Governance, Risk and Compliance GRC Analyst
Governance, Risk and Compliance GRC Analyst

Governance, Risk and Compliance GRC Analyst

Full-Time 36000 - 60000 £ / year (est.) Home office (partial)
N

At a Glance

  • Tasks: Join our Cyber Security team to manage risks and ensure compliance with regulations.
  • Company: N Brown is a leading digital retailer focused on inclusion and sustainability.
  • Benefits: Enjoy hybrid working, 24 days holiday, mental health support, and colleague discounts.
  • Why this job: Be part of a diverse team that values your input and promotes a strong security culture.
  • Qualifications: Strong writing skills, technical knowledge, and experience with compliance frameworks like PCI DSS required.
  • Other info: Flexible working hours and a vibrant office location in Manchester's Northern Quarter.

The predicted salary is between 36000 - 60000 £ per year.

We're looking for a Governance, Risk and Compliance (GRC) Analyst to join our Cyber Security and Risk team here at N Brown Group. The Governance, Risk and Compliance team is responsible for the development and rollout of our security policies and procedures; for building an awareness programme to promote a strong security culture across the organisation; identifying and tracking risks in our supply chain; and for ensuring we maintain compliance with regulations such as the PCI DSS. The team works closely with 1st and 2nd line risk to develop suitable controls and metrics to ensure the Digital Operations department is operating within risk appetite, and track remediation tasks when it is not.

As a Governance, Risk and Compliance (GRC) Analyst you will work across all these areas of the team's responsibilities and help to identify ways to improve simplicity and efficiency. Although this isn’t a technical role, you will be expected to have sufficient technical expertise to understand technology risks and controls to mitigate them.

What will you do as a Governance, Risk and Compliance (GRC) Analyst at N Brown?

  • Support the risk management process by identifying and evaluating threats, and work with risk owners to understand the business impact and help develop treatment plans.
  • Track open risk remediation tasks and facilitate the approval process for risk acceptance requests, ensuring sufficient mitigating controls are in place.
  • Complete risk-based security due diligence on third-party providers during the initial contracting phase and at regular intervals.
  • Contribute to the development of control testing strategies, to ensure our security controls are operating effectively and achieving their purpose.
  • Help maintain compliance with applicable regulations such as the PCI DSS, assist in finding ways to streamline the assessment process.
  • Support the development and delivery of the security awareness training programme by working closely with colleagues across the business to promote a strong information security culture.
  • Design and delivery of regular communication materials over multiple channels.
  • Management and reporting of regular phishing simulation exercises.
  • Management and oversight of Penetration tests.
  • Drive adoption and adherence to Information Security policy, standards, and guidelines.
  • Evaluate requests for exceptions to policies and security compliance queries.
  • Integrate and transform information security policies, standards and procedures.

What skills and experience will you have?

  • Skilled in writing a range of documentation, relevant for the business, ranging from processes and procedures to reports, standards and frameworks.
  • Experience of applying policies and controls in an agile, cloud first organisation.
  • Sufficient technical knowledge to understand risks associated with technology platforms and the controls to mitigate them.
  • Able to constructively challenge processes and procedures to drive continuous improvement.
  • Experience of working within PCI DSS, or other compliance frameworks.
  • Excellent communication skills with the ability to build great relationships across the business and articulate security concepts to non-technical colleagues.
  • Knowledge of how to assist in the delivery of a security awareness programme across a large business.

Benefits:

  • Hybrid working.
  • 24 days holiday (+ 8 bank holidays) + paid volunteer time.
  • Annual bonus scheme.
  • Enhanced maternity and adoption leave.
  • Company pension with up to 8% N Brown contribution.
  • Mental Health support both internally and externally, including access to our wellbeing champions and counselling services.
  • A range of financial wellbeing support.
  • Colleague discount across all N Brown brands.
  • Onsite café with subsidised rates and local restaurant discounts!
  • Life Assurance and Private Medical Insurance.

N Brown – who we are and why work for us?

At N Brown, we're committed to building a diverse workforce and creating an inclusive environment that values equality for all. Our vision is that by 'championing inclusion, we'll become the most loved and trusted fashion retailer'. Diversity, Equity, Inclusion and Belonging are, therefore, at the heart of our culture.

We're a forward-thinking digital retailer with a financial services proposition to be proud of. We're customer-obsessed, serving them through three core brands: JD Williams, Simply Be, and Jacamo. We're experienced, with over 160 years of trading under our belt. We're inclusive, as we believe in fashion without boundaries; and we're sustainable, striving to make as little impact on the planet as possible.

