ExCo, Board and other senior forums. Support Corporate Governance requirements and delivery of Board and Committee papers. About You Highly motivated, adaptable and able to work autonomously under tight deadlines. Delivery focused with strong planning, analytical and communication skills. Experience in financial services, preferably within Affluent or high net worth segments. Knowledge of risk management practices and relevant regulatory bodies such as CASS, COBS, SMCR. Proficiency with Microsoft Word, Excel and the ability to use data and metrics to drive action. Credibility, professionalism, strong personal integrity and ability to influence across all levels. Consumer Duty While not a direct customer facing role, the duties performed support overall positive outcomes for our customers by enabling leaders to balance risk and reward and ensure regulatory compliance. This contributes to improved services, customer centric outcomes and overall satisfaction. Benefits Holiday: 182 hours (26 days) Quilter Incentive Scheme - all employees eligible for incentive participation. Non contributory company pension scheme, boostable via personal contributions. Private Medical Insurance - single cover standard with optional extension. Life Assurance - 4 salary. Income Protection - 75% of salary, payable after 26 weeks of absence. Healthcare Cash Plan - Jersey employees only. Flexible benefits available for UK employees via salary deduction. Inclusion & Diversity We value diversity and promote inclusivity in all aspects of our culture. We provide equal opportunities for all applicants and celebrate unique contributions. We are committed to treating all job applicants fairly and with respect, welcoming a wide range of backgrounds, identities and abilities. Reasonable adjustments are available upon request to ensure accessibility throughout the recruitment process.
16/07/2026
Full time
About the Business Quilter plc is a leading wealth management business, overseeing £141.2billion in customer investments. It offers financial advice, investment platforms, multi asset solutions and discretionary fund management through its Affluent and High Net Worth segments. Position Details Level: 3 Department: COO - Business Risk Location: Southampton, United Kingdom (Hybrid: 2-3 days per week in office) Contract: Permanent Regulated: Non Regulated Role Overview We are looking for a Governance, Risk & Compliance (GRC) Analyst to support the COO Business Risk and Governance team. The role embeds our enterprise and operational risk management frameworks, supports informed decision making and promotes a positive risk culture aligned to the Group COO's SMCR responsibilities. Key Responsibilities Support COO first line of defence colleagues with GRC activity, queries and regulatory requests. Implement, embed and improve Quilter's risk management frameworks. Provide analysis, insight, briefings, reports and presentations for decision making. Track industry, regulatory and internal methodology changes; educate colleagues on key requirements. Identify opportunities to improve processes, increase efficiency, add value and enhance client outcomes. Support change activity in line with risk and governance frameworks. Build effective working relationships across business areas, central functions, 2nd line Risk, Internal Audit and external partners. Support related framework activity, including Supplier Due Diligence, Consumer Duty, Operational Resilience, Business Developed Applications and SMCR. Contribute to quarterly RCSA activity, audit activity, Group Policy Attestation processes and oversight of risk management activity. Provide assurance through testing, reviewing controls and preparing clear reports with recommendations. Produce accurate and insightful reporting for management and governance forums; support GRC metrics, data and reporting. Co ordinate governance processes and committee support (agendas, meeting materials, actions and records). Maintain accurate governance records for ExCo, Board and other senior forums. Support Corporate Governance requirements and delivery of Board and Committee papers. About You Highly motivated, adaptable and able to work autonomously under tight deadlines. Delivery focused with strong planning, analytical and communication skills. Experience in financial services, preferably within Affluent or high net worth segments. Knowledge of risk management practices and relevant regulatory bodies such as CASS, COBS, SMCR. Proficiency with Microsoft Word, Excel and the ability to use data and metrics to drive action. Credibility, professionalism, strong personal integrity and ability to influence across all levels. Consumer Duty While not a direct customer facing role, the duties performed support overall positive outcomes for our customers by enabling leaders to balance risk and reward and ensure regulatory compliance. This contributes to improved services, customer centric outcomes and overall satisfaction. Benefits Holiday: 182 hours (26 days) Quilter Incentive Scheme - all employees eligible for incentive participation. Non contributory company pension scheme, boostable via personal contributions. Private Medical Insurance - single cover standard with optional extension. Life Assurance - 4 salary. Income Protection - 75% of salary, payable after 26 weeks of absence. Healthcare Cash Plan - Jersey employees only. Flexible benefits available for UK employees via salary deduction. Inclusion & Diversity We value diversity and promote inclusivity in all aspects of our culture. We provide equal opportunities for all applicants and celebrate unique contributions. We are committed to treating all job applicants fairly and with respect, welcoming a wide range of backgrounds, identities and abilities. Reasonable adjustments are available upon request to ensure accessibility throughout the recruitment process.
Square One Resources
GRC Analyst: Hybrid, Stakeholder Impact & Risk
Square One Resources Reading, Berkshire
Square One is seeking a Governance & Compliance Analyst (GRC) for a 6-month contract based in Reading or Paddington, with hybrid on-site presence. The role focuses on asset lifecycle governance, risk assessment, and regulatory compliance within a technology environment. You will engage senior stakeholders, drive governance reporting, and support security prioritisation decisions. A strong GRC background and stakeholder management are essential for success.
16/07/2026
Full time
Square One is seeking a Governance & Compliance Analyst (GRC) for a 6-month contract based in Reading or Paddington, with hybrid on-site presence. The role focuses on asset lifecycle governance, risk assessment, and regulatory compliance within a technology environment. You will engage senior stakeholders, drive governance reporting, and support security prioritisation decisions. A strong GRC background and stakeholder management are essential for success.
Hays Senior Finance
Interim Regulatory Analyst / GRC Consultant
Hays Senior Finance
Your New Company Join a large, complex organisation operating within a highly regulated environment, where compliance, governance and regulatory adherence are critical to business success. You'll be working alongside senior stakeholders, technology teams, security professionals and programme leaders to help interpret evolving regulatory requirements and support informed business decision-making. Your New Role As a Regulatory Analyst / GRC Consultant, you will act as a trusted advisor on regulatory and governance matters, providing expert guidance on how regulatory frameworks impact business operations, technology initiatives and strategic decisions. This is a consultative role focused on interpretation and advice rather than hands-on delivery, requiring someone who can analyse complex regulations and translate them into clear business implications and recommendations. Key responsibilities will include: Analysing regulatory frameworks including TSA, ISO 27001, SOX and related governance requirements. Providing strategic advice on regulatory and compliance impacts across projects and programmes. Acting as a regulatory subject matter expert during stakeholder meetings and discussions. Supporting responses to regulatory enquiries and customer compliance queries. Interpreting regulatory requirements and translating them into practical business recommendations. Identifying gaps between current practices and regulatory expectations. Advising senior stakeholders on compliance risks, obligations and best practice. Supporting a fast-paced environment where regulatory priorities can change quickly. What You'll Need to Succeed To be successful in this role, you will have: Strong experience within Regulatory Compliance, Governance, Risk & Compliance (GRC), Controls or Advisory environments. Proven experience interpreting complex regulatory or control frameworks and advising stakeholders accordingly. Knowledge of TSA (Telecoms Security Act) is highly desirable. Experience working with frameworks such as ISO 27001, SOX, NIST or similar governance and compliance standards. Excellent analytical and impact assessment skills. The ability to translate technical or regulatory requirements into clear business outcomes. Strong stakeholder management and communication skills. A consultative mindset with the confidence to challenge, advise and influence. Previous consultancy or advisory experience would be advantageous. What You'll Get in Return Competitive day rate of 590. Hybrid working model with approximately two days on-site per week. Opportunity to work within a complex regulatory environment on high-profile compliance initiatives. Exposure to senior stakeholders and strategic decision-making. A collaborative and fast-moving environment where your expertise will add real value What You Need to Do Now If you're an experienced Regulatory Analyst, GRC Consultant or Governance professional looking for your next contract opportunity, apply now or contact us for a confidential discussion. Please note that occasional travel to either Reading or Paddington may be required at short notice, and flexibility around on-site working is essential. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
15/07/2026
Seasonal
Your New Company Join a large, complex organisation operating within a highly regulated environment, where compliance, governance and regulatory adherence are critical to business success. You'll be working alongside senior stakeholders, technology teams, security professionals and programme leaders to help interpret evolving regulatory requirements and support informed business decision-making. Your New Role As a Regulatory Analyst / GRC Consultant, you will act as a trusted advisor on regulatory and governance matters, providing expert guidance on how regulatory frameworks impact business operations, technology initiatives and strategic decisions. This is a consultative role focused on interpretation and advice rather than hands-on delivery, requiring someone who can analyse complex regulations and translate them into clear business implications and recommendations. Key responsibilities will include: Analysing regulatory frameworks including TSA, ISO 27001, SOX and related governance requirements. Providing strategic advice on regulatory and compliance impacts across projects and programmes. Acting as a regulatory subject matter expert during stakeholder meetings and discussions. Supporting responses to regulatory enquiries and customer compliance queries. Interpreting regulatory requirements and translating them into practical business recommendations. Identifying gaps between current practices and regulatory expectations. Advising senior stakeholders on compliance risks, obligations and best practice. Supporting a fast-paced environment where regulatory priorities can change quickly. What You'll Need to Succeed To be successful in this role, you will have: Strong experience within Regulatory Compliance, Governance, Risk & Compliance (GRC), Controls or Advisory environments. Proven experience interpreting complex regulatory or control frameworks and advising stakeholders accordingly. Knowledge of TSA (Telecoms Security Act) is highly desirable. Experience working with frameworks such as ISO 27001, SOX, NIST or similar governance and compliance standards. Excellent analytical and impact assessment skills. The ability to translate technical or regulatory requirements into clear business outcomes. Strong stakeholder management and communication skills. A consultative mindset with the confidence to challenge, advise and influence. Previous consultancy or advisory experience would be advantageous. What You'll Get in Return Competitive day rate of 590. Hybrid working model with approximately two days on-site per week. Opportunity to work within a complex regulatory environment on high-profile compliance initiatives. Exposure to senior stakeholders and strategic decision-making. A collaborative and fast-moving environment where your expertise will add real value What You Need to Do Now If you're an experienced Regulatory Analyst, GRC Consultant or Governance professional looking for your next contract opportunity, apply now or contact us for a confidential discussion. Please note that occasional travel to either Reading or Paddington may be required at short notice, and flexibility around on-site working is essential. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Information Security GRC Analyst
GEDU CAREERS
