Information Security - GRC Analyst
Information Security - GRC Analyst

Information Security - GRC Analyst

Full-Time 30000 - 40000 ÂŁ / year (est.) No home office possible
Avalere Health Inc.

At a Glance

  • Tasks: Support governance, risk, and compliance in information security while driving impactful projects.
  • Company: Avalere Health, dedicated to ensuring every patient receives equal care.
  • Benefits: Flexible working, competitive pension, private medical insurance, and generous leave policies.
  • Other info: Inclusive culture with strong support for professional growth and diverse backgrounds.
  • Why this job: Kickstart your career in a meaningful role that makes a real difference in healthcare.
  • Qualifications: Detail-oriented with a foundational understanding of information security concepts.

The predicted salary is between 30000 - 40000 ÂŁ per year.

About Avalere Health

United by one profound purpose: to reach EVERY PATIENT POSSIBLE. At Avalere Health, we ensure every patient is identified, treated, supported, and cared for. Our Advisory, Medical, and Marketing teams come together to forge unconventional connections, building a future where healthcare is not a barrier and no patient is left behind. Achieving our mission starts with providing enriching, purpose-driven careers for our team that empower them to make a tangible impact on patient lives.

We are committed to creating a culture where our employees are empowered to bring their whole selves to work and tap into the power of diverse backgrounds and skillsets to play a part in making a difference for every patient, everywhere. Our flexible approach to working allows our global teams to decide where they want to work, whether in-office or at home based on team and client need. Major city hubs in London, Manchester, Washington, D.C., and New York, and smaller offices globally, serve as collaboration hubs allowing our teams to come together when it matters. Homeworkers are equally supported, with dedicated social opportunities and resources.

Our inclusive culture is at the heart of everything we do. We proudly support our employees in bringing their whole selves to work with our six Employee Network Groups – Diverse Ability, Family, Gender, LGBTQ+, Mental Health, and Race/Ethnicity. These groups provide opportunities to promote diversity, equity and inclusion and to connect, learn, and socialise through regular meetings and programs of activity. We are an accredited Fertility Friendly employer with our Fertility Policy, enhanced parental leave, and culture of flexibility ensuring every employee feels supported across their family planning journey and can work in a way that suits their family’s needs.

We take pride in supporting professional growth for our employees through day‑to‑day career experiences, access to thousands of on‑demand training sessions, regular career conversations, and the opportunity for global, cross‑capability career moves. We take pride in being part of the Disability Confident Scheme. This helps make sure you can be interviewed fairly if you have a disability, long term health condition, or are neurodiverse. If you would like to apply and need adjustments made, you can let us know in your application.

About The Role

The Information Security GRC Analyst supports the InfoSec GRC Lead in operating and improving the organization’s governance, risk, and compliance program. The role focuses on reviewing client MSAs and related security requirements, supporting internal and client audits, driving risk and exception management workflows, and supporting supplier/third‑party security reviews. The organization is aligned to ISO/IEC 27001 and is implementing ISO/IEC 42001. The role supports compliance activities relevant to HIPAA, GDPR, and APPI. This is an excellent opportunity for recent graduates or young professionals to build their career in information security.

What You’ll Do

  • Governance & Management System Support: Maintain documentation and evidence for ISO/IEC 27001 & ISO/IEC 42001; support continual improvement activities.
  • Client MSA & Security Requirements Review: Extract and document security requirements from client MSAs; identify gaps and risks; coordinate with Legal and Privacy teams.
  • Audit Support: Coordinate internal and client audit requests; collect evidence; ensure traceability between requirements, controls, and evidence.
  • Risk Management & Exceptions: Assist with risk assessments for vendors/projects; maintain risk registers; support exception workflows.
  • Supplier Reviews: Assess third‑party security submissions; track supplier risk ratings and remediation actions.
  • Compliance Support: Help map regulatory requirements (HIPAA, GDPR, APPI) to internal controls; maintain compliance documentation.
  • Reporting & Improvement: Produce operational reports on audit status/risk metrics; contribute to process improvements.

About You

  • Exceptional attention to detail
  • Strong written communication skills
  • Professional discretion handling sensitive information
  • Foundational understanding of information security concepts (access control, encryption, incident response)
  • Exposure or interest in ISO/IEC 27001 or AI governance frameworks (ISO/IEC 42001)
  • Experience supporting audits, vendor risk reviews or privacy compliance is advantageous
  • Familiarity with GRC/ticketing/documentation platforms (e.g., ServiceNow/Jira)
  • Suitable for junior candidates (1–3 years) in security, IT, risk, compliance, audit, or related fields, or equivalent demonstrated capability.
  • Bachelor’s degree in information security, IT, Risk Management, Compliance, or similar is beneficial but not required with relevant experience.
  • Minimum requirement: Candidate must hold or be able to achieve the ISC2 Certified in Cybersecurity (CC) certification within an agreed onboarding period (company‑supported).

