At a Glance
- Tasks: Lead and enhance our Information Security Management System while managing risks and compliance.
- Company: Join Cirrus Logic, a leader in mixed-signal processing with an award-winning culture.
- Benefits: Enjoy a hybrid work model, competitive salary, and opportunities for professional growth.
- Other info: Collaborative team culture that values diversity and innovation.
- Why this job: Make a real impact on security and risk management in a dynamic tech environment.
- Qualifications: Experience in information security, GRC, and strong analytical skills required.
The predicted salary is between 60750 - 74250 £ per year.
Edinburgh, Scotland
Global Operations – IT /Full Time /Hybrid
For over four decades, Cirrus Logic has been propelled by the top engineers in mixed-signal processing. Our rockstar team thrives on solving complex challenges with innovative end-user solutions for the world's top consumer brands. Cirrus Logic is also known for its award-winning culture, built on a foundation of inclusion and fairness, meaningful community engagement, and delivering enjoyable employee experiences at every turn.
We are seeking a highly motivated, experienced professional to join the Cirrus Logic Information Security team as a Lead Information Security Analyst - Governance, Risk Management, & Compliance (GRC). You will be responsible for designing, operating, and continually improving our ISO 27001–aligned governance, risk, and compliance program, with a strong focus on Integrated Risk Management, Third Party Risk Management, and security control effectiveness. You will also help define, refine, and operationalise the responsible use of AI technologies and services (including GenAI and Agentic AI) across the enterprise from a security and risk perspective. This role is highly collaborative and supports business strategy in a dynamic, engineering driven environment.
Key Responsibilities:
- GRC Program & ISO 27001: Lead day‑to‑day operation and continuous improvement of our ISO 27001–aligned Information Security Management System (ISMS), including policies, standards, and control procedures across the organization.
- Policy, Standards, and Exception Management: Develop, maintain, and socialise information security policies, standards, and guidelines; manage exceptions, ensuring decisions are risk‑based, documented, and periodically reviewed.
- Integrated Risk Management: Lead security risk and control assessments for new systems, services, and business initiatives, partnering with Security, IT, and business owners to identify threats, evaluate the design and operating effectiveness of controls, and document and track risk treatment plans.
- Third‑Party Risk Management: Plan and execute third‑party risk assessments for suppliers and service providers, including review of third-party security questionnaires, trust documents, and remediation plans to ensure third-party security meets Cirrus Logic’s requirements.
- Risk Analysis & Reporting: Analyze risks across technologies and business processes, prioritize remediation efforts based on business impact and likelihood, and prepare clear risk and control status reports for security leadership and key stakeholders.
- GRC Tooling & Automation: Configure, administer, and optimize GRC tooling, such as ServiceNow GRC or OneTrust GRC, to support risk registers, control libraries, assessments, exceptions, and third-party workflows.
- Audit & Assessment Support: Coordinate and provide evidence for internal and external audits, customer security assessments, and certifications (e.g., ISO 27001, SOC‑related reviews).
- Privacy & Regulatory Support: Partner with Legal, HR, and other stakeholders to identify and manage security‑related privacy and regulatory obligations; support privacy risk assessments and data protection controls as needed.
- AI Risk & Governance: Define and maintain security and risk guardrails for the use of AI/ML technologies, including acceptable-use guidelines, control requirements, and review processes for new AI use cases and vendors.
- Collaboration & Enablement: Act as a trusted advisor to the team members, IT, and business teams, helping translate security and risk requirements into practical, implementable solutions.
- Communication, Executive Presence & Awareness: Strong executive presence with outstanding written, verbal, and presentation skills.
Required Skills and Qualifications:
- Proven experience in Information Security with a strong focus on GRC, risk management, and/or security compliance in a global environment.
- Bachelor’s degree in cybersecurity, information systems, or a related field, or demonstrated equivalent experience as a security professional.
- Hands‑on experience with ISO/IEC 27001 and related security control frameworks.
- Demonstrated experience with Integration Risk Management and Third‑Party Risk Management.
- Technical fluency across core IT and security domains.
- Experience configuring and maintaining an enterprise-grade GRC platform.
- Strong analytical and problem‑solving skills.
- Effective communication and interpersonal skills.
- Proven ability to drive work independently and manage multiple concurrent initiatives.
- Experience working in high‑tech, engineering, or semiconductor environments is beneficial.
- Relevant certifications are preferred but not required.
This position is based in our Edinburgh office. It is a hybrid role (minimum 2+ days onsite) with the flexibility to work from home, depending on business needs. Candidates must live within a commutable distance or be willing to relocate.
At Cirrus Logic, we believe that diversity drives innovation, and we are committed to encouraging an open and collaborative culture where different approaches, ideas, and points of view are respected and valued.
Locations
Lead Information Security Analyst, GRC in Midlothian, Scotland employer: Cirrus Logic
Cirrus Logic is an exceptional employer located in the vibrant city of Edinburgh, offering a dynamic hybrid working environment that fosters collaboration and innovation. With a strong commitment to diversity, employees benefit from a culture that encourages personal and professional growth, alongside opportunities to enhance their skills in embedded systems and automation. Join us to be part of a forward-thinking team where your contributions truly matter.
StudySmarter Expert Advice🤫
We think this is how you could land Lead Information Security Analyst, GRC in Midlothian, Scotland
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Cirrus Logic, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Cirrus Logic
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Cirrus Logic. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Lead Information Security Analyst, GRC in Midlothian, Scotland
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Cirrus Logic insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Cirrus Logic that you’re committed to staying ahead in the game.
How to prepare for a job interview at Cirrus Logic
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Cirrus Logic to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Cirrus Logic.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.