Working Pattern: Full-Time - 40 hrs Per Week Salary Range: £40,000 to £42,500 Our Vision: Changing lives through education. We're looking for an Information Security GRC professional to join our team! If you have experience in risk, compliance, and frameworks like ISO 27001 or NIST, this is a great opportunity to make an impact across GBS and the GEDU Group. Please note, we are unable to offer sponsorship for this position. What the role involves: Perform risk assessments in line with security best practice and GBS/GEDU information security policies and procedures. Support the Information Security Manager in maintaining the corporate IS risk register and compiling monthly reporting to Senior Management via monthly and ad-hoc dashboards and summaries . Support the Information Security Manager to implement ISO 27001 framework for GBS and GEDU Group. Work with stakeholders to identify corrective action plans and reduce risks to acceptable levels. Continually improve the information security risk assessment process and documentation. Carry out third-party risk assessments for GBS and GEDU group. Produce, update and review all information security policies, and provide appropriate training where needed. Maintain and ensure compliance with all external regulatory requirements. Track and report on external and internal information security audit findings to ensure successful closure and completion. Maintain and assist in the regular update and provision of security awareness training to all levels of staff. Assist in efforts to plan and track progress toward security certifications (e.g., Cyber Essentials Plus) Assist with technical analysis and investigations by working collaboratively with technical analysts and the Information Security Manager QUALIFICATIONS: Bachelor's degree in information technology, Computer Science, or a related field. ESSENTIAL SKILLS and EXPERIENCE: Proven experience in implementing ISO 27001 compliance and Business Continuity/ITDR is mandatory. Experience in working with Governance Risk Compliance (GRC) and GRC reporting More than 5 years of experience in Information Security, Risk and IT Experience in performing impact, likelihood and risk analyses / assessments. Ability to 'translate' technical security issues into business risk. DESIRABLE SKILLS and EXPERIENCE: Knowledge of cyber audit and frameworks desirable Ability to form complex communications/messages/policies in a simple, clear and concise manner to various stakeholders and interested parties Analytical mindset and creative problem-solving links What we offer: Time off that fits your lifestyle - 33 days annual leave (including bank holidays), 1-day extra leave per year of service (up to 5 days) and Buy/Sell additional holidays (up to 5 days) Opportunities for growth - tuition reimbursement for career development courses, wide variety of training courses Pension Scheme and Flexible Benefits (via salary sacrifice) - Cycle to Work, Workplace Nursery, Tech, Health, Dental and Life Assurance schemes, Women's Health scheme (via Hertlity), and much more Discounts, Perks and Employee Assistance: discounts platform, Employee Assistance Programme (EAP), discounted gym membership, eyecare vouchers and much more Reward for your impact - annual salary increase reviews, annual discretionary bonus, £500 award, employee referral scheme GBS is committed to equality, diversity and inclusion and providing a workplace free from discrimination or harassment. We welcome applications from all backgrounds and communities. We take our core values seriously and work hard to create an environment where everyone feels welcomed. About Us GEDU Global Education is a dynamic and innovative group of education providers. Across our institutions, programmes are designed to have a direct impact on the lives of our students, apprentices and trainees; to equip them with the skills, knowledge and experience necessary for success in their chosen field. Job Info Job Identification 25761 Posting Date 05/19/2026, 09:09 AM Apply Before 06/14/2026, 11:00 PM Degree Level Bachelor's Degree Job Schedule Full time Locations 891 Greenford Road London, Greater London, UB6 0HE, GB Organization Global Banking School Ltd, Global Banking School Ltd, GEDU
14/07/2026
Full time
Working Pattern: Full-Time - 40 hrs Per Week Salary Range: £40,000 to £42,500 Our Vision: Changing lives through education. We're looking for an Information Security GRC professional to join our team! If you have experience in risk, compliance, and frameworks like ISO 27001 or NIST, this is a great opportunity to make an impact across GBS and the GEDU Group. Please note, we are unable to offer sponsorship for this position. What the role involves: Perform risk assessments in line with security best practice and GBS/GEDU information security policies and procedures. Support the Information Security Manager in maintaining the corporate IS risk register and compiling monthly reporting to Senior Management via monthly and ad-hoc dashboards and summaries . Support the Information Security Manager to implement ISO 27001 framework for GBS and GEDU Group. Work with stakeholders to identify corrective action plans and reduce risks to acceptable levels. Continually improve the information security risk assessment process and documentation. Carry out third-party risk assessments for GBS and GEDU group. Produce, update and review all information security policies, and provide appropriate training where needed. Maintain and ensure compliance with all external regulatory requirements. Track and report on external and internal information security audit findings to ensure successful closure and completion. Maintain and assist in the regular update and provision of security awareness training to all levels of staff. Assist in efforts to plan and track progress toward security certifications (e.g., Cyber Essentials Plus) Assist with technical analysis and investigations by working collaboratively with technical analysts and the Information Security Manager QUALIFICATIONS: Bachelor's degree in information technology, Computer Science, or a related field. ESSENTIAL SKILLS and EXPERIENCE: Proven experience in implementing ISO 27001 compliance and Business Continuity/ITDR is mandatory. Experience in working with Governance Risk Compliance (GRC) and GRC reporting More than 5 years of experience in Information Security, Risk and IT Experience in performing impact, likelihood and risk analyses / assessments. Ability to 'translate' technical security issues into business risk. DESIRABLE SKILLS and EXPERIENCE: Knowledge of cyber audit and frameworks desirable Ability to form complex communications/messages/policies in a simple, clear and concise manner to various stakeholders and interested parties Analytical mindset and creative problem-solving links What we offer: Time off that fits your lifestyle - 33 days annual leave (including bank holidays), 1-day extra leave per year of service (up to 5 days) and Buy/Sell additional holidays (up to 5 days) Opportunities for growth - tuition reimbursement for career development courses, wide variety of training courses Pension Scheme and Flexible Benefits (via salary sacrifice) - Cycle to Work, Workplace Nursery, Tech, Health, Dental and Life Assurance schemes, Women's Health scheme (via Hertlity), and much more Discounts, Perks and Employee Assistance: discounts platform, Employee Assistance Programme (EAP), discounted gym membership, eyecare vouchers and much more Reward for your impact - annual salary increase reviews, annual discretionary bonus, £500 award, employee referral scheme GBS is committed to equality, diversity and inclusion and providing a workplace free from discrimination or harassment. We welcome applications from all backgrounds and communities. We take our core values seriously and work hard to create an environment where everyone feels welcomed. About Us GEDU Global Education is a dynamic and innovative group of education providers. Across our institutions, programmes are designed to have a direct impact on the lives of our students, apprentices and trainees; to equip them with the skills, knowledge and experience necessary for success in their chosen field. Job Info Job Identification 25761 Posting Date 05/19/2026, 09:09 AM Apply Before 06/14/2026, 11:00 PM Degree Level Bachelor's Degree Job Schedule Full time Locations 891 Greenford Road London, Greater London, UB6 0HE, GB Organization Global Banking School Ltd, Global Banking School Ltd, GEDU
Analyst, Senior GRC Analyst
News Corporation
Job Description : Position - Senior Governance, Risk and Compliance (GRC) Analyst Location - London Hybrid - 3 days in office The Senior Governance, Risk and Compliance (GRC) Analyst will have an understanding of security and privacy principles as well as a sound understanding of regulatory and compliance requirements affecting a UK business. As a Senior GRC analyst your roles will support and maintain the News UK Cyber GRC Program along with the BISO and central GRC function, including the development, implementation and maintenance of cyber security policies, standards, guidelines and processes to ensure compliance is maintained and risk is managed. What's the role? Work with key internal and external stakeholders to ensure compliance with PCI DSS, Privacy and GDPR compliance requirements, audits and assessments. Assist in the risk assessment process and report on enterprise-wide and third-party security controls. Support in the implementation of key security initiatives across the organisation. Support management of audits, external assessments and assurance processes including, but not limited to PCI DSS and NIST CSF. Develop and manage meaningful metrics to measure and track cyber risks and the effectiveness of the governance, risk and compliance function. Conduct compliance readiness assessments and assurance activities against policies, standards requirements. Track technology and cyber related audit findings and actions. Assist with the development of measurable cyber security standards that align with policy control objectives. Support user and specialist user education and awareness exercises for employees. Assist in the development of effective measurement and simplified reporting of cyber security risks within the business. Assist with third party security assessments against industry standards as well as News UK control standards. Assist in maintaining the cyber security risk register. Who are you? 6+ years' experience within Cyber Security or related fields. Demonstrated experience in governance, risk and compliance in dynamic and complex cyber security, technology and business environment. Strong knowledge and experience with Industry Frameworks and Standards such as NIST CSF, PCI DSS and ISO 27001. Good working knowledge of Cloud infrastructure, especially AWS. Previous experience working in a SOX compliance environment is desirable. Strong oral and written communication skills. Qualification in Information Security, Computer Science, Engineering or similar. Professional security certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) or similar preferred. Equal Opportunity Employer All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status or any other protected characteristic. Reasonable Accommodation We are committed to providing reasonable accommodation for qualified individuals with disabilities in our job application and/or interview process. If you need assistance or accommodation in completing your application or participating in an interview due to a disability, email us at . Please put "Reasonable Accommodation" in the subject line and provide a brief description of the type of assistance you need. This inbox will not be monitored for application status updates.
11/07/2026
Full time
Job Description : Position - Senior Governance, Risk and Compliance (GRC) Analyst Location - London Hybrid - 3 days in office The Senior Governance, Risk and Compliance (GRC) Analyst will have an understanding of security and privacy principles as well as a sound understanding of regulatory and compliance requirements affecting a UK business. As a Senior GRC analyst your roles will support and maintain the News UK Cyber GRC Program along with the BISO and central GRC function, including the development, implementation and maintenance of cyber security policies, standards, guidelines and processes to ensure compliance is maintained and risk is managed. What's the role? Work with key internal and external stakeholders to ensure compliance with PCI DSS, Privacy and GDPR compliance requirements, audits and assessments. Assist in the risk assessment process and report on enterprise-wide and third-party security controls. Support in the implementation of key security initiatives across the organisation. Support management of audits, external assessments and assurance processes including, but not limited to PCI DSS and NIST CSF. Develop and manage meaningful metrics to measure and track cyber risks and the effectiveness of the governance, risk and compliance function. Conduct compliance readiness assessments and assurance activities against policies, standards requirements. Track technology and cyber related audit findings and actions. Assist with the development of measurable cyber security standards that align with policy control objectives. Support user and specialist user education and awareness exercises for employees. Assist in the development of effective measurement and simplified reporting of cyber security risks within the business. Assist with third party security assessments against industry standards as well as News UK control standards. Assist in maintaining the cyber security risk register. Who are you? 6+ years' experience within Cyber Security or related fields. Demonstrated experience in governance, risk and compliance in dynamic and complex cyber security, technology and business environment. Strong knowledge and experience with Industry Frameworks and Standards such as NIST CSF, PCI DSS and ISO 27001. Good working knowledge of Cloud infrastructure, especially AWS. Previous experience working in a SOX compliance environment is desirable. Strong oral and written communication skills. Qualification in Information Security, Computer Science, Engineering or similar. Professional security certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) or similar preferred. Equal Opportunity Employer All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status or any other protected characteristic. Reasonable Accommodation We are committed to providing reasonable accommodation for qualified individuals with disabilities in our job application and/or interview process. If you need assistance or accommodation in completing your application or participating in an interview due to a disability, email us at . Please put "Reasonable Accommodation" in the subject line and provide a brief description of the type of assistance you need. This inbox will not be monitored for application status updates.
