Senior Governance, Risk and Compliance Analyst
Senior Governance, Risk and Compliance Analyst

Senior Governance, Risk and Compliance Analyst

Full-Time 50000 - 60000 ÂŁ / year (est.) Home office (partial)
City IT

At a Glance

  • Tasks: Join a dynamic team to enhance security frameworks and achieve key certifications.
  • Company: CEF, a leading electrical wholesale business with a collaborative culture.
  • Benefits: Remote work, annual bonus, 25 days holiday, and wellness resources.
  • Other info: Flexible working with opportunities for professional development and team collaboration.
  • Why this job: Make a real impact in a fast-evolving tech environment while growing your skills.
  • Qualifications: Experience in information security and ISO27001 certification is essential.

The predicted salary is between 50000 - 60000 ÂŁ per year.

About the role: You’ll be joining a close-knit, highly capable security team who genuinely enjoy working together and take pride in what they deliver. It’s a collaborative environment where ideas are shared openly, support is always there when you need it, and everyone is trusted to get on with their work without unnecessary layers or noise. There’s a strong sense of accountability, but also a lot of flexibility and understanding — people here back each other and celebrate progress together. From a technical perspective, you’ll help evolve our governance framework, strengthen existing controls and play a key role in achieving and maintaining certifications such as ISO27001. We’re looking for someone who has been through that journey before and can bring a pragmatic, delivery-focused approach. You’ll need to be comfortable operating in a business that’s evolving quickly, able to balance structure with flexibility, and confident working with stakeholders at all levels. Just as importantly, you’ll be someone who listens, builds trust easily and brings a calm, thoughtful approach to problem-solving.

Responsibilities:

  • Working closely with the Governance and Compliance Manager (located in South Yorkshire, UK)
  • Working closely with the Head of Information Security (located in North Yorkshire, UK)
  • Leading the implementation and the changes required to help CEF to gain ISO27001 and additional certifications (such as ISO42001) as deemed necessary by the business
  • Support CEF maintain security certifications (Cyber Essentials, PCI) and support activities to enhance security controls
  • Auditing and reviewing security controls, policies and procedures to ensure alignment with current ways of working and best practice
  • Undertaking security control gap analysis and proposing strategies to remediate or reduce any observed risks
  • Supporting other Governance, Risk and Compliance team members in completing 3rd party supplier activities such as security due diligence reviews and client information security questionnaires
  • Working with the Governance and Compliance Manager to foster a culture of continuous security training and upskilling for all CEF team members
  • Supporting security governance measures and policies for AWS cloud security
  • Working with the Governance and Compliance manager to identify, assess and prioritise potential information and data governance risks and issues across the business (including products, solutions, systems, data, people and processes), and through effective partnering relationships with business leaders, ensure that effective actions and controls are in place to mitigate those risks

Essential Experience:

  • Previous experience in an operational information security role, engaging and communicating successfully with senior stakeholders across different business areas to address and ensure information security compliance.
  • Previous experience gaining or maintaining ISO27001 certification
  • Proven experience of defining the information security policies, controls and processes to manage an organisations’ risk position
  • Proven experience of utilising Information Security principles and best practices such as ISO 27001, NIST, NCSC, PCI DSS requirements and other regulatory obligations.
  • Experience in risk and vulnerability management

What We Offer:

  • Work from anywhere in the UK – we aim to come together multiple times a year in our office in Durham so you must be willing to travel when required.
  • Annual discretionary bonus
  • 25 days holiday plus UK bank holidays.
  • Company pension scheme.
  • Access to Champion Health – the “Netflix of wellbeing”, covering physical, mental and financial wellbeing.
  • Access to MySavings Platform, offering discounts and vouchers across groceries, dining out, gym memberships, days out, experiences and travel.
  • Access to Light Up Learning, our platform for leadership, technical and personal development.
  • Free use of our onsite gym at Janet Nash House, Durham.

