Technical GRC Analyst

Technical GRC Analyst

Full-Time 40000 - 50000 £ / year (est.) No working from home possible
Bromcom Computers

At a Glance

  • Tasks: Support governance, risk, compliance, and security assurance in a dynamic EdTech SaaS environment.
  • Company: Join Bromcom, a forward-thinking EdTech company committed to innovation and inclusivity.
  • Benefits: Enjoy competitive pay, flexible working options, and opportunities for professional growth.
  • Other info: Collaborative culture with excellent career advancement opportunities in a growing sector.
  • Why this job: Make a real impact on data protection and compliance while working with cutting-edge technology.
  • Qualifications: Experience in IT risk or compliance roles, understanding of GDPR, and strong organisational skills.

The predicted salary is between 40000 - 50000 £ per year.

We are seeking a Technical GRC Analyst to support the day-to-day operation of our governance, risk, compliance, and security assurance processes within a growing EdTech SaaS environment. This role will focus on administering established policies and workflows, coordinating compliance and security activities, handling requests from across the business, and performing risk assessments—particularly where personal data, information security, and GDPR considerations are involved. You will play a key role in ensuring that our systems, processes, security tooling, and third-party relationships meet our security, compliance, and data protection standards. Working closely with the IT & Information Security Manager and wider IT team, you will help maintain audit readiness, support operational security assurance activities, and coordinate remediation and evidence management across the organisation. The role offers exposure across governance, operational security assurance, compliance, and risk management within a growing SaaS environment.

Key Responsibilities

  • Administer and operate IT risk, compliance, and security assurance processes aligned to internal policies and regulatory requirements (including GDPR).
  • Act as a central point of contact for compliance-related requests (e.g. Subject Access Requests (SARs), data sharing requests, access requests, exceptions, and supplier onboarding).
  • Perform risk assessments using defined criteria, with a focus on data protection and information security risks.
  • Review requests against defined policies and controls, escalating where appropriate in line with internal governance processes.
  • Support third-party / supplier risk assessments, including reviewing security and data protection documentation and tracking follow-up actions.
  • Support periodic reviews of high-risk and business-critical suppliers, applications, and technology platforms to ensure appropriate security, compliance, and data protection controls remain in place.
  • Support the implementation and ongoing operation of compliance and assurance tooling (Vanta), including evidence collection, test management, stakeholder coordination, remediation tracking, and control adoption activities.
  • Ensure appropriate documentation, audit trails, and evidence are maintained for assessments, compliance activities, and operational processes.
  • Support internal and external audits (e.g. ISO 27001), including evidence gathering, action tracking, and coordination of remediation activities.
  • Monitor compliance with policies and highlight potential risks, gaps, or control weaknesses for review.
  • Support coordination and operational delivery of security improvement initiatives across IT and business teams.
  • Support incident management processes through documentation, tracking, and coordination of follow-up actions.
  • Coordinate security awareness activities, including phishing simulation campaigns and training tracking.
  • Assist with reviews of security tooling configurations and collection of supporting control evidence.
  • Work closely with engineering, product, and business teams to ensure compliance and security processes are understood and followed.
  • Contribute ideas and feedback to improve workflows and operational processes, particularly where they impact scalability, operational efficiency, or customer trust.

Skills & Experience

Essential:

  • Experience in IT risk, compliance, or GRC roles within a SaaS or technology environment.
  • Understanding of GDPR and handling of personal data (especially sensitive or child/student data).
  • Experience performing risk assessments using structured frameworks and defined processes.
  • Ability to interpret policies and apply them to operational and real-world scenarios.
  • Strong organisational, coordination, and documentation skills (audit trails, evidence, decision logs).
  • Experience working with cross-functional teams (e.g. engineering, product, operations).
  • Experience supporting operational security assurance activities, such as evidence collection, control validation, remediation tracking, or audit preparation.