In May 2024 we were delighted to be named one of The Sunday Times Best Places to Work 2024. We work hard to create a happy and inclusive culture for everyone and we're so proud to have made this list – as voted for by our very own colleagues!

Ways of Working

We offer hybrid working which varies across the business depending on the role you're in. Our Head Office is located in the Northern Quarter in Manchester City Centre. So, if you are travelling by train, tram or bus we're perfectly located, plus we're surrounded by cool cafes, trendy bars and the best places to eat!

Our working hours are 36.17 per week and our core working hours are between 10am – 4pm. Given we don’t have strict working hours you can find the working pattern that's right for you.

Our promise:

We're an equal opportunity employer and value diversity. We do not discriminate based on race, religion, colour, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status.

What happens when you apply to this role as Governance, Risk and Compliance (GRC) Analyst at N Brown?

As soon as we receive your application, we'll send you an email to let you know. We always aim to come back to you as soon as possible with an update and we really appreciate you taking the time to apply for a role with us. Good luck!

Governance, Risk and Compliance GRC Analyst employer: N Brown Group

N Brown Group is an exceptional employer, offering a vibrant work culture that champions diversity and inclusion while prioritising employee wellbeing. With benefits like hybrid working, generous holiday allowances, and a commitment to professional growth, employees thrive in a supportive environment located in the heart of Manchester's Northern Quarter, surrounded by a dynamic array of cafes and eateries.
N

Contact Detail:

N Brown Group Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Governance, Risk and Compliance GRC Analyst

✨Tip Number 1

Familiarise yourself with the PCI DSS regulations and other compliance frameworks relevant to the role. Understanding these standards will not only help you in interviews but also demonstrate your commitment to the responsibilities of a GRC Analyst.

✨Tip Number 2

Network with professionals in the cybersecurity and risk management fields. Attend industry events or webinars to connect with others who work in governance, risk, and compliance, as they can provide valuable insights and potentially refer you to opportunities.

✨Tip Number 3

Showcase your communication skills by preparing to discuss how you've effectively conveyed complex security concepts to non-technical colleagues in past roles. This is crucial for a GRC Analyst, as you'll need to build relationships across the business.

✨Tip Number 4

Research N Brown Group's current security policies and any recent news related to their compliance efforts. Being knowledgeable about the company’s initiatives will allow you to tailor your discussions and show genuine interest during the interview process.

We think you need these skills to ace Governance, Risk and Compliance GRC Analyst

Risk Management
Compliance Knowledge (PCI DSS and other frameworks)
Technical Understanding of Technology Risks
Documentation Skills
Communication Skills
Stakeholder Engagement
Analytical Skills
Continuous Improvement Mindset
Security Awareness Training Development
Control Testing Strategies
Agile Methodologies
Relationship Building
Problem-Solving Skills
Reporting and Metrics Development

Some tips for your application 🫡

Understand the Role: Before you start writing your application, make sure you fully understand the responsibilities and requirements of the Governance, Risk and Compliance (GRC) Analyst position. Tailor your application to highlight how your skills and experiences align with the specific tasks mentioned in the job description.

Highlight Relevant Experience: When detailing your work history, focus on experiences that relate directly to governance, risk management, and compliance. Mention any previous roles where you developed security policies, conducted risk assessments, or worked with compliance frameworks like PCI DSS.

Showcase Communication Skills: Since excellent communication skills are essential for this role, provide examples of how you've effectively communicated complex security concepts to non-technical colleagues. This could be through training sessions, reports, or presentations.

Craft a Strong Cover Letter: Use your cover letter to express your enthusiasm for the role and the company. Discuss your understanding of N Brown's commitment to diversity and inclusion, and explain how you can contribute to their security culture and compliance efforts.

How to prepare for a job interview at N Brown Group

✨Understand the GRC Landscape

Familiarise yourself with the key concepts of Governance, Risk, and Compliance. Be prepared to discuss how these elements interact within an organisation, especially in relation to security policies and procedures.

✨Showcase Your Communication Skills

As a GRC Analyst, you'll need to articulate complex security concepts to non-technical colleagues. Prepare examples of how you've successfully communicated technical information in the past.

✨Demonstrate Technical Knowledge

While this isn't a technical role, having a solid understanding of technology risks is crucial. Brush up on relevant technologies and be ready to discuss how you would identify and mitigate risks associated with them.

✨Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving skills in real-world scenarios. Think about past experiences where you've identified risks or improved processes, and be ready to share those stories.

Governance, Risk and Compliance GRC Analyst
N Brown Group
N
  • Governance, Risk and Compliance GRC Analyst

    Full-Time
    36000 - 60000 £ / year (est.)

    Application deadline: 2027-07-06

  • N

    N Brown Group

Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>