About Us: Founded in 1951 in Kenilworth, UK, City Electrical Factors (CEF) has grown into a world-leading electrical wholesale and manufacturing business with over 400 branches across the UK and a strong presence in the USA, Canada, Spain and Australia. Our IT and digital teams are driving the next chapter of our journey... Re-engineering legacy systems, adopting modern cloud technologies and exploring AI to deliver faster, smarter and more connected customer experiences. We’re a predominantly remote workforce with teams distributed across the UK, USA, Canada, Spain and Australia. Our culture is collaborative, forward-thinking and people-focused — where your ideas and contributions genuinely matter.

Our Mission: City is a world leading electrical wholesale and manufacturing business providing electrical products to the industry. We in IT are delivering value to our business and our customers with the implementation of packaged software and bespoke engineering for the digital age using AWS serverless technology. We need talented and creative people across all areas to join us in rearchitecting our forward thinking business over the next few years and beyond as we evolve.

Ready to Apply? If you’re excited by technology, value collaboration and want to make a genuine impact, we’d love to hear from you. Click Apply to get started!

Senior Governance, Risk and Compliance Analyst employer: City IT

At City Electrical Factors (CEF), we pride ourselves on fostering a collaborative and supportive work culture that empowers our employees to thrive. With flexible working arrangements, comprehensive benefits including a company pension scheme, and access to personal development platforms, we are committed to your growth and well-being. Join us in our Durham office or work remotely from anywhere in the UK, and be part of a forward-thinking team that values your contributions and celebrates collective success.
City IT

Contact Detail:

City IT Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Governance, Risk and Compliance Analyst

✨Tip Number 1

Network like a pro! Reach out to current employees on LinkedIn or other platforms. Ask them about their experiences and the company culture. This not only gives you insider info but also shows your genuine interest in the role.

✨Tip Number 2

Prepare for the interview by researching common questions related to governance, risk, and compliance. Think of examples from your past experience that showcase your skills in these areas. We want to see how you’ve tackled challenges before!

✨Tip Number 3

Showcase your soft skills! In a collaborative environment like ours, being able to communicate effectively and build trust is key. Be ready to discuss how you've worked with stakeholders and resolved conflicts in the past.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining our team and contributing to our mission.

We think you need these skills to ace Senior Governance, Risk and Compliance Analyst

ISO 27001
ISO 42001
Cyber Essentials
PCI DSS
Risk Management
Vulnerability Management
Information Security Policies
Stakeholder Engagement
Auditing Skills
Gap Analysis
Security Controls Implementation
Continuous Security Training
Cloud Security (AWS)
Problem-Solving Skills
Communication Skills

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with ISO27001 and other relevant certifications. We want to see how your background aligns with our needs, so don’t hold back on showcasing your skills!

Showcase Your Collaboration Skills: Since we value teamwork, share examples of how you've successfully worked with stakeholders at different levels. Let us know how you’ve built trust and fostered collaboration in your previous roles.

Be Clear and Concise: When writing your application, keep it straightforward and to the point. We appreciate clarity, so avoid jargon and make sure your key achievements stand out. This helps us quickly see what you bring to the table!

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it’s super easy to do!

How to prepare for a job interview at City IT

✨Know Your Stuff

Make sure you brush up on ISO27001 and other relevant certifications. Be ready to discuss your previous experiences in gaining or maintaining these certifications, as well as how you've implemented security controls in past roles.

✨Show Your Collaborative Spirit

Since the role emphasises teamwork, think of examples where you've successfully worked with others, especially senior stakeholders. Highlight how you’ve built trust and fostered a supportive environment in your previous positions.

✨Be Pragmatic and Flexible

Prepare to discuss how you balance structure with flexibility in a fast-paced environment. Share specific instances where you adapted your approach to meet evolving business needs while still ensuring compliance and security.

✨Problem-Solving Mindset

Demonstrate your calm and thoughtful approach to problem-solving. Think of challenges you've faced in governance, risk, and compliance, and be ready to explain how you identified issues and proposed effective solutions.

Senior Governance, Risk and Compliance Analyst
City IT

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>