Analyst, Senior GRC Analyst
Storyful
Senior Governance, Risk and Compliance (GRC) Analyst Location: London. Hybrid: 3 days in office. Responsibilities Work with key internal and external stakeholders to ensure compliance with PCI DSS, Privacy and GDPR compliance requirements, audits and assessments. Assist in the risk assessment process and report on enterprise-wide and third-party security controls. Support in the implementation of key security initiatives across the organisation. Support management of audits, external assessments and assurance processes including, but not limited to PCI DSS and NIST CSF. Develop and manage meaningful metrics to measure and track cyber risks and the effectiveness of the governance, risk and compliance function. Conduct compliance readiness assessments and assurance activities against policies, standards requirements. Track technology and cyber related audit findings and actions. Assist with the development of measurable cyber security standards that align with policy control objectives. Support user and specialist user education and awareness exercises for employees. Assist in the development of effective measurement and simplified reporting of cyber security risks within the business. Assist with third party security assessments against industry standards as well as News UK control standards. Assist in maintaining the cyber security risk register. Qualifications 6+ years' experience within Cyber Security or related fields. Demonstrated experience in governance, risk and compliance in dynamic and complex cyber security, technology and business environment. Strong knowledge and experience with Industry Frameworks and Standards such as NIST CSF, PCI DSS and ISO 27001. Good working knowledge of Cloud infrastructure, especially AWS. Previous experience working in a SOX compliance environment is desirable. Strong oral and written communication skills. Qualification in Information Security, Computer Science, Engineering or similar. Professional security certifications such as CISSP, CISM, CISA, CRISC or similar preferred. Equal Opportunity Employer All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status or any other protected characteristic. Reasonable Accommodation We are committed to providing reasonable accommodation for qualified individuals with disabilities in our job application and/or interview process. If you need assistance or accommodation in completing your application or participating in an interview due to a disability, email us at . Please put "Reasonable Accommodation" in the subject line and provide a brief description of the type of assistance you need. This inbox will not be monitored for application status updates. Please refer to the privacy notice at the bottom of this page for submitting any data access, deletion, or other data subject rights requests, where permitted under your local laws and regulations.
11/07/2026
Full time
Senior Governance, Risk and Compliance (GRC) Analyst Location: London. Hybrid: 3 days in office. Responsibilities Work with key internal and external stakeholders to ensure compliance with PCI DSS, Privacy and GDPR compliance requirements, audits and assessments. Assist in the risk assessment process and report on enterprise-wide and third-party security controls. Support in the implementation of key security initiatives across the organisation. Support management of audits, external assessments and assurance processes including, but not limited to PCI DSS and NIST CSF. Develop and manage meaningful metrics to measure and track cyber risks and the effectiveness of the governance, risk and compliance function. Conduct compliance readiness assessments and assurance activities against policies, standards requirements. Track technology and cyber related audit findings and actions. Assist with the development of measurable cyber security standards that align with policy control objectives. Support user and specialist user education and awareness exercises for employees. Assist in the development of effective measurement and simplified reporting of cyber security risks within the business. Assist with third party security assessments against industry standards as well as News UK control standards. Assist in maintaining the cyber security risk register. Qualifications 6+ years' experience within Cyber Security or related fields. Demonstrated experience in governance, risk and compliance in dynamic and complex cyber security, technology and business environment. Strong knowledge and experience with Industry Frameworks and Standards such as NIST CSF, PCI DSS and ISO 27001. Good working knowledge of Cloud infrastructure, especially AWS. Previous experience working in a SOX compliance environment is desirable. Strong oral and written communication skills. Qualification in Information Security, Computer Science, Engineering or similar. Professional security certifications such as CISSP, CISM, CISA, CRISC or similar preferred. Equal Opportunity Employer All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status or any other protected characteristic. Reasonable Accommodation We are committed to providing reasonable accommodation for qualified individuals with disabilities in our job application and/or interview process. If you need assistance or accommodation in completing your application or participating in an interview due to a disability, email us at . Please put "Reasonable Accommodation" in the subject line and provide a brief description of the type of assistance you need. This inbox will not be monitored for application status updates. Please refer to the privacy notice at the bottom of this page for submitting any data access, deletion, or other data subject rights requests, where permitted under your local laws and regulations.
Senior GRC Analyst: Hybrid London, PCI/DSS & ISO 27001
Storyful
Storyful is seeking a Senior Governance, Risk and Compliance (GRC) Analyst based in London. This hybrid role will require you to work 3 days in the office. The ideal candidate will have over 6 years of experience in Cyber Security, strong knowledge of industry standards like PCI DSS and a firm grasp of Cloud infrastructure, particularly AWS. Key responsibilities include ensuring compliance with regulations and supporting risk assessments. We value equal opportunity and encourage all qualified applicants to apply.
11/07/2026
Full time
Storyful is seeking a Senior Governance, Risk and Compliance (GRC) Analyst based in London. This hybrid role will require you to work 3 days in the office. The ideal candidate will have over 6 years of experience in Cyber Security, strong knowledge of industry standards like PCI DSS and a firm grasp of Cloud infrastructure, particularly AWS. Key responsibilities include ensuring compliance with regulations and supporting risk assessments. We value equal opportunity and encourage all qualified applicants to apply.
Senior GRC Analyst - Hybrid London (PCI DSS & GDPR)
News Corporation
News Corporation is seeking a Senior Governance, Risk and Compliance (GRC) Analyst to support the Cyber GRC Program. Located in London, the role requires extensive compliance knowledge and 6+ years of Cyber Security experience. You'll work with stakeholders to manage audits, security initiatives, and risk assessments. The ideal candidate possesses strong knowledge of frameworks such as NIST CSF and PCI DSS, excellent communication skills, and relevant qualifications. Hybrid work mode expected.
11/07/2026
Full time
News Corporation is seeking a Senior Governance, Risk and Compliance (GRC) Analyst to support the Cyber GRC Program. Located in London, the role requires extensive compliance knowledge and 6+ years of Cyber Security experience. You'll work with stakeholders to manage audits, security initiatives, and risk assessments. The ideal candidate possesses strong knowledge of frameworks such as NIST CSF and PCI DSS, excellent communication skills, and relevant qualifications. Hybrid work mode expected.
Information Security Analyst Information security London
Checkout Ltd
Company Description We're You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we're behind many of the digital experiences you use every day. We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers. Whether you want to book a holiday, order food, renew a subscription, or check out online, there's a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale. If you want to do career-defining work, you've come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact. With 20 offices across six continents and London as our HQ, we're shaping the future of fintech - and we're just getting started. The Role As an Information Security Analyst at you will work across the full breadth of the information security function, spanning Governance, Risk and Compliance (GRC), AI Governance, Application Security (AppSec), Technology Risk, and Data Governance. This is a role for someone who has built a solid foundation in information security and is ready to move from guided execution to genuine ownership of tasks and smaller workstreams. Security at Checkout operates at scale and at pace. We are a global payments business, regulated across multiple jurisdictions, building infrastructure that processes billions of transactions. Our security function needs analysts who understand how different domains fit together, communicate clearly with technical and non-technical colleagues, and take accountability for the quality of their work. At L2 you will implement security controls, respond to security incidents, identify risks, and support compliance activities across multiple domains. You work independently for extended periods and are developing the cross-domain knowledge and stakeholder skills that will prepare you for programme ownership at L3 and beyond. How You'll Make Impact Governance, Risk and Compliance Support workstreams within Checkout's GRC programme, including ISO 27001, SOC 2, PCI DSS, and applicable regulatory obligations across our global licensed entities. Assist with control evidence collection activities, coordinating with internal teams to gather accurate and timely evidence in support of audit readiness. Maintain GRC documentation including policies, standards, procedures, and control matrices under the guidance of senior colleagues. Support monitoring of the risk register, tracking remediation activity against agreed timelines and escalating where commitments are at risk. Assist in conducting third party risk assessments, evaluating supplier security controls in line with Checkout's TPRM framework. Develop working knowledge of regulatory obligations across Checkout's operating markets, including FCA/PRA requirements, payment scheme rules, and DORA. AI Governance Support the operationalisation of Checkout's AI governance framework, aligned to ISO 42001, the EU AI Act, and NIST AI RMF. Assist in conducting AI risk assessments for internal AI and ML systems and third party AI tools, under the guidance of more senior analysts. Help maintain an inventory of AI use cases and associated risk classifications, working with product and engineering teams as directed. Develop awareness of the evolving regulatory landscape for AI in financial services and contribute to policy and control documentation. Contribute to the development and communication of responsible AI usage guidance for staff, helping teams across the business understand acceptable use boundaries, data handling expectations, and the risks associated with AI tools in a regulated environment. Application Security Contribute to Checkout's application security programme, including support for secure code review processes, SDLC integration, and developer security guidance. Support threat modelling activities for new and existing products, identifying security requirements under the guidance of senior colleagues. Assist in managing vulnerability findings from penetration tests, bug bounty programmes, and automated tooling, tracking remediation and validating fixes. Apply knowledge of the OWASP Top 10 and secure development frameworks to practical security reviews and guidance activities. Technology Risk Support technology risk assessments across infrastructure, cloud environments, and third party systems, contributing to outputs with actionable treatment recommendations. Assist with control assurance activities including vulnerability scanning coordination, access control assessments, and firewall and configuration reviews. Develop an understanding of Checkout's technology risk landscape, identifying emerging threats and contributing inputs to the risk register. Support DORA related ICT risk management activities under the direction of senior analysts. Data Governance Support Checkout's data governance programme, including data classification activities, data flow mapping, and enforcement of data handling standards. Assist with data loss prevention (DLP) controls and tooling, contributing to activities that ensure sensitive data is protected throughout its lifecycle. Help maintain records of processing activities (RoPA) and support data protection impact assessments (DPIAs) for new systems. Develop working knowledge of GDPR, UK GDPR, and applicable regional data protection requirements as they affect Checkout's operations. Cross domain Collaboration Work with Engineering, Product, Legal, Procurement, Finance, and Compliance teams to support the embedding of security requirements into processes, systems, and projects. Respond to security due diligence requests from merchants, partners, and regulators with accuracy and within agreed SLAs, escalating complex queries appropriately. Communicate clearly with internal stakeholders on security requirements, keeping teams updated on changes and project progress. Contribute to security awareness initiatives, promoting a security conscious culture across Checkout. What We're Looking for Experience 1 to 2 years of experience in information security, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Working knowledge of at least one of the following domains: GRC, AppSec, technology risk, or data governance. Practical familiarity with at least one compliance framework: PCI DSS, ISO 27001, SOC 2, NIST CSF, or equivalent. Some exposure to external audits, risk assessments, or security assurance activities. Ability to manage tasks independently and deliver on commitments reliably. Skills and Approach Clear written and verbal communication. You can translate security concepts for technical and non technical audiences. Detail oriented and methodical. You approach your work carefully and follow through consistently. Curious and proactive. You ask questions, flag issues early, and look for root causes rather than surface fixes. Collaborative and adaptable. You work effectively across teams and adjust your approach as priorities shift. Receptive to feedback and committed to developing your information security skills across multiple domains. Preferred Pursuing or holding a relevant certification: CompTIA Security+, CISA (in progress), ISO 27001 Foundation, or equivalent. Familiarity with cloud environments (AWS, Azure, GCP) from a security or compliance perspective. Exposure to security or GRC tooling such as Wiz, Qualys, Microsoft Sentinel, ServiceNow GRC, or similar. Awareness of AI governance frameworks or the OWASP LLM Top 10. Some scripting or automation experience (Python, etc.) is a plus.
10/07/2026
Full time
Company Description We're You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we're behind many of the digital experiences you use every day. We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers. Whether you want to book a holiday, order food, renew a subscription, or check out online, there's a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale. If you want to do career-defining work, you've come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact. With 20 offices across six continents and London as our HQ, we're shaping the future of fintech - and we're just getting started. The Role As an Information Security Analyst at you will work across the full breadth of the information security function, spanning Governance, Risk and Compliance (GRC), AI Governance, Application Security (AppSec), Technology Risk, and Data Governance. This is a role for someone who has built a solid foundation in information security and is ready to move from guided execution to genuine ownership of tasks and smaller workstreams. Security at Checkout operates at scale and at pace. We are a global payments business, regulated across multiple jurisdictions, building infrastructure that processes billions of transactions. Our security function needs analysts who understand how different domains fit together, communicate clearly with technical and non-technical colleagues, and take accountability for the quality of their work. At L2 you will implement security controls, respond to security incidents, identify risks, and support compliance activities across multiple domains. You work independently for extended periods and are developing the cross-domain knowledge and stakeholder skills that will prepare you for programme ownership at L3 and beyond. How You'll Make Impact Governance, Risk and Compliance Support workstreams within Checkout's GRC programme, including ISO 27001, SOC 2, PCI DSS, and applicable regulatory obligations across our global licensed entities. Assist with control evidence collection activities, coordinating with internal teams to gather accurate and timely evidence in support of audit readiness. Maintain GRC documentation including policies, standards, procedures, and control matrices under the guidance of senior colleagues. Support monitoring of the risk register, tracking remediation activity against agreed timelines and escalating where commitments are at risk. Assist in conducting third party risk assessments, evaluating supplier security controls in line with Checkout's TPRM framework. Develop working knowledge of regulatory obligations across Checkout's operating markets, including FCA/PRA requirements, payment scheme rules, and DORA. AI Governance Support the operationalisation of Checkout's AI governance framework, aligned to ISO 42001, the EU AI Act, and NIST AI RMF. Assist in conducting AI risk assessments for internal AI and ML systems and third party AI tools, under the guidance of more senior analysts. Help maintain an inventory of AI use cases and associated risk classifications, working with product and engineering teams as directed. Develop awareness of the evolving regulatory landscape for AI in financial services and contribute to policy and control documentation. Contribute to the development and communication of responsible AI usage guidance for staff, helping teams across the business understand acceptable use boundaries, data handling expectations, and the risks associated with AI tools in a regulated environment. Application Security Contribute to Checkout's application security programme, including support for secure code review processes, SDLC integration, and developer security guidance. Support threat modelling activities for new and existing products, identifying security requirements under the guidance of senior colleagues. Assist in managing vulnerability findings from penetration tests, bug bounty programmes, and automated tooling, tracking remediation and validating fixes. Apply knowledge of the OWASP Top 10 and secure development frameworks to practical security reviews and guidance activities. Technology Risk Support technology risk assessments across infrastructure, cloud environments, and third party systems, contributing to outputs with actionable treatment recommendations. Assist with control assurance activities including vulnerability scanning coordination, access control assessments, and firewall and configuration reviews. Develop an understanding of Checkout's technology risk landscape, identifying emerging threats and contributing inputs to the risk register. Support DORA related ICT risk management activities under the direction of senior analysts. Data Governance Support Checkout's data governance programme, including data classification activities, data flow mapping, and enforcement of data handling standards. Assist with data loss prevention (DLP) controls and tooling, contributing to activities that ensure sensitive data is protected throughout its lifecycle. Help maintain records of processing activities (RoPA) and support data protection impact assessments (DPIAs) for new systems. Develop working knowledge of GDPR, UK GDPR, and applicable regional data protection requirements as they affect Checkout's operations. Cross domain Collaboration Work with Engineering, Product, Legal, Procurement, Finance, and Compliance teams to support the embedding of security requirements into processes, systems, and projects. Respond to security due diligence requests from merchants, partners, and regulators with accuracy and within agreed SLAs, escalating complex queries appropriately. Communicate clearly with internal stakeholders on security requirements, keeping teams updated on changes and project progress. Contribute to security awareness initiatives, promoting a security conscious culture across Checkout. What We're Looking for Experience 1 to 2 years of experience in information security, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Working knowledge of at least one of the following domains: GRC, AppSec, technology risk, or data governance. Practical familiarity with at least one compliance framework: PCI DSS, ISO 27001, SOC 2, NIST CSF, or equivalent. Some exposure to external audits, risk assessments, or security assurance activities. Ability to manage tasks independently and deliver on commitments reliably. Skills and Approach Clear written and verbal communication. You can translate security concepts for technical and non technical audiences. Detail oriented and methodical. You approach your work carefully and follow through consistently. Curious and proactive. You ask questions, flag issues early, and look for root causes rather than surface fixes. Collaborative and adaptable. You work effectively across teams and adjust your approach as priorities shift. Receptive to feedback and committed to developing your information security skills across multiple domains. Preferred Pursuing or holding a relevant certification: CompTIA Security+, CISA (in progress), ISO 27001 Foundation, or equivalent. Familiarity with cloud environments (AWS, Azure, GCP) from a security or compliance perspective. Exposure to security or GRC tooling such as Wiz, Qualys, Microsoft Sentinel, ServiceNow GRC, or similar. Awareness of AI governance frameworks or the OWASP LLM Top 10. Some scripting or automation experience (Python, etc.) is a plus.
Senior Information Security Analyst Information security London
Checkout Ltd
Company Description We're You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we're behind many of the digital experiences you use every day. We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers. Whether you want to book a holiday, order food, renew a subscription, or check out online, there's a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale. If you want to do career-defining work, you've come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact. With 20 offices across six continents and London as our HQ, we're shaping the future of fintech - and we're just getting started. The Role As a Senior Information Security Analyst within the GRC team, you will lead the strategic and technical execution of Checkout's governance, risk and compliance programme. This is a role for a seasoned GRC professional who brings deep expertise across regulatory compliance, enterprise risk management, and security governance - and who can operate with full autonomy while shaping how the function evolves. You will take ownership of Checkout's most complex and high stakes compliance programmes - PCI DSS v4.0.1, ISO 27001, SOC 2, DORA, and emerging obligations across our global licensed entities - while providing expert guidance to engineering, product, legal, and compliance teams on the security requirements that underpin our ability to operate and grow in regulated markets worldwide. At L4, you are a trusted advisor. You do not just manage compliance - you set the direction for it. You define how risk is identified, assessed, and treated. You advise on product and infrastructure decisions from a risk perspective. You mentor and develop junior and mid level analysts. And you work closely with security leadership to ensure the GRC programme is aligned to the business's strategic objectives and risk appetite. Your influence extends well beyond the GRC team. You help shape the security culture at Checkout, driving a risk aware mindset across the business through clear communication, pragmatic guidance, and expert leadership. How You'll Make An Impact GRC Programme Leadership Lead defined sub areas of Checkout's GRC programme end to end, including PCI DSS v4.0.1, ISO 27001, SOC 2, and regulatory obligations across Europe, MENA, APAC, and the Americas. Define how control evidence is collected and maintained, moving the function toward continuous audit readiness and away from point in time preparation. Own and drive improvements to GRC documentation including policies, standards, procedures, and control matrices - ensuring they reflect Checkout's evolving risk profile and regulatory obligations. Lead gap analyses against new and evolving requirements, including DORA ICT risk obligations and the EU AI Act, producing prioritised remediation roadmaps with clear business impact framing. Own the risk register for your sub area, managing risk treatment through to closure and escalating to leadership where risk appetite may be exceeded. Define and refine Checkout's third party risk management approach for high risk and critical vendors, setting assessment standards and overseeing their consistent application. Drive continual improvement of the GRC programme itself - regularly assessing programme maturity, identifying process inefficiencies, and implementing improvements to how risk is identified, assessed, treated, and reported across the business. Audit and Assessment Leadership Serve as the primary point of contact for external auditors, QSAs, and regulatory assessors across PCI DSS, ISO 27001, SOC 2, and ITGC audit cycles. Demonstrated experience implementing ISO management system standards end to end, covering initial scoping and gap assessment through control design, policy development, internal audit programme, and certification - ideally across more than one standard. Lead end to end audit delivery - scoping, evidence preparation, walkthrough facilitation, finding management, and formal closure. Own the end to end response process for complex merchant assurance and regulatory due diligence requests, ensuring Checkout's compliance posture is presented accurately and persuasively. Lead quarterly and annual compliance activities including vulnerability scanning coordination, penetration testing programmes, access reviews, and firewall configuration assurance. Policy, Controls and Regulatory Strategy Apply expert knowledge of PCI DSS v4.0.1, ISO 27001/27002, SOC 2, DORA, NIST CSF, and related frameworks to drive control design, policy development, and compliance strategy. Advise product and engineering teams on compliance requirements at the point of design, embedding regulatory obligations into architecture decisions and development workflows. Lead Checkout's regulatory change management activities - monitoring the evolving landscape across financial services, data protection, and AI regulation, assessing business impact, and driving remediation programmes. Identify and drive systemic improvements to GRC processes, including automation opportunities that improve programme efficiency and evidence quality. Contribute to the design and development of GRC tooling, dashboards, and risk reporting to improve leadership visibility of Checkout's compliance and risk posture. Stakeholder Influence and Team Development Act as a senior trusted advisor to Engineering, Product, Legal, Finance, Procurement, and Compliance on all GRC matters, communicating risk in business terms that drive informed decisions. Represent the GRC function in cross functional forums, governance committees, and regulatory discussions, influencing decisions that affect Checkout's risk posture. Mentor and develop junior and mid level GRC analysts (L1-L3), raising the capability of the team through structured knowledge sharing, review, and coaching. Promote a security first culture across Checkout through proactive engagement, executive level reporting, and accessible guidance that empowers non security teams to make good risk decisions. What We're Looking For Experience 5 or more years of experience in GRC, information security compliance, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Deep working knowledge of PCI DSS (v4.0.1 required), ISO 27001, and SOC 2. Practical experience with DORA, NIST CSF, the EU AI Act, or FCA/PRA obligations is strongly preferred. Demonstrated track record of leading external audits and regulatory assessments end to end, including managing assessor relationships and driving findings to closure. Proven ability to own and deliver complex GRC programme workstreams independently, including gap analyses, risk treatment programmes, and regulatory change initiatives. Experience advising engineering and product teams on compliance requirements, with the ability to translate regulatory obligations into practical, proportionate controls. Track record of developing and mentoring less experienced colleagues. Skills and Approach Expert written and verbal communication. You can frame complex regulatory and risk issues for a technical audience, a business stakeholder, and executive leadership - and adapt your style to drive the right outcome in each context. Strategic and analytical thinker. You see beyond individual findings and controls to understand systemic risk patterns, root causes, and the broader implications for the business. Decisive under ambiguity. You can set direction and make sound judgement calls on prioritisation and risk treatment without waiting for perfect information. Highly collaborative and influential. You understand that compliance must be embedded across the business, and you build the relationships and credibility needed to make that happen. Pragmatic and outcome focused. You design controls and processes that are proportionate to risk and workable in practice, not just theoretically sound. Preferred CISA, CISM, CISSP, PCIP, ISO 27001 Lead Implementer or Lead Auditor, or equivalent advanced certification. Familiarity with cloud environments (AWS, Azure, GCP) at an architecture or control level. Experience with AI governance frameworks such as ISO 42001, the EU AI Act, or NIST AI RMF. Experience designing or implementing GRC tooling, risk platforms, or compliance automation solutions. Background in a Big Four advisory, payments scheme, or regulatory environment is advantageous. Additional Information Bring all of you to work. We create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one. Here, you'll move fast, take on meaningful challenges, and be recognized for the impact you deliver. It's a place where ambition gets met with opportunity, and where your growth is in your hands. We work as one team, and we back each other to succeed. So whatever your background or identity, if you're ready to grow and make a difference, you'll be right at home here. It's important we set you up for success and make our process as accessible as possible. So let us know in your application . click apply for full job details
