At a Glance
- Tasks: Join our Security & Compliance team as a Security GRC Analyst, ensuring compliance and mitigating risks.
- Company: Turnitin is a global leader in education technology, promoting integrity and fairness for over 25 years.
- Benefits: Enjoy remote work, generous time off, health coverage, and wellness programs tailored for your needs.
- Why this job: Make a real impact in education while working in a supportive, diverse, and innovative environment.
- Qualifications: Bachelor's degree or equivalent experience with 3+ years in Information Security or Cybersecurity Compliance required.
- Other info: We value continuous learning and encourage applicants who meet most criteria to apply.
The predicted salary is between 36000 - 60000 £ per year.
When you join Turnitin, you'll be welcomed into a company that is a recognized innovator in the global education space. For over 25 years, Turnitin has partnered with educational institutions to promote honesty, consistency, and fairness across all subject areas and assessment types. Over 21,000 academic institutions, publishers, and corporations use our services: Feedback Studio, Originality, Gradescope, ExamSoft, Similarity, and iThenticate. Experience a remote-centric culture that empowers you to work with purpose and accountability in a way that best suits you, supported by a comprehensive package that prioritises your overall well-being. Our diverse community of colleagues are all unified by a shared desire to make a difference in education. Turnitin is a global organization with team members in over 35 countries including the United States, Mexico, United Kingdom, Australia, Japan, India, and the Philippines.
Turnitin is seeking an experienced Security GRC Analyst to join our Security & Compliance team. The Sr Security GRC Analyst will be responsible for ensuring that our information and cloud systems comply with relevant regulatory frameworks, industry standards, and internal policies. They will also collaborate with various departments, monitor compliance, conduct assessments, and support initiatives to identify and mitigate risks. We are looking for someone who brings strong analytical ability, attention to detail, effective communication, compliance experience, and the willingness to continuously learn. This role requires hands-on work, critical thinking and the ability to find new solutions for compliance. This role reports to the GRC Information Security Manager.
Responsibilities:
- Maintain compliance tracking capabilities to help ensure adherence with Turnitin’s security program and industry standards such as NIST CSF, NIST 800-53, SOC 2, TX-RAMP and PCI DSS.
- Conduct risk and compliance assessments, audits, and risk evaluations to identify potential risk and compliance gaps.
- Lead preparation and audit activities required to maintain our SOC 2 Type 2.
- Collaborate with internal teams and external auditors for audit and compliance reviews.
- Collaborate with sales and customer support teams to respond to security questionnaires and security posture questions from customers.
- Support TPRM Program and conduct third-party risk assessments.
- Complete user access reviews.
- Administration of GRC platform.
- Participate in the development and documentation of security policy, standards and processes to align with company information security strategy.
- Provide security awareness and phishing training for employees and promote a culture of security and compliance.
- Coordinate phish testing.
- Collaborate with DevOps, IT, Legal, Engineering, People Team, and other departments to ensure security control and policy requirements are integrated into systems and business processes.
- Provide input on ways to improve and automate team processes.
Qualifications:
- Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent experience).
- 3+ years of experience in a role related to Information Security or Cybersecurity Compliance.
- Professional certification such as CCSK, AWS Cloud Practitioner, or other related industry certification.
- Familiarity with cybersecurity frameworks and regulatory standards such as NIST, SOC 2, TX-RAMP, and PCI DSS.
- Familiarity of risk management and security best practices.
- Experience with assessing security controls, risk mitigation strategies, and audit procedures.
- Understanding of concepts related to AWS Cloud Infrastructure and security.
- Experience conducting security impact analysis for system changes.
- Experience conducting periodic internal security reviews or risk assessments to ensure that compliance procedures and technical configurations are followed.
- Experience conducting third-party risk assessments.
- Contract review experience for security requirements.
- Highly organized and proactive individual capable of managing multiple responsibilities and delivering results.
Preferred Skills:
- Experience running SOC 2 audits or NIST based authorizations.
- Experience using Jira and Confluence for project and task management.
- Hands-on experience with Wiz, KnowBe4, and Hyperproof.
- Demonstrated knowledge of security assessment of cloud technology and services (AWS).
- Entry level cybersecurity certification such as Security+, GIAC GSEC, or ISC2 Certified in Cybersecurity.
Additional Information:
Total Rewards @ Turnitin Turnitin maintains a Total Rewards package that is competitive within the local job market. Beyond the intrinsic rewards of unleashing your potential to positively impact global education, and thriving in an organization that is free of politics and full of humble, inclusive and collaborative teammates, the extrinsic rewards at Turnitin include generous time off and health and wellness programs that offer choice and flexibility and provide a safety net for the challenges that life presents from time to time.
