At a Glance
- