Cyber Security Analyst - Governance, Risk and Culture (GRC)

Cyber Security Analyst - Governance, Risk and Culture (GRC)

Full-Time 45000 - 55000 £ / year (est.) Home office (partial)
B

At a Glance

  • Tasks: Strengthen security posture and foster a cyber-conscious culture across the organisation.
  • Company: Join a dynamic consulting-led environment at Baringa.
  • Benefits: Enjoy generous leave, flexible working, and a wellbeing fund.
  • Other info: Diverse and inclusive workplace with excellent career growth opportunities.
  • Why this job: Make a real impact in cyber security while developing your skills.
  • Qualifications: Experience in Cyber Security GRC and knowledge of compliance requirements.

The predicted salary is between 45000 - 55000 £ per year.

We are currently looking for a Cyber Security Analyst to join our Governance, Risk and Culture (GRC) capability within the wider Cyber Security Team, where you will play a key role in strengthening the firm's security posture, ensuring compliance, and embedding a cyber‑conscious culture across the organisation. The role contributes to the delivery of governance, risk management and assurance activities, including supplier due diligence, audit responses, and the development and maintenance of security policies, standards and controls. You will be a key member of a growing team in a dynamic, consulting‑led environment, working closely with technical, IT and business stakeholders to identify and manage cyber risks and align security strategy with business priorities. Baringa will support your development across GRC domains, offering exposure to evolving regulatory requirements, cloud technologies and emerging areas such as AI, with a wide range of opportunities to shape our approach and make a meaningful impact.

What will you be doing?

  • Develop a complete understanding of Baringa's technology and information systems.
  • Lead in the response to RFPs/audits, including supplier security due diligence and third‑party audit and assurance activities.
  • Identify and communicate current and emerging security threats and cyber risks.
  • Support a program of awareness‑raising and training to deliver compliance and to foster a cyber‑conscious culture across the company.
  • Assist with the definition, implementation and maintenance of corporate security policies, standards and procedures.
  • Provide ‘hands on’ assistance, particularly in technical control implementation and incident response.
  • Coordinating the needs of in‑house IT experts and remote employees, vendors and contractors.
  • Work as part of a team to communicate ideas, suggestions and solutions that achieve the firm's long‑term objectives, especially the GRC Strategy.
  • Align organisational security strategy and infrastructure with overall business and information technology strategy.
  • Manage company compliance with information security, policies, standards, contractual obligations and guidance through business managers and champions providing advice, support and guidance on risk‑based good practice.
  • Lead on and produce technical security MI in support of governance and vulnerability management engagements.
  • Support client engagement leads on client queries and requests during the business development process and ongoing client engagement regarding Baringa's information technology security policies and processes.

What are we looking for?

  • Experience in full‑time operational Cyber Security GRC, or Cyber Security role.
  • Experience of compliance requirements for cloud technology stacks such as Microsoft and AWS.
  • Experience utilising emerging technologies, such as AI, to design and implement security solutions, monitoring and improving those solutions while working with a Cyber Security team.
  • Thorough understanding of relevant industry security standards and protocols including ISO27001, NIST, NSCS CAF, SOC, NIS 2 Directive and NCSC Cloud Security Principles.
  • Background of consulting and engineering the design and development of security best practices, implementation of security measures, policies and processes to meet business goals, customer needs and regulatory requirements.
  • Ability to use logic and reasoning to identify the strengths and weaknesses of IT systems, while seeking out vulnerabilities in IT infrastructures.
  • Assist in risk assessment procedures, policy formation, role‑based authorisation methodologies, authentication technologies and security attack pathologies.
  • Growth mentality with excellent problem‑solving skills, willing to assist in all areas of Cyber and to learn new technologies & processes.
  • A self‑motivated individual with a “can do” attitude, who can work on their own initiative as well as part of a team.
  • An excellent communicator who can help develop good Cyber practices with an ability to interact with all levels within the company.
  • Strong leadership, stakeholder management, and project/team‑building skills, including the ability to lead teams and drive initiatives in multiple departments.