10/07/2026
Full time
Company Description We're You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we're behind many of the digital experiences you use every day. We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers. Whether you want to book a holiday, order food, renew a subscription, or check out online, there's a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale. If you want to do career-defining work, you've come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact. With 20 offices across six continents and London as our HQ, we're shaping the future of fintech - and we're just getting started. The Role As a Senior Information Security Analyst within the GRC team, you will lead the strategic and technical execution of Checkout's governance, risk and compliance programme. This is a role for a seasoned GRC professional who brings deep expertise across regulatory compliance, enterprise risk management, and security governance - and who can operate with full autonomy while shaping how the function evolves. You will take ownership of Checkout's most complex and high stakes compliance programmes - PCI DSS v4.0.1, ISO 27001, SOC 2, DORA, and emerging obligations across our global licensed entities - while providing expert guidance to engineering, product, legal, and compliance teams on the security requirements that underpin our ability to operate and grow in regulated markets worldwide. At L4, you are a trusted advisor. You do not just manage compliance - you set the direction for it. You define how risk is identified, assessed, and treated. You advise on product and infrastructure decisions from a risk perspective. You mentor and develop junior and mid level analysts. And you work closely with security leadership to ensure the GRC programme is aligned to the business's strategic objectives and risk appetite. Your influence extends well beyond the GRC team. You help shape the security culture at Checkout, driving a risk aware mindset across the business through clear communication, pragmatic guidance, and expert leadership. How You'll Make An Impact GRC Programme Leadership Lead defined sub areas of Checkout's GRC programme end to end, including PCI DSS v4.0.1, ISO 27001, SOC 2, and regulatory obligations across Europe, MENA, APAC, and the Americas. Define how control evidence is collected and maintained, moving the function toward continuous audit readiness and away from point in time preparation. Own and drive improvements to GRC documentation including policies, standards, procedures, and control matrices - ensuring they reflect Checkout's evolving risk profile and regulatory obligations. Lead gap analyses against new and evolving requirements, including DORA ICT risk obligations and the EU AI Act, producing prioritised remediation roadmaps with clear business impact framing. Own the risk register for your sub area, managing risk treatment through to closure and escalating to leadership where risk appetite may be exceeded. Define and refine Checkout's third party risk management approach for high risk and critical vendors, setting assessment standards and overseeing their consistent application. Drive continual improvement of the GRC programme itself - regularly assessing programme maturity, identifying process inefficiencies, and implementing improvements to how risk is identified, assessed, treated, and reported across the business. Audit and Assessment Leadership Serve as the primary point of contact for external auditors, QSAs, and regulatory assessors across PCI DSS, ISO 27001, SOC 2, and ITGC audit cycles. Demonstrated experience implementing ISO management system standards end to end, covering initial scoping and gap assessment through control design, policy development, internal audit programme, and certification - ideally across more than one standard. Lead end to end audit delivery - scoping, evidence preparation, walkthrough facilitation, finding management, and formal closure. Own the end to end response process for complex merchant assurance and regulatory due diligence requests, ensuring Checkout's compliance posture is presented accurately and persuasively. Lead quarterly and annual compliance activities including vulnerability scanning coordination, penetration testing programmes, access reviews, and firewall configuration assurance. Policy, Controls and Regulatory Strategy Apply expert knowledge of PCI DSS v4.0.1, ISO 27001/27002, SOC 2, DORA, NIST CSF, and related frameworks to drive control design, policy development, and compliance strategy. Advise product and engineering teams on compliance requirements at the point of design, embedding regulatory obligations into architecture decisions and development workflows. Lead Checkout's regulatory change management activities - monitoring the evolving landscape across financial services, data protection, and AI regulation, assessing business impact, and driving remediation programmes. Identify and drive systemic improvements to GRC processes, including automation opportunities that improve programme efficiency and evidence quality. Contribute to the design and development of GRC tooling, dashboards, and risk reporting to improve leadership visibility of Checkout's compliance and risk posture. Stakeholder Influence and Team Development Act as a senior trusted advisor to Engineering, Product, Legal, Finance, Procurement, and Compliance on all GRC matters, communicating risk in business terms that drive informed decisions. Represent the GRC function in cross functional forums, governance committees, and regulatory discussions, influencing decisions that affect Checkout's risk posture. Mentor and develop junior and mid level GRC analysts (L1-L3), raising the capability of the team through structured knowledge sharing, review, and coaching. Promote a security first culture across Checkout through proactive engagement, executive level reporting, and accessible guidance that empowers non security teams to make good risk decisions. What We're Looking For Experience 5 or more years of experience in GRC, information security compliance, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Deep working knowledge of PCI DSS (v4.0.1 required), ISO 27001, and SOC 2. Practical experience with DORA, NIST CSF, the EU AI Act, or FCA/PRA obligations is strongly preferred. Demonstrated track record of leading external audits and regulatory assessments end to end, including managing assessor relationships and driving findings to closure. Proven ability to own and deliver complex GRC programme workstreams independently, including gap analyses, risk treatment programmes, and regulatory change initiatives. Experience advising engineering and product teams on compliance requirements, with the ability to translate regulatory obligations into practical, proportionate controls. Track record of developing and mentoring less experienced colleagues. Skills and Approach Expert written and verbal communication. You can frame complex regulatory and risk issues for a technical audience, a business stakeholder, and executive leadership - and adapt your style to drive the right outcome in each context. Strategic and analytical thinker. You see beyond individual findings and controls to understand systemic risk patterns, root causes, and the broader implications for the business. Decisive under ambiguity. You can set direction and make sound judgement calls on prioritisation and risk treatment without waiting for perfect information. Highly collaborative and influential. You understand that compliance must be embedded across the business, and you build the relationships and credibility needed to make that happen. Pragmatic and outcome focused. You design controls and processes that are proportionate to risk and workable in practice, not just theoretically sound. Preferred CISA, CISM, CISSP, PCIP, ISO 27001 Lead Implementer or Lead Auditor, or equivalent advanced certification. Familiarity with cloud environments (AWS, Azure, GCP) at an architecture or control level. Experience with AI governance frameworks such as ISO 42001, the EU AI Act, or NIST AI RMF. Experience designing or implementing GRC tooling, risk platforms, or compliance automation solutions. Background in a Big Four advisory, payments scheme, or regulatory environment is advantageous. Additional Information Bring all of you to work. We create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one. Here, you'll move fast, take on meaningful challenges, and be recognized for the impact you deliver. It's a place where ambition gets met with opportunity, and where your growth is in your hands. We work as one team, and we back each other to succeed. So whatever your background or identity, if you're ready to grow and make a difference, you'll be right at home here. It's important we set you up for success and make our process as accessible as possible. So let us know in your application . click apply for full job details
Governance Risk and Compliance (GRC) Analyst
Assured Data Protection Inc. Leeds, Yorkshire
Governance Risk and Compliance (GRC) Analyst Leeds, West Yorkshire, United Kingdom - Full Time Location : Hybrid - Remote / Leeds UK Position Title : Governance, Risk and Compliance (GRC) Analyst Job Type : Full-Time Assured Data Protection is a global leader in data backup and disaster recovery managed services, specialising in safeguarding against data loss and downtime in the event of a disaster, cyber, or ransomware attack. Our fully managed services include immutable backup, disaster recovery, and cyber resiliency to protect data on-premises and in the cloud, with 24/7/365 expert support. We offer a flexible, consumption-based model to grow with your business, making data protection cost-effective and scalable. Our purpose built software provides industry leading monitoring and reporting capabilities to provide actionable insights into your data protection strategy. Our global datacentres ensure data sovereignty, meeting your organisation's compliance requirements. A dedicated team is always available to recover your data and minimise disruption in the event of a disaster. As the Governance, Risk and Compliance Analyst, you will work under the direction of the Global Head of Compliance to ensure international compliance needs are met. The GRC analyst is a key member of the Governance, Risk and Compliance team, responsible for supporting the development, implementation and maintenance of the company's GRC framework. The role involves a blend of operational and analytical tasks, working closely with various departments to ensure adherence to internal policies and external regulations. The role is critical for developing, implementing and maintaining the business' GRC Framework, contributing to a culture of compliance, integrity and ethical conduct. Key Responsibilities: Governance Assist in maintaining our Information Security Management System (ISMS), Quality Management System (QMS) and SOC2 in our Compliance monitoring tooling. Support with policy development and creation. Compliance & Regulatory Adherence Complete customer, partner and vendor due diligence activities. Assist with internal and external audits. Identify and remedy gaps in policy and process to support compliance needs. Assist in the development of Compliance training programs to support a culture of compliance within the organisation. Risk Management Assist with our Risk Management process which includes maintenance of our Risk Register. Ensure identified risks are documented and logged on our InfoSec Risk Register. Key Experience and Qualifications: Preferred Qualifications Industry recognised certifications such as CRISC, ISO 27001 Lead Implementer would be highly beneficial. Experience Prior work experience or equivalent in the Technology sector. Prior work experience in international compliance frameworks and standards; such as UK & EU GDPR, HIPAA, PCI-DSS, NIST, SOC2, ISO 27001, ISO 9001. Project Management experience. Prior experience with compliance tooling. Experience working with Information Security and Legal Teams. Skills & Competencies Understanding of core Risk Management principles. Ability to embrace flexibility and adapt seamlessly to change. Ability to use initiative to solve complex problems. Ability to communicate with stakeholders at every seniority level of the business. What We Offer: Hybrid working options for flexibility Regular team building and off site company events. A dynamic, inclusive, and collaborative work environment At Assured Data Protection we value diversity and inclusivity. We offer perks such as flex holidays and flexible working practices to allow our employees to show up as their whole selves. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know. You must have the legal right to work in the UK at the time of application, as we are unable to offer visa sponsorship for this role.
