Lead Information Security Analyst, GRC in Edinburgh
Lead Information Security Analyst, GRC

Lead Information Security Analyst, GRC in Edinburgh

Edinburgh Full-Time 60000 - 80000 ÂŁ / year (est.) No home office possible
Cirrus Logic

At a Glance

  • Tasks: Lead and enhance our information security governance, risk management, and compliance programme.
  • Company: Join Cirrus Logic, a leader in mixed-signal processing with an award-winning culture.
  • Benefits: Enjoy a hybrid work model, competitive salary, and opportunities for professional growth.
  • Other info: Be part of a collaborative environment that values diversity and innovation.
  • Why this job: Make a real impact on security while working with cutting-edge technologies and diverse teams.
  • Qualifications: Experience in information security, GRC, and strong analytical skills required.

The predicted salary is between 60000 - 80000 ÂŁ per year.

For over four decades, Cirrus Logic has been propelled by top engineers in mixed‑signal processing. Our team thrives on solving complex challenges with innovative end‑user solutions for the world's top consumer brands. Cirrus Logic is known for its award‑winning culture, built on inclusion and fairness, meaningful community engagement, and enjoyable employee experiences. We invite you to join us and help make Cirrus Logic an exceptional place to grow your career.

We are seeking a highly motivated, experienced professional to join the Cirrus Logic Information Security team as a Lead Information Security Analyst – Governance, Risk Management & Compliance (GRC). You will be responsible for designing, operating, and continuously improving our ISO 27001‑aligned governance, risk, and compliance program, with a focus on integrated risk management, third‑party risk management, and security control effectiveness. You will also help define, refine, and operationalise the responsible use of AI technologies and services across the enterprise.

Key Responsibilities

  • Lead day‑to‑day operation and continuous improvement of our ISO 27001‑aligned ISMS, including policies, standards, and control procedures.
  • Develop, maintain, and socialise information security policies, standards, and guidelines; manage exceptions and ensure decisions are risk‑based, documented, and periodically reviewed.
  • Lead security risk and control assessments for new systems, services, and business initiatives, partnering with security, IT, and business owners to identify threats, evaluate design and operating effectiveness of controls, and document and track risk treatment plans. This includes evaluating AI/ML use cases for security, data protection, and misuse risks.
  • Plan and execute third‑party risk assessments for suppliers and service providers, including review of third‑party security questionnaires, trust documents, and remediation plans to ensure third‑party security meets Cirrus Logic’s requirements.
  • Analyze risks across technologies and business processes, prioritise remediation efforts based on business impact and likelihood, and prepare clear risk and control status reports for security leadership and key stakeholders.
  • Configure, administer, and optimise GRC tooling such as ServiceNow GRC or OneTrust GRC to support risk registers, control libraries, assessments, exceptions, and third‑party workflows, including integration with IT and security platforms where appropriate.
  • Coordinate and provide evidence for internal and external audits, customer security assessments, and certifications such as ISO 27001 and SOC‑related reviews.
  • Partner with Legal, HR, and other stakeholders to identify and manage security‑related privacy and regulatory obligations; support privacy risk assessments and data protection controls, and assess privacy implications of AI/ML solutions.
  • Define and maintain security and risk guardrails for the use of AI/ML technologies, including acceptable‑use guidelines, control requirements, and review processes for new AI use cases and vendors.
  • Act as a trusted advisor to team members, IT, and business teams, translating security and risk requirements into practical, implementable solutions that align with engineering and operational realities. Partner closely with IT, engineering, and business teams to embed security, risk, and governance requirements into AI solution design and operation. Work effectively with a globally dispersed team across various time zones.
  • Maintain strong executive presence, outstanding written, verbal, and presentation skills. Communicate complex risk, control, compliance, and program matters clearly to technical teams, business stakeholders, and executive leadership. Develop high‑quality executive‑ready content and support GRC awareness, communications, and training initiatives.

Required Skills and Qualifications

  • Proven experience in Information Security with a strong focus on GRC, risk management, and/or security compliance in a global environment.
  • Bachelor’s degree in cybersecurity, information systems, or a related field, or demonstrated equivalent experience as a security professional in a globally dispersed enterprise.
  • Hands‑on experience with ISO/IEC 27001 (ISMS lifecycle, Annex A controls, risk assessment and treatment) and related security control frameworks such as NIST CSF, ISO 27000, TISAX.
  • Demonstrated experience with Integrated Risk Management (project/solution risk assessments) and Third‑Party Risk Management (vendor due diligence, ongoing monitoring, remediation).
  • Technical fluency across core IT and security domains such as network, endpoint, identity, cloud/SaaS, logging/monitoring, and experience working with Security Engineering, Security Operations, and IT teams.
  • Experience configuring and maintaining an enterprise‑grade GRC platform, preferably ServiceNow GRC, for risk, control, assessment, and exception workflows.
  • Strong analytical and problem‑solving skills, balancing security, compliance, and business objectives in a practical way.
  • Effective communication and interpersonal skills, conveying risk and technical issues to both technical and non‑technical stakeholders, including senior leaders.
  • Proven ability to drive work independently, manage multiple concurrent initiatives, and follow through to completion in a fast‑paced environment.
  • Experience working in high‑tech, engineering, or semiconductor environments is beneficial.
  • Relevant certifications such as ISO 27001 Lead Implementer/Lead Auditor, CISSP, CISM, CISA, CRISC are preferred but not required.