Benefits

  • Generous Annual Leave Policy: 5 weeks of annual leave available at the start of each year, plus a 5‑Year Recharge benefit granting an extra 2 weeks of paid leave after 5 years of continuous service.
  • Flexible Working: Hybrid working policy and additional flexibility around taking unpaid leave.
  • Corporate Responsibility Days: 3 days per year to help social and environmental causes.
  • Wellbeing Fund: Annual People Fund to support employees’ wellbeing through an activity of their choice.
  • Profit Share Scheme: Participation in the Baringa Group Profit Share Scheme.

Diversity and Inclusion

We are proud to be an Equal Opportunity Employer. We believe that creating an environment where everyone feels a sense of belonging is central to our culture and that diversity is paramount to driving creativity, innovation, and value for our clients and our people.

Equal Employment Opportunity Statement

All applications received will be reviewed by a member of our Talent Acquisition team. We never rely solely on automated screening or AI tools to make hiring decisions. Your application will be considered for employment without regard to race, ethnicity, religion, gender, gender identity or expression, sexual orientation, nationality, disability, age, faith or social background. We do not filter applications by university background and encourage those who have taken alternative educational and career paths to apply. We encourage applications from those who identify with less represented and minority groups. We operate an inclusive recruitment process, ensuring reasonable adjustments where needed.

Cyber Security Analyst - Governance, Risk and Culture (GRC) employer: Baringa

Baringa is an exceptional employer that prioritises employee development and a supportive work culture, particularly for the Cyber Security Analyst role within our Governance, Risk and Culture team. With generous benefits such as a flexible working policy, extensive annual leave, and a commitment to diversity and inclusion, we foster an environment where every team member can thrive and make a meaningful impact on our security posture and organisational culture.

B

Contact Details:

Baringa Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Security Analyst - Governance, Risk and Culture (GRC)

Tip Number 1

Network like a pro! Reach out to current employees at Baringa or in the Cyber Security field on LinkedIn. Ask them about their experiences and any tips they might have for landing a role in GRC. Personal connections can make all the difference!

Tip Number 2

Prepare for interviews by brushing up on your knowledge of compliance requirements and security standards like ISO27001 and NIST. Be ready to discuss how you've tackled cyber risks in the past and how you can contribute to fostering a cyber-conscious culture.

Tip Number 3

Showcase your problem-solving skills! During interviews, share specific examples of how you've identified vulnerabilities and implemented security measures. This will demonstrate your hands-on experience and growth mentality, which are key for this role.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining the team at Baringa.

We think you need these skills to ace Cyber Security Analyst - Governance, Risk and Culture (GRC)

Cyber Security Governance
Risk Management
Compliance with Cloud Technologies
Supplier Security Due Diligence
Incident Response
Technical Control Implementation
Security Policy Development

Some tips for your application 🫡

Know the Role:Before you start writing, make sure you fully understand what a Cyber Security Analyst in Governance, Risk and Culture does. Dive into the job description and highlight key responsibilities and skills that resonate with your experience.

Tailor Your Application:Don’t just send a generic CV and cover letter! We want to see how your unique skills and experiences align with our needs. Use specific examples from your past roles that demonstrate your expertise in cyber security and risk management.

Show Your Passion:Let us know why you’re excited about this role and working with us at StudySmarter. Share your enthusiasm for cyber security and how you can contribute to fostering a cyber-conscious culture within our team.

Apply Through Our Website:Make sure to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re serious about joining our team!

How to prepare for a job interview at Baringa

Know Your Stuff

Before the interview, dive deep into Baringa's technology and information systems. Familiarise yourself with their security policies, standards, and the specific compliance requirements for cloud technologies like Microsoft and AWS. This knowledge will help you demonstrate your understanding of the role and how you can contribute.

Showcase Your Experience

Be ready to discuss your previous experience in Cyber Security GRC roles. Prepare examples of how you've handled audits, supplier due diligence, or risk assessments. Highlight any hands-on experience with technical controls and incident response, as this will show your practical skills and readiness for the job.

Communicate Clearly

As an excellent communicator, you’ll need to convey complex ideas simply. Practice explaining security concepts and strategies in layman's terms. This will not only showcase your expertise but also your ability to interact with various stakeholders across the organisation.

Emphasise Your Growth Mindset

Baringa values a growth mentality, so be prepared to discuss how you approach learning new technologies and processes. Share examples of challenges you've faced and how you've overcome them, demonstrating your problem-solving skills and willingness to adapt in a dynamic environment.