09/07/2026
Full time
Governance Risk and Compliance (GRC) Analyst Leeds, West Yorkshire, United Kingdom - Full Time Location : Hybrid - Remote / Leeds UK Position Title : Governance, Risk and Compliance (GRC) Analyst Job Type : Full-Time Assured Data Protection is a global leader in data backup and disaster recovery managed services, specialising in safeguarding against data loss and downtime in the event of a disaster, cyber, or ransomware attack. Our fully managed services include immutable backup, disaster recovery, and cyber resiliency to protect data on-premises and in the cloud, with 24/7/365 expert support. We offer a flexible, consumption-based model to grow with your business, making data protection cost-effective and scalable. Our purpose built software provides industry leading monitoring and reporting capabilities to provide actionable insights into your data protection strategy. Our global datacentres ensure data sovereignty, meeting your organisation's compliance requirements. A dedicated team is always available to recover your data and minimise disruption in the event of a disaster. As the Governance, Risk and Compliance Analyst, you will work under the direction of the Global Head of Compliance to ensure international compliance needs are met. The GRC analyst is a key member of the Governance, Risk and Compliance team, responsible for supporting the development, implementation and maintenance of the company's GRC framework. The role involves a blend of operational and analytical tasks, working closely with various departments to ensure adherence to internal policies and external regulations. The role is critical for developing, implementing and maintaining the business' GRC Framework, contributing to a culture of compliance, integrity and ethical conduct. Key Responsibilities: Governance Assist in maintaining our Information Security Management System (ISMS), Quality Management System (QMS) and SOC2 in our Compliance monitoring tooling. Support with policy development and creation. Compliance & Regulatory Adherence Complete customer, partner and vendor due diligence activities. Assist with internal and external audits. Identify and remedy gaps in policy and process to support compliance needs. Assist in the development of Compliance training programs to support a culture of compliance within the organisation. Risk Management Assist with our Risk Management process which includes maintenance of our Risk Register. Ensure identified risks are documented and logged on our InfoSec Risk Register. Key Experience and Qualifications: Preferred Qualifications Industry recognised certifications such as CRISC, ISO 27001 Lead Implementer would be highly beneficial. Experience Prior work experience or equivalent in the Technology sector. Prior work experience in international compliance frameworks and standards; such as UK & EU GDPR, HIPAA, PCI-DSS, NIST, SOC2, ISO 27001, ISO 9001. Project Management experience. Prior experience with compliance tooling. Experience working with Information Security and Legal Teams. Skills & Competencies Understanding of core Risk Management principles. Ability to embrace flexibility and adapt seamlessly to change. Ability to use initiative to solve complex problems. Ability to communicate with stakeholders at every seniority level of the business. What We Offer: Hybrid working options for flexibility Regular team building and off site company events. A dynamic, inclusive, and collaborative work environment At Assured Data Protection we value diversity and inclusivity. We offer perks such as flex holidays and flexible working practices to allow our employees to show up as their whole selves. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know. You must have the legal right to work in the UK at the time of application, as we are unable to offer visa sponsorship for this role.
Lorien
Technology Risk / Compliance Analyst
Lorien City, Edinburgh
Technology Risk / Compliance Analyst (GRC) Up to 66,000 + benefits Edinburgh or Glasgow Hybrid - 2 days office / 3 days home Our client is a fast-growing, well-established software business providing regulatory and compliance solutions to financial services organisations. They are looking for a Technology Risk / Compliance Analyst to join their Governance, Risk & Compliance function, reporting directly to the VP of GRC. This role can be based out of either the Edinburgh or Glasgow office, working a hybrid pattern of 2 days in the office and 3 days from home. This is a genuine opportunity to build specialist expertise in technology, cyber, data and third-party risk within a regulated financial services environment - with direct exposure to senior GRC oversight, governance forums, control assurance and client due diligence work. What you'll be doing Supporting risk and control self-assessments across technology, cyber security, data, cloud services and third-party/supplier risk Analysing incidents, operational events and control data to identify trends, root causes and areas for improvement Tracking risk actions and remediation plans, escalating overdue items where required Maintaining key risk indicators and control information to support accurate governance and client assurance reporting Preparing draft packs, dashboards and summary updates for senior GRC review Supporting responses to client, audit and regulatory due diligence requests Contributing to continuous improvement of risk processes, including the use of automation and AI-enabled tools What we're looking for Proven skills in a risk, audit, technology, cyber, data or controls role Financial services background essential - experience working in, or with, a regulated environment Experience with a GRC or compliance automation platform (e.g. Secureframe, Vanta, Drata or similar) is a strong plus Naturally curious and proactive - comfortable identifying risks unprompted and confident challenging control owners on findings Strong analytical skills and the ability to translate risk data into clear, actionable insight for technical, non-technical and client audiences Awareness of frameworks such as ISO 27001, NIST, SOC 2, GDPR, DORA or operational resilience is desirable What's on offer Salary up to 66,000 depending on experience Hybrid working - 2 days in the office (Edinburgh or Glasgow), 3 days from home Benefits package (pension, healthcare and further details on application) Direct exposure to senior GRC leadership and governance forums Genuine scope to shape and improve risk processes, not just maintain them If the above sounds like you please send a copy of your latest CV for a confidential discussion Guidant, Carbon60, Lorien & SRG - The Impellam Group Portfolio are acting as an Employment Business in relation to this vacancy.
08/07/2026
Full time
Technology Risk / Compliance Analyst (GRC) Up to 66,000 + benefits Edinburgh or Glasgow Hybrid - 2 days office / 3 days home Our client is a fast-growing, well-established software business providing regulatory and compliance solutions to financial services organisations. They are looking for a Technology Risk / Compliance Analyst to join their Governance, Risk & Compliance function, reporting directly to the VP of GRC. This role can be based out of either the Edinburgh or Glasgow office, working a hybrid pattern of 2 days in the office and 3 days from home. This is a genuine opportunity to build specialist expertise in technology, cyber, data and third-party risk within a regulated financial services environment - with direct exposure to senior GRC oversight, governance forums, control assurance and client due diligence work. What you'll be doing Supporting risk and control self-assessments across technology, cyber security, data, cloud services and third-party/supplier risk Analysing incidents, operational events and control data to identify trends, root causes and areas for improvement Tracking risk actions and remediation plans, escalating overdue items where required Maintaining key risk indicators and control information to support accurate governance and client assurance reporting Preparing draft packs, dashboards and summary updates for senior GRC review Supporting responses to client, audit and regulatory due diligence requests Contributing to continuous improvement of risk processes, including the use of automation and AI-enabled tools What we're looking for Proven skills in a risk, audit, technology, cyber, data or controls role Financial services background essential - experience working in, or with, a regulated environment Experience with a GRC or compliance automation platform (e.g. Secureframe, Vanta, Drata or similar) is a strong plus Naturally curious and proactive - comfortable identifying risks unprompted and confident challenging control owners on findings Strong analytical skills and the ability to translate risk data into clear, actionable insight for technical, non-technical and client audiences Awareness of frameworks such as ISO 27001, NIST, SOC 2, GDPR, DORA or operational resilience is desirable What's on offer Salary up to 66,000 depending on experience Hybrid working - 2 days in the office (Edinburgh or Glasgow), 3 days from home Benefits package (pension, healthcare and further details on application) Direct exposure to senior GRC leadership and governance forums Genuine scope to shape and improve risk processes, not just maintain them If the above sounds like you please send a copy of your latest CV for a confidential discussion Guidant, Carbon60, Lorien & SRG - The Impellam Group Portfolio are acting as an Employment Business in relation to this vacancy.
Zachary Daniels Recruitment
Senior GRC Cyber Security Analyst
Zachary Daniels Recruitment
Senior GRC Cyber Security Analyst London (Hybrid, 3 days in office) 70,000- 85,000 + Benefits A growing international organisation is looking to strengthen its cyber security capability with the appointment of a Senior Cyber Security Analyst (Governance, Risk & Compliance). This is a fantastic opportunity to join a developing security function where you'll play a key role in governance, risk management, regulatory compliance and information security assurance across the business. The Opportunity Working closely with the Director of Information Security, you'll help drive security governance, maintain compliance frameworks and provide clear security risk insight to stakeholders across the organisation. This is a varied role offering exposure to security strategy, audits, supplier assurance and executive reporting within a complex technology environment. Key Responsibilities Governance & Compliance Maintain Information Security policies, standards and procedures Support compliance with ISO 27001, GDPR, NIS2 and related frameworks Coordinate audit evidence and compliance activities Maintain governance documentation and control frameworks Risk Management Maintain the Information Security Risk Register Facilitate risk assessments with business stakeholders Track remediation plans and improvement actions Produce meaningful security reporting and dashboards Third Party Assurance Conduct supplier security assessments Manage customer security questionnaires Support third-party due diligence activities Reporting & Security Awareness Produce KPI and KRI reporting Support executive and board reporting Coordinate security awareness initiatives Contribute to Business Continuity and Disaster Recovery activities About You You'll have previous experience within a Cyber Security Governance, Risk & Compliance function together with knowledge of: ISO 27001 GDPR NIS2 Risk Management Security Policies & Standards Audit & Compliance Supplier Assurance Microsoft 365 Relevant cyber security certifications would be advantageous but are not essential. Package 70,000- 85,000 DOE Hybrid Working 3 days in the London Office Opportunity to shape and mature cyber governance Exposure to enterprise security programmes Excellent long-term career progression Apply today with your most up-to-date CV! BH36687
07/07/2026
Full time
Senior GRC Cyber Security Analyst London (Hybrid, 3 days in office) 70,000- 85,000 + Benefits A growing international organisation is looking to strengthen its cyber security capability with the appointment of a Senior Cyber Security Analyst (Governance, Risk & Compliance). This is a fantastic opportunity to join a developing security function where you'll play a key role in governance, risk management, regulatory compliance and information security assurance across the business. The Opportunity Working closely with the Director of Information Security, you'll help drive security governance, maintain compliance frameworks and provide clear security risk insight to stakeholders across the organisation. This is a varied role offering exposure to security strategy, audits, supplier assurance and executive reporting within a complex technology environment. Key Responsibilities Governance & Compliance Maintain Information Security policies, standards and procedures Support compliance with ISO 27001, GDPR, NIS2 and related frameworks Coordinate audit evidence and compliance activities Maintain governance documentation and control frameworks Risk Management Maintain the Information Security Risk Register Facilitate risk assessments with business stakeholders Track remediation plans and improvement actions Produce meaningful security reporting and dashboards Third Party Assurance Conduct supplier security assessments Manage customer security questionnaires Support third-party due diligence activities Reporting & Security Awareness Produce KPI and KRI reporting Support executive and board reporting Coordinate security awareness initiatives Contribute to Business Continuity and Disaster Recovery activities About You You'll have previous experience within a Cyber Security Governance, Risk & Compliance function together with knowledge of: ISO 27001 GDPR NIS2 Risk Management Security Policies & Standards Audit & Compliance Supplier Assurance Microsoft 365 Relevant cyber security certifications would be advantageous but are not essential. Package 70,000- 85,000 DOE Hybrid Working 3 days in the London Office Opportunity to shape and mature cyber governance Exposure to enterprise security programmes Excellent long-term career progression Apply today with your most up-to-date CV! BH36687
Cybersecurity Analyst
Academy Education Network Ltd Manchester, Lancashire
Overview Cybersecurity Analysts protect organisations from cyber threats. Depending on the speciality, roles may involve monitoring live security events in a Security Operations Centre (SOC), researching threat intelligence, conducting penetration tests to uncover vulnerabilities, or managing Governance, Risk & Compliance (GRC) workstreams. All work aligns with recognised frameworks such as NIST CSF, ISO 27001, and CIS Controls. Responsibilities Monitor security events and respond to active threats in real time. Run vulnerability assessments, penetration tests, and incident response exercises. Specialise in SOC analysis, threat intelligence, penetration testing, GRC, or cloud security. Work for banks, telcos, defence contractors, government agencies, NHS and FTSE 100 corporates. Career Progression Typical career stages for a Cybersecurity Analyst: Years 0-2: SOC Analyst (Tier 1) - monitor events and respond to common incidents; progression via CompTIA Security+ and SANS GCIH or CEH. Years 2-5: Cybersecurity Analyst / Penetration Tester - specialise in penetration testing (CREST CRT, OSCP), threat intelligence or GRC (ISO 27001 Lead Auditor). Years 5-8: Senior Analyst / Security Engineer - lead complex incident response, run major risk assessments, or design enterprise security architecture; often required to hold CISSP. Years 8+: Lead / Head of Security / CISO - strategic leadership of an organisation's security function; requires technical depth and business/board level communication. Qualifications & Skills Required technical knowledge and professional traits include: Calm decision making under incident pressure. Clear written reporting for non technical executives. Ethical decision making and professional integrity. Continuous learning across rapidly evolving threats. Methodical, evidence based investigation. Teamwork across IT, business and law enforcement. Relevant certifications such as CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP, ISO 27001 Lead Auditor. Typical Salary Ranges (UK) Junior SOC analysts at major banks and managed service providers start at £35,000-£45,000. Penetration testers and threat intelligence analysts at top consultancies earn £45,000-£65,000 within 3 years. Senior engineers and CISO track leaders in FTSE 100 companies can reach £100,000+. Education and Entry Routes Common pathways include: MSc Cybersecurity - 1 year postgraduate specialist degree (many are NCSC certified). Cybersecurity Apprenticeship - 2-4 years, fully employer funded (Levels 4 & 6). CompTIA Security+ plus a Tier 1 SOC role - common entry for career changers. University undergraduate degree in Cybersecurity or Computer Science - 3 years; with student loans and progression into junior roles. FAQ - Becoming a Cybersecurity Analyst in the UK How long does it take to become a cyber analyst? Typically straight after a 3 year undergraduate degree, or via CompTIA Security+ and a Tier 1 SOC role. Do I need a cybersecurity degree to work in the UK? Not strictly, but a specialist degree and relevant certifications are the most reliable route. Is the role on the Skilled Worker visa shortage list? No; however, salaries often meet the threshold and most private sector employers sponsor international analysts. What's the difference between a SOC analyst and a penetration tester? SOC analysts monitor events; penetration testers actively find vulnerabilities. Which UK certifications matter most? CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP. Can I move into cybersecurity from another career? Yes - career changers can transition via Security+ and a Tier 1 SOC role within 6-12 months.