Location and Work Arrangement

Position is based in the Edinburgh office. The role is hybrid, requiring a minimum of two days onsite with flexibility to work from home, depending on business needs. Candidates must live within a commutable distance or be willing to relocate.

Export control restrictions based on applicable laws prohibit candidates who are nationals of certain embargoed countries from working in this position without Cirrus Logic first obtaining an export license. Candidates for this role must be able to access technical data without a requirement for an export license. Cirrus Logic is unable to sponsor or obtain export licenses for this position.

Commitment to Diversity

Cirrus Logic believes that diversity drives innovation and is committed to an open, collaborative culture where everyone can contribute regardless of race, colour, national origin, religion or belief, gender or gender identity, sexual orientation, age, marital status, pregnancy status, or disability.

Lead Information Security Analyst, GRC in Edinburgh employer: Cirrus Logic

Cirrus Logic is an exceptional employer that fosters a culture of inclusion and fairness, providing employees with meaningful community engagement and enjoyable experiences. With a strong commitment to professional growth, the company offers opportunities for career advancement in a dynamic environment, particularly for those in the Lead Information Security Analyst role. Located in Edinburgh, the hybrid work model allows for flexibility while being part of a globally dispersed team, making it an attractive place for talented individuals seeking to make a significant impact in the field of information security.
Cirrus Logic

Contact Detail:

Cirrus Logic Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Lead Information Security Analyst, GRC in Edinburgh

✨Tip Number 1

Network like a pro! Reach out to current employees at Cirrus Logic on LinkedIn or through mutual connections. Ask them about their experiences and any tips they might have for landing the Lead Information Security Analyst role.

✨Tip Number 2

Prepare for the interview by brushing up on ISO 27001 and GRC concepts. We recommend creating a cheat sheet of key points and examples from your past experience that align with the job description. This will help you articulate your expertise clearly.

✨Tip Number 3

Showcase your problem-solving skills during interviews. Be ready to discuss specific challenges you've faced in information security and how you tackled them. This will demonstrate your analytical abilities and fit for the role.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows your genuine interest in joining Cirrus Logic and being part of our amazing culture.

We think you need these skills to ace Lead Information Security Analyst, GRC in Edinburgh

Information Security
Governance, Risk Management & Compliance (GRC)
ISO 27001
Risk Assessment
Third-Party Risk Management
Integrated Risk Management
Security Control Frameworks (NIST CSF, ISO 27000, TISAX)
GRC Tooling (ServiceNow GRC, OneTrust GRC)
Analytical Skills
Problem-Solving Skills
Communication Skills
Interpersonal Skills
Technical Fluency in IT and Security Domains
Project Management
Executive Presence

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Lead Information Security Analyst role. Highlight your experience with GRC, risk management, and compliance, and don’t forget to mention any relevant certifications you have!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your skills align with Cirrus Logic's mission. Keep it concise but impactful.

Showcase Your Communication Skills: Since this role requires strong communication skills, make sure your application reflects that. Use clear language and structure your documents well to demonstrate your ability to convey complex ideas simply.

Apply Through Our Website: We encourage you to apply through our website for the best chance of being noticed. It’s super easy, and you’ll be able to track your application status directly!

How to prepare for a job interview at Cirrus Logic

✨Know Your GRC Inside Out

Make sure you’re well-versed in Governance, Risk Management, and Compliance principles, especially ISO 27001. Brush up on the key controls and how they apply to real-world scenarios, as you might be asked to discuss your experience with these frameworks during the interview.

✨Showcase Your Analytical Skills

Prepare to demonstrate your analytical and problem-solving abilities. Think of specific examples where you've balanced security needs with business objectives, particularly in risk assessments or third-party evaluations. This will show that you can think critically about complex issues.

✨Communicate Clearly and Confidently

Practice explaining technical concepts in simple terms. You’ll need to convey complex risk and compliance matters to both technical and non-technical stakeholders, so being able to articulate your thoughts clearly is crucial. Consider doing mock interviews to refine this skill.

✨Familiarise Yourself with GRC Tools

If you have experience with GRC platforms like ServiceNow or OneTrust, be ready to discuss it. If not, do some research on how these tools function and their importance in managing risk and compliance. Showing familiarity with these systems can set you apart from other candidates.

Lead Information Security Analyst, GRC in Edinburgh
Cirrus Logic
Location: Edinburgh

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>