At a Glance
- Tasks: Support the InfoSec team in governance, risk, and compliance across multiple business areas.
- Company: Join Leonardo UK, a leader in Aerospace, Defence, and Security.
- Benefits: Enjoy flexible working, generous leave, and a comprehensive benefits package.
- Other info: Opportunities for career growth and professional development await you.
- Why this job: Make a real impact in security while developing your skills in a dynamic environment.
- Qualifications: Experience in information security or a willingness to learn is essential.
The predicted salary is between 58500 - 71500 £ per year.
Your impact
Leonardo UK operates in a complex security, regulatory and defence environment. As a Governance, Risk and Compliance Analyst, you will support the Information Security team in maintaining clear standards, assessing risk and providing assurance that security controls are understood, evidenced and reviewed across the business. The role will work across multiple business areas and may require travel between Leonardo UK sites, with hybrid working supported where appropriate.
What you will do as Governance, Risk and Compliance Analyst:
- Support the Head of Governance, Risk and Compliance with the day-to-day information security governance, risk and compliance workload.
- Assist with maintaining security standards, control mappings and assurance processes.
- Support reviews of security management and assurance plans to help ensure controls are properly described, evidenced and aligned to the agreed standard.
- Conduct or support risk assessments where security controls are not implemented, including documenting the risk position and supporting appropriate review.
- Conduct audit and assurance activity across Leonardo UK systems and services.
- Help track non-compliances, remediation activity and risk acceptance decisions.
- Work with delivery teams, system owners and security specialists to gather evidence and support proportionate security governance.
- Contribute to compliance, risk and assurance reporting for the Information Security function.
- Support continual improvement of the Information Security Operating Model, including better use of data, tooling and automation.
What you’ll bring
You will bring experience or strong working knowledge of information security governance, risk and compliance. You should be comfortable working with security standards, control frameworks, risk records and assurance evidence in a regulated environment.
Essential experience and skills:
- Experience in information security, cyber risk, compliance, assurance or audit.
- Knowledge of security control frameworks and risk management practices.
- Understanding of cyber and information risk frameworks and methodologies.
- Understanding of MoD and other UK government security policy and frameworks.
- Familiarity with security standards, policies, control frameworks or risk management artefacts.
- Practical understanding of risk assessment, residual risk, risk acceptance and non-compliance management.
- Experience supporting audits, assurance reviews, control testing or compliance reporting.
- Ability to review evidence and assess whether security controls are clearly described and appropriately supported.
- Experience working with technical and non-technical stakeholders to gather information and support risk or assurance activity.
- Professional security qualification such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or willingness to work towards one.
- Knowledge of governance tooling, dashboards, data analysis or automation would be beneficial.
This is not an exhaustive list, and we are keen to hear from you even if you might not have experience in all the above. The most important skill is a good attitude and willingness to learn.
Security Clearance
This role is subject to pre-employment screening in line with the UK Government’s Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV).
Why join us
At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work–life balance. Whether you're looking to grow professionally, care for your health, or plan for the future, we’re here to help you thrive.
- Time to Recharge: Enjoy generous leave with the opportunity to accrue up to 12 additional flexi-days each year.
- Secure your Future: Benefit from our award-winning pension scheme with up to 15% employer contribution.
- Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks championing inclusion and diversity.
- Rewarding Performance: All employees at management level and below are eligible for our bonus scheme.
- Never Stop Learning: Free access to 4,000+ online courses via Coursera and LinkedIn Learning.
- Refer a friend: Receive a financial reward through our referral programme.
- Tailored Perks: Spend up to £500 annually on flexible benefits including private healthcare, dental, family cover, tech & lifestyle discounts, gym memberships and more.
- Flexible working: Flexible hours with hybrid working options. For part time opportunities, please talk to us about what might be possible for this role.
For a full list of our company benefits please visit our website.
Leonardo UK operates a grade-based salary framework with broad bands. The salary range shown reflects the approved grade band for this role, or a narrower hiring range published within that band, and is benchmarked against the external market. Exceptions above the standard range are managed through governance controls to protect internal equity.
Leonardo is a global leader in Aerospace, Defence, and Security. Headquartered in Italy, we employ over 53,000 people worldwide including 8,500 across 9 sites in the UK. Our employees are not just part of a team—they are key contributors to shaping innovation, advancing technology, and enhancing global safety.
At Leonardo we are committed to building an inclusive, accessible, and welcoming workplace. We believe that a diverse workforce sparks creativity, drives innovation, and leads to better outcomes for our people and our customers. If you have any accessibility requirements to support you during the recruitment process, just let us know.
InfoSec Governance, Risk and Compliance Analyst in Yeovil employer: 慨正橡扯
At 慨正橡扯, we pride ourselves on being an exceptional employer that champions innovation and collaboration in the field of Behavioral Economics and Retirement Research. Our hybrid working model not only offers flexibility but also nurtures a vibrant work culture where employees are encouraged to grow and develop their skills through meaningful projects and leadership opportunities. Join us in Europe, where your expertise will directly contribute to enhancing investor outcomes and shaping impactful business strategies.
StudySmarter Expert Advice🤫
We think this is how you could land InfoSec Governance, Risk and Compliance Analyst in Yeovil
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including 慨正橡扯, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through 慨正橡扯
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at 慨正橡扯. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace InfoSec Governance, Risk and Compliance Analyst in Yeovil
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at 慨正橡扯 insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to 慨正橡扯 that you’re committed to staying ahead in the game.
How to prepare for a job interview at 慨正橡扯
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at 慨正橡扯 to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at 慨正橡扯.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.