Our Mission is to ensure the integrity of global education and meaningfully improve learning outcomes.
Our Values underpin everything we do.
- Customer Centric - We realise our mission to ensure integrity and improve learning outcomes by putting educators and learners at the center of everything we do.
- Passion for Learning - We seek out teammates that are constantly learning and growing and build a workplace which enables them to do so.
- Integrity - We believe integrity is the heartbeat of Turnitin. It shapes our products, the way we treat each other, and how we work with our customers and vendors.
- Action & Ownership - We have a bias toward action and empower teammates to make decisions.
- One Team - We strive to break down silos, collaborate effectively, and celebrate each other’s successes.
- Global Mindset - We respect local cultures and embrace diversity. We think globally and act locally to maximize our impact on education.
Remote First Culture
- Health Care Coverage*
- Education Reimbursement*
- Competitive Paid Time Off
- 4 Self-Care Days per year
- National Holidays*
- Charitable contribution match*
- Monthly Wellness or Home Office Reimbursement/*
- Access to Modern Health (mental health platform)
- Retirement Plan with match/contribution*
* varies by country
Seeing Beyond the Job Ad At Turnitin, we recognize it’s unrealistic for candidates to fulfill 100% of the criteria in a job ad. We encourage you to apply if you meet the majority of the requirements because we know that skills evolve over time. If you’re willing to learn and evolve alongside us, join our team!
Turnitin, LLC is committed to the policy that all persons have equal access to its programs, facilities and employment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Security GRC Analyst (UK Remote) employer: Turnitin, LLC
Contact Detail:
Turnitin, LLC Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security GRC Analyst (UK Remote)
✨Tip Number 1
Familiarise yourself with the specific compliance frameworks mentioned in the job description, such as NIST CSF and SOC 2. Understanding these frameworks will not only help you during interviews but also demonstrate your commitment to the role.
✨Tip Number 2
Network with current or former employees of Turnitin on platforms like LinkedIn. Engaging with them can provide insights into the company culture and expectations, which can be invaluable during your application process.
✨Tip Number 3
Prepare to discuss your experience with risk assessments and compliance audits in detail. Be ready to share specific examples of how you've identified and mitigated risks in previous roles, as this is a key responsibility for the position.
✨Tip Number 4
Showcase your willingness to learn by mentioning any recent courses or certifications related to cybersecurity or compliance that you've pursued. This aligns with Turnitin's value of a passion for learning and can set you apart from other candidates.
We think you need these skills to ace Security GRC Analyst (UK Remote)
Some tips for your application 🫡
Tailor Your CV: Make sure to customise your CV to highlight relevant experience in Information Security and Cybersecurity Compliance. Emphasise your familiarity with frameworks like NIST, SOC 2, and PCI DSS, as well as any specific tools or certifications you possess.
Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for education and compliance. Mention how your skills align with Turnitin's mission and values, and provide examples of how you've successfully managed compliance or security projects in the past.
Highlight Relevant Experience: In your application, focus on your hands-on experience with risk assessments, audits, and compliance tracking. Use specific examples to demonstrate your analytical abilities and attention to detail, which are crucial for this role.
Show Willingness to Learn: Turnitin values continuous learning. In your application, express your eagerness to grow within the role and mention any recent training or certifications you've pursued related to cybersecurity or compliance.
How to prepare for a job interview at Turnitin, LLC
✨Understand the Compliance Landscape
Familiarise yourself with key regulatory frameworks and standards such as NIST CSF, SOC 2, and PCI DSS. Be prepared to discuss how your experience aligns with these standards and how you can contribute to maintaining compliance at Turnitin.
✨Showcase Your Analytical Skills
As a Security GRC Analyst, strong analytical abilities are crucial. Prepare examples from your past experiences where you identified risks or compliance gaps and how you addressed them. This will demonstrate your problem-solving skills and attention to detail.
✨Communicate Effectively
Effective communication is key in this role, especially when collaborating with various departments. Practice articulating complex security concepts in simple terms, as you may need to explain compliance requirements to non-technical stakeholders.
✨Demonstrate a Willingness to Learn
Turnitin values continuous learning. Be ready to discuss how you stay updated on industry trends and your approach to professional development. Mention any relevant certifications or courses you are pursuing to show your commitment to growth in the field.