07/07/2026
Full time
Overview Cybersecurity Analysts protect organisations from cyber threats. Depending on the speciality, roles may involve monitoring live security events in a Security Operations Centre (SOC), researching threat intelligence, conducting penetration tests to uncover vulnerabilities, or managing Governance, Risk & Compliance (GRC) workstreams. All work aligns with recognised frameworks such as NIST CSF, ISO 27001, and CIS Controls. Responsibilities Monitor security events and respond to active threats in real time. Run vulnerability assessments, penetration tests, and incident response exercises. Specialise in SOC analysis, threat intelligence, penetration testing, GRC, or cloud security. Work for banks, telcos, defence contractors, government agencies, NHS and FTSE 100 corporates. Career Progression Typical career stages for a Cybersecurity Analyst: Years 0-2: SOC Analyst (Tier 1) - monitor events and respond to common incidents; progression via CompTIA Security+ and SANS GCIH or CEH. Years 2-5: Cybersecurity Analyst / Penetration Tester - specialise in penetration testing (CREST CRT, OSCP), threat intelligence or GRC (ISO 27001 Lead Auditor). Years 5-8: Senior Analyst / Security Engineer - lead complex incident response, run major risk assessments, or design enterprise security architecture; often required to hold CISSP. Years 8+: Lead / Head of Security / CISO - strategic leadership of an organisation's security function; requires technical depth and business/board level communication. Qualifications & Skills Required technical knowledge and professional traits include: Calm decision making under incident pressure. Clear written reporting for non technical executives. Ethical decision making and professional integrity. Continuous learning across rapidly evolving threats. Methodical, evidence based investigation. Teamwork across IT, business and law enforcement. Relevant certifications such as CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP, ISO 27001 Lead Auditor. Typical Salary Ranges (UK) Junior SOC analysts at major banks and managed service providers start at £35,000-£45,000. Penetration testers and threat intelligence analysts at top consultancies earn £45,000-£65,000 within 3 years. Senior engineers and CISO track leaders in FTSE 100 companies can reach £100,000+. Education and Entry Routes Common pathways include: MSc Cybersecurity - 1 year postgraduate specialist degree (many are NCSC certified). Cybersecurity Apprenticeship - 2-4 years, fully employer funded (Levels 4 & 6). CompTIA Security+ plus a Tier 1 SOC role - common entry for career changers. University undergraduate degree in Cybersecurity or Computer Science - 3 years; with student loans and progression into junior roles. FAQ - Becoming a Cybersecurity Analyst in the UK How long does it take to become a cyber analyst? Typically straight after a 3 year undergraduate degree, or via CompTIA Security+ and a Tier 1 SOC role. Do I need a cybersecurity degree to work in the UK? Not strictly, but a specialist degree and relevant certifications are the most reliable route. Is the role on the Skilled Worker visa shortage list? No; however, salaries often meet the threshold and most private sector employers sponsor international analysts. What's the difference between a SOC analyst and a penetration tester? SOC analysts monitor events; penetration testers actively find vulnerabilities. Which UK certifications matter most? CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP. Can I move into cybersecurity from another career? Yes - career changers can transition via Security+ and a Tier 1 SOC role within 6-12 months.
Application Security Assessment Specialist - Banking
Salt Digital Recruitment
Security Risk Assessment Specialist - Freelance Contractor - BrusselsRate: Flexible; Duration: 1 year; Hybrid: 8 days onsite per month in Brussels office, remainder remote. Division: CISO - IT Risk. About the role We are looking for an experienced and dynamic Senior Security Analyst to join our IT Risk Transformation team. In this role, you will contribute to the design and enhancement of our application security risk assessment process and perform security risk assessments across a wide range of applications. You will work closely with cross functional teams from across the organization and will be exposed to a diversified set of topics, business and technologies. Responsibilities Contribute to the design of an application security risk assessment framework. Design the approach for executing application security assessments. Participate in building the data model supporting the above activities. Create standard reporting templates. Organise documentation and track activity. Execute security assessments. Analyse the business context, technical architecture and supporting components of applications using sources such as CMDB, network topology, documentation and workshops. Identify relevant threats, risk scenarios and appropriate security controls based on the application's specific environment. Detect security gaps, articulate clear and actionable findings, and provide practical recommendations. Produce detailed reports outlining risks, observations and recommended security measures. Collaborate with internal stakeholders including IT, architects, project managers, business owners and risk teams to validate findings and support remediation plans. Experience 5-10 years of proven experience conducting security risk assessments. Hands on experience contributing to the design of security processes, frameworks or security solutions. Solid understanding of cybersecurity frameworks (ISO27001, CIS, NIST, DORA) and threat/risk frameworks (MITRE, EBIOS). Good knowledge of financial IT security regulatory requirements (DORA, ESMA, etc.). Practical understanding of how information security controls must be implemented. Experience in defining or applying security requirements on Microsoft Azure, IBM Mainframe or Microsoft Windows platforms is a plus. Fluency in English and prior experience in the financial sector. Knowledge of financial markets, FMIs and CSD operations is advantageous. Experience with tools such as ServiceNow, Excel and basic security testing platforms. Experience with ServiceNow GRC is advantageous. Certifications such as CISSP, CSSLP, CCSP, CISM, CISMP, GCIH, CEH are advantageous. Skills Strong communication and coordination skills, engaging effectively with stakeholders across diverse teams. Proactive, self motivated and comfortable in a dynamic, continuously evolving environment. Strong analytical capabilities and creative problem solving skills. Structured, synthetic, delivering clear, concise and relevant responses. Calm, organized, efficient under pressure, maintaining clarity even in uncertain situations. Collaborative mindset, working effectively with executives, business leaders and technical teams. Autonomous and well organized, with strong prioritisation and time management ability.
07/07/2026
Full time
Security Risk Assessment Specialist - Freelance Contractor - BrusselsRate: Flexible; Duration: 1 year; Hybrid: 8 days onsite per month in Brussels office, remainder remote. Division: CISO - IT Risk. About the role We are looking for an experienced and dynamic Senior Security Analyst to join our IT Risk Transformation team. In this role, you will contribute to the design and enhancement of our application security risk assessment process and perform security risk assessments across a wide range of applications. You will work closely with cross functional teams from across the organization and will be exposed to a diversified set of topics, business and technologies. Responsibilities Contribute to the design of an application security risk assessment framework. Design the approach for executing application security assessments. Participate in building the data model supporting the above activities. Create standard reporting templates. Organise documentation and track activity. Execute security assessments. Analyse the business context, technical architecture and supporting components of applications using sources such as CMDB, network topology, documentation and workshops. Identify relevant threats, risk scenarios and appropriate security controls based on the application's specific environment. Detect security gaps, articulate clear and actionable findings, and provide practical recommendations. Produce detailed reports outlining risks, observations and recommended security measures. Collaborate with internal stakeholders including IT, architects, project managers, business owners and risk teams to validate findings and support remediation plans. Experience 5-10 years of proven experience conducting security risk assessments. Hands on experience contributing to the design of security processes, frameworks or security solutions. Solid understanding of cybersecurity frameworks (ISO27001, CIS, NIST, DORA) and threat/risk frameworks (MITRE, EBIOS). Good knowledge of financial IT security regulatory requirements (DORA, ESMA, etc.). Practical understanding of how information security controls must be implemented. Experience in defining or applying security requirements on Microsoft Azure, IBM Mainframe or Microsoft Windows platforms is a plus. Fluency in English and prior experience in the financial sector. Knowledge of financial markets, FMIs and CSD operations is advantageous. Experience with tools such as ServiceNow, Excel and basic security testing platforms. Experience with ServiceNow GRC is advantageous. Certifications such as CISSP, CSSLP, CCSP, CISM, CISMP, GCIH, CEH are advantageous. Skills Strong communication and coordination skills, engaging effectively with stakeholders across diverse teams. Proactive, self motivated and comfortable in a dynamic, continuously evolving environment. Strong analytical capabilities and creative problem solving skills. Structured, synthetic, delivering clear, concise and relevant responses. Calm, organized, efficient under pressure, maintaining clarity even in uncertain situations. Collaborative mindset, working effectively with executives, business leaders and technical teams. Autonomous and well organized, with strong prioritisation and time management ability.