What we can offer

  • You’ll receive up to a 7% pension contribution, life insurance, income protection, and private medical insurance for peace of mind.
  • Enjoy flexible working arrangements, including flexible hybrid working, along with the option to work from anywhere across the globe two weeks each year.
  • We provide 25 days of annual leave plus two personal well‑being days, along with gifted end‑of‑year holidays and an early Summer Friday finish in June, July, and August.
  • Access free counselling through our employee assistance program, as well as personalized health support.
  • Enhanced maternity, paternity, family leave, and fertility policies provide support across every stage of your family‑planning journey, as well as on‑demand support from our partner Peppy.
  • You can also benefit from continuous opportunities to professionally develop with on‑demand training, support, and global mobility opportunities across the business.

We encourage all applicants to read our candidate privacy notice before applying to Avalere Health.

Information Security - GRC Analyst employer: Avalere Health Inc.

Avalere Health is an exceptional employer dedicated to empowering its employees to make a meaningful impact on patient lives. With a flexible working culture that supports both in-office and remote work, alongside comprehensive benefits such as enhanced family leave policies and continuous professional development opportunities, Avalere fosters an inclusive environment where diverse backgrounds are celebrated. Employees can thrive in a collaborative atmosphere, supported by various Employee Network Groups and resources that promote well-being and career growth.
Avalere Health Inc.

Contact Detail:

Avalere Health Inc. Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security - GRC Analyst

✨Tip Number 1

Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. We all know that sometimes it’s not just what you know, but who you know that can help you land that dream job.

✨Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their mission and values, especially how they relate to patient care. This will show you’re genuinely interested and ready to contribute to their goals.

✨Tip Number 3

Practice your responses to common interview questions, but keep it natural. We want you to sound confident and authentic, so don’t just memorise answers—make them your own!

✨Tip Number 4

Don’t forget to follow up after your interview! A simple thank-you email can go a long way in showing your appreciation and keeping you top of mind. And remember, apply through our website for the best chance at landing that role!

We think you need these skills to ace Information Security - GRC Analyst

Governance, Risk, and Compliance (GRC)
ISO/IEC 27001
ISO/IEC 42001
HIPAA compliance
GDPR compliance
APPI compliance
Audit Support
Risk Assessment
Documentation Skills
Attention to Detail
Written Communication Skills
Information Security Concepts
Vendor Risk Reviews
Familiarity with GRC Platforms (e.g., ServiceNow, Jira)
ISC2 Certified in Cybersecurity (CC) certification

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter for the Information Security GRC Analyst role. Highlight your relevant skills and experiences that align with the job description, especially around governance, risk, and compliance.

Showcase Your Attention to Detail: Since this role requires exceptional attention to detail, be sure to proofread your application thoroughly. Any typos or errors could give the impression that you might overlook important details in your work.

Express Your Passion for Information Security: Let us know why you're excited about a career in information security! Share any relevant projects, coursework, or experiences that demonstrate your interest and foundational understanding of security concepts.

Apply Through Our Website: We encourage you to apply directly through our website. This ensures your application is received properly and gives you the best chance to showcase your fit for the role. Plus, it’s super easy!

How to prepare for a job interview at Avalere Health Inc.

✨Know Your Stuff

Make sure you brush up on information security concepts, especially those related to ISO/IEC 27001 and 42001. Familiarise yourself with HIPAA, GDPR, and APPI regulations, as these will likely come up during your interview.

✨Showcase Your Attention to Detail

Since this role requires exceptional attention to detail, be prepared to discuss examples from your past experiences where you demonstrated this skill. Whether it’s through academic projects or previous jobs, highlight how your meticulous nature has led to successful outcomes.

✨Prepare for Scenario Questions

Expect scenario-based questions that assess your problem-solving skills in risk management and compliance. Think of situations where you had to identify gaps or manage exceptions, and be ready to explain your thought process and actions.

✨Ask Insightful Questions

At the end of the interview, don’t forget to ask questions that show your interest in the company culture and the role. Inquire about their approach to continuous improvement in governance and compliance, or how they support professional growth within the team.

Information Security - GRC Analyst
Avalere Health Inc.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>