Desirable:

  • Familiarity with ISO 27001, Cyber Essentials, or similar frameworks.
  • Experience supporting audits, evidence collection, or remediation tracking activities.
  • Experience with vendor / third-party risk management.
  • Exposure to data protection processes (e.g. SARs, DPIAs, data sharing assessments).
  • Exposure to data classification, data governance, or data loss prevention (DLP) processes.
  • Experience with GRC, compliance, or assurance platforms (e.g. Vanta, Drata) and ticketing/workflow management tools.
  • Exposure to Microsoft 365 security and compliance tooling (e.g. Entra ID, Intune, Secure Score, Defender).
  • Basic understanding of cloud/SaaS architecture and common security controls.

Key Behaviours:

  • Pragmatic approach to risk, with the ability to balance compliance requirements with business needs.
  • Comfortable assessing requests against defined policies and escalating concerns where appropriate.
  • Confident communicating risks, issues, and follow-up actions to stakeholders.
  • Detail-oriented, with a strong focus on documentation, evidence quality, and traceability.
  • Organised and proactive, with the ability to manage multiple tasks and follow through on actions.
  • Able to operate independently within established processes and governance frameworks.
  • Collaborative approach to working with technical and non-technical teams.

Bromcom is an equal opportunities employer.

Technical GRC Analyst employer: Bromcom Computers

Bromcom is an exceptional employer, offering a dynamic work environment within the EdTech SaaS sector that fosters innovation and collaboration. Employees benefit from a strong focus on professional development, with opportunities to engage in meaningful projects that enhance governance, risk, and compliance processes. The company promotes a culture of inclusivity and support, ensuring that every team member can thrive while contributing to the mission of delivering secure and compliant educational technology solutions.

Bromcom Computers

Contact Details:

Bromcom Computers Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Technical GRC Analyst

Tip Number 1

Network like a pro! Reach out to folks in the EdTech and SaaS space on LinkedIn. Join relevant groups, attend webinars, and don’t be shy about asking for informational interviews. You never know who might have the inside scoop on job openings!

Tip Number 2

Prepare for those interviews by brushing up on your knowledge of GDPR and risk assessment frameworks. We want you to feel confident discussing how you can help maintain compliance and security in our environment. Practice common interview questions and think of examples from your past experience that showcase your skills.

Tip Number 3

Show us your passion for governance, risk, and compliance! When you get the chance to chat with us, share your thoughts on current trends in data protection and compliance. This will not only demonstrate your expertise but also your enthusiasm for the role.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at StudySmarter. Let’s make it happen!

We think you need these skills to ace Technical GRC Analyst

IT Risk Management
Governance, Risk, Compliance (GRC)
GDPR Knowledge
Risk Assessment
Policy Interpretation
Organisational Skills
Documentation Skills

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Technical GRC Analyst role. Highlight your experience in IT risk, compliance, and any relevant SaaS environments. We want to see how your skills align with our needs!

Showcase Your Skills:In your cover letter, don’t just list your skills—show us how you've used them! Talk about specific projects or experiences where you’ve performed risk assessments or handled compliance requests. We love a good story!

Be Clear and Concise:When writing your application, keep it clear and to the point. Use bullet points for key achievements and make sure your language is straightforward. We appreciate clarity as much as you do!

Apply Through Our Website:Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it’s super easy—just a few clicks and you’re done!

How to prepare for a job interview at Bromcom Computers

Know Your GRC Basics

Make sure you brush up on your knowledge of governance, risk, and compliance (GRC) principles, especially in a SaaS context. Be ready to discuss GDPR and how it impacts data handling, as well as any relevant frameworks like ISO 27001. This will show that you understand the core responsibilities of the role.

Prepare for Scenario Questions

Expect to be asked about real-world scenarios where you had to perform risk assessments or handle compliance requests. Think of specific examples from your past experience that highlight your problem-solving skills and ability to work with cross-functional teams. Use the STAR method (Situation, Task, Action, Result) to structure your answers.

Showcase Your Organisational Skills

Since this role requires strong organisational and documentation skills, be prepared to discuss how you manage multiple tasks and maintain audit trails. Bring examples of how you've tracked evidence or coordinated activities in previous roles, as this will demonstrate your attention to detail and proactive approach.

Ask Insightful Questions

At the end of the interview, don’t forget to ask questions that show your interest in the company and the role. Inquire about their current compliance challenges or how they measure success in their GRC processes. This not only shows your enthusiasm but also helps you gauge if the company is the right fit for you.