Tombola
Governance, Risk & Compliance (GRC) Analyst
Tombola
Sunderland - hybrid - Perm Some roles sit in tech. Some sit in compliance. This one sits right in the middle. We're looking for someone who can confidently bridge both worlds, understanding the technical detail while translating it into clear, practical guidance across the business. This role has opened up due to an internal promotion into a senior position, something we love to celebrate at tombola as part of how we grow and develop our people. We're on the lookout for a Governance, Risk & Compliance (GRC) Analyst to join our friendly and growing InfoSec team here at tombola. You'll be joining a collaborative team of security-minded professionals along side our Operational Security, Offensive Security and IT Support Teams. We take what we do seriously, but we don't take ourselves too seriously. What you'll be doing This is a key role where you'll sit right at the heart of how we balance security, compliance and innovation. You'll be helping us shape and deliver an effective technical compliance framework, making sure we maintain a strong security posture while still moving at pace as a business. Working closely with technology teams, compliance, and stakeholders across tombola, you'll help identify, assess and manage technology and security risks. A big part of your role will be translating complex technical and regulatory requirements into something meaningful and actionable for different audiences across the business. You'll also: Support the ongoing development and improvement of our ISMS, policies, standards and processes Lead and support audits, working with external partners and Group teams Help ensure our platforms and games meet both local and international regulatory requirements Act as a key point of contact between InfoSec and the wider business, building strong relationships and driving the right outcomes What we're looking for We're looking for someone who's curious, confident and comfortable operating between technical and non-technical worlds. You don't need to be hands on coding, but you do need to understand technology well enough to ask the right questions, challenge where needed and hold your own in conversations with technical teams. You'll likely bring: A strong understanding of security frameworks, standards or compliance environments The ability to interpret technical concepts and communicate them clearly to different audiences Confidence to challenge, influence and guide stakeholders across the business Strong organisational skills, with the ability to manage multiple priorities We'd also love someone who: Is naturally inquisitive and enjoys getting into the detail Is comfortable asking questions and challenging the status quo Enjoys working with a wide range of people and building relationships Takes pride in doing things thoroughly and properly Ways of working This role is based at our Sunderland HQ, with a hybrid approach of 3 days in the office and 2 days working from home. That means plenty of time collaborating with the team, alongside space to focus and get stuck into the detail. Why tombola We're a business built on innovation, collaboration and doing things differently. We're always looking to improve how we work and we genuinely welcome new ideas and perspectives. If you're looking for a role where you can make an impact, grow your career and be part of a team that backs each other, we'd love to hear from you. At tombola we know that our differences make us stronger and that thinking differently is key to long term success. We work hard to create a culture of inclusivity where everyone can celebrate our Free to be mevalue. We are committed to creating opportunities for everyone here at tombola, we welcome applications from all backgrounds and encourage individuals to apply, even if you don't meet every requirement.
07/07/2026
Full time
Sunderland - hybrid - Perm Some roles sit in tech. Some sit in compliance. This one sits right in the middle. We're looking for someone who can confidently bridge both worlds, understanding the technical detail while translating it into clear, practical guidance across the business. This role has opened up due to an internal promotion into a senior position, something we love to celebrate at tombola as part of how we grow and develop our people. We're on the lookout for a Governance, Risk & Compliance (GRC) Analyst to join our friendly and growing InfoSec team here at tombola. You'll be joining a collaborative team of security-minded professionals along side our Operational Security, Offensive Security and IT Support Teams. We take what we do seriously, but we don't take ourselves too seriously. What you'll be doing This is a key role where you'll sit right at the heart of how we balance security, compliance and innovation. You'll be helping us shape and deliver an effective technical compliance framework, making sure we maintain a strong security posture while still moving at pace as a business. Working closely with technology teams, compliance, and stakeholders across tombola, you'll help identify, assess and manage technology and security risks. A big part of your role will be translating complex technical and regulatory requirements into something meaningful and actionable for different audiences across the business. You'll also: Support the ongoing development and improvement of our ISMS, policies, standards and processes Lead and support audits, working with external partners and Group teams Help ensure our platforms and games meet both local and international regulatory requirements Act as a key point of contact between InfoSec and the wider business, building strong relationships and driving the right outcomes What we're looking for We're looking for someone who's curious, confident and comfortable operating between technical and non-technical worlds. You don't need to be hands on coding, but you do need to understand technology well enough to ask the right questions, challenge where needed and hold your own in conversations with technical teams. You'll likely bring: A strong understanding of security frameworks, standards or compliance environments The ability to interpret technical concepts and communicate them clearly to different audiences Confidence to challenge, influence and guide stakeholders across the business Strong organisational skills, with the ability to manage multiple priorities We'd also love someone who: Is naturally inquisitive and enjoys getting into the detail Is comfortable asking questions and challenging the status quo Enjoys working with a wide range of people and building relationships Takes pride in doing things thoroughly and properly Ways of working This role is based at our Sunderland HQ, with a hybrid approach of 3 days in the office and 2 days working from home. That means plenty of time collaborating with the team, alongside space to focus and get stuck into the detail. Why tombola We're a business built on innovation, collaboration and doing things differently. We're always looking to improve how we work and we genuinely welcome new ideas and perspectives. If you're looking for a role where you can make an impact, grow your career and be part of a team that backs each other, we'd love to hear from you. At tombola we know that our differences make us stronger and that thinking differently is key to long term success. We work hard to create a culture of inclusivity where everyone can celebrate our Free to be mevalue. We are committed to creating opportunities for everyone here at tombola, we welcome applications from all backgrounds and encourage individuals to apply, even if you don't meet every requirement.
Senior SAP Security Analyst
Rsgroup Corby, Northamptonshire
Senior SAP Security Analyst Location: Corby, ENG, GB, NN17 5JF Brand: RS Group Function: Digital & Technology Work Location: Hybrid - this is a hybrid role, offering a combination of working remotely and from our Corby office. Contract Type: Permanent The Opportunity The Senior SAP Security Analyst is responsible for leading the design, implementation, and governance of SAP security and access controls across the enterprise. This role ensures that user access is appropriately provisioned, compliant with internal policies and regulatory requirements, and aligned with business needs. The senior analyst also drives continuous improvement of security processes, provides guidance to junior team members, and partners with stakeholders to manage risk while enabling efficient operations. What You Will Be Doing Ensure SAP compliance procedures align with Group-level Information Security policies, PCI and NIST security requirements. Utilise proficiency in SAP systems, applications and processes to develop and maintain SAP security architecture and controls. Design, create and manage SAP user profiles, roles and authorisations, defining and enforcing standards to ensure effective role-based access control. Manage SAP Security using SAP Governance, Risk and Compliance (GRC) solutions, including Access Control and Process Control. Ensure technical debt is addressed through clear roadmaps for corrective action to simplify, standardise and strengthen security. Define and recommend actions to mitigate security risks and actively manage them through to resolution. Develop and maintain security policies, procedures, training and compliance reporting in line with RS Group Information Security policies. Work closely with business, project and SAP teams to implement controls, embed security into governance and delivery, and ensure new technologies are deployed securely and compliantly. Drive improvements in team Ways of Working, including processes, standards, documentation and security management practices. Support demand management, capacity planning and backlog prioritisation to ensure effective delivery of team objectives. Articulate emerging trends to leadership and drive initiatives that improve tooling, security management and ways of working. Manage third party service providers to ensure compliance with security SLAs, KPIs, processes, procedures and standards, and drive remediation where required. What You'll Bring 5+ years of experience in an SAP Security related role Minimum of 5 years' experience in an Information Security role Excellent written and oral communication skills Self-motivated and able to work independently Experience and proficiency in various security-related toolsets and best practices Strong understanding of SAP GRC College degree or equivalent experience in an IT related function Certification in SAP GRC Rewards Our total reward package includes financial, wellbeing and lifestyle components, and a global recognition programme. Financial: pension/retirement; life assurance; salary finance (payroll deduction loan scheme) Wellbeing: medical plans; health screening; critical illness; disability insurance; holiday / paid time off; employee assistance programme; discounted gym/health club membership Lifestyle: transportation assistance schemes (e.g., cycle to work, travel loans, car leasing); onsite catering/lunch vouchers; retail discounts All employees are welcome to apply under the Equal Employment Opportunity guidelines. RS Group is an equal opportunity employer.
07/07/2026
Full time
Senior SAP Security Analyst Location: Corby, ENG, GB, NN17 5JF Brand: RS Group Function: Digital & Technology Work Location: Hybrid - this is a hybrid role, offering a combination of working remotely and from our Corby office. Contract Type: Permanent The Opportunity The Senior SAP Security Analyst is responsible for leading the design, implementation, and governance of SAP security and access controls across the enterprise. This role ensures that user access is appropriately provisioned, compliant with internal policies and regulatory requirements, and aligned with business needs. The senior analyst also drives continuous improvement of security processes, provides guidance to junior team members, and partners with stakeholders to manage risk while enabling efficient operations. What You Will Be Doing Ensure SAP compliance procedures align with Group-level Information Security policies, PCI and NIST security requirements. Utilise proficiency in SAP systems, applications and processes to develop and maintain SAP security architecture and controls. Design, create and manage SAP user profiles, roles and authorisations, defining and enforcing standards to ensure effective role-based access control. Manage SAP Security using SAP Governance, Risk and Compliance (GRC) solutions, including Access Control and Process Control. Ensure technical debt is addressed through clear roadmaps for corrective action to simplify, standardise and strengthen security. Define and recommend actions to mitigate security risks and actively manage them through to resolution. Develop and maintain security policies, procedures, training and compliance reporting in line with RS Group Information Security policies. Work closely with business, project and SAP teams to implement controls, embed security into governance and delivery, and ensure new technologies are deployed securely and compliantly. Drive improvements in team Ways of Working, including processes, standards, documentation and security management practices. Support demand management, capacity planning and backlog prioritisation to ensure effective delivery of team objectives. Articulate emerging trends to leadership and drive initiatives that improve tooling, security management and ways of working. Manage third party service providers to ensure compliance with security SLAs, KPIs, processes, procedures and standards, and drive remediation where required. What You'll Bring 5+ years of experience in an SAP Security related role Minimum of 5 years' experience in an Information Security role Excellent written and oral communication skills Self-motivated and able to work independently Experience and proficiency in various security-related toolsets and best practices Strong understanding of SAP GRC College degree or equivalent experience in an IT related function Certification in SAP GRC Rewards Our total reward package includes financial, wellbeing and lifestyle components, and a global recognition programme. Financial: pension/retirement; life assurance; salary finance (payroll deduction loan scheme) Wellbeing: medical plans; health screening; critical illness; disability insurance; holiday / paid time off; employee assistance programme; discounted gym/health club membership Lifestyle: transportation assistance schemes (e.g., cycle to work, travel loans, car leasing); onsite catering/lunch vouchers; retail discounts All employees are welcome to apply under the Equal Employment Opportunity guidelines. RS Group is an equal opportunity employer.
Senior SAP Security & GRC Lead - Hybrid Role
Rsgroup Corby, Northamptonshire
Rsgroup is looking for a Senior SAP Security Analyst in Corby to lead the design and governance of SAP security across the enterprise. This hybrid role demands a leader who will ensure user access is compliant and aligned with business needs. With a focus on continuous improvement, the candidate will manage third-party security compliance, develop security policies, and enhance team processes. Ideal candidates should have over 5 years of experience in SAP security and information security roles.
07/07/2026
Full time
Rsgroup is looking for a Senior SAP Security Analyst in Corby to lead the design and governance of SAP security across the enterprise. This hybrid role demands a leader who will ensure user access is compliant and aligned with business needs. With a focus on continuous improvement, the candidate will manage third-party security compliance, develop security policies, and enhance team processes. Ideal candidates should have over 5 years of experience in SAP security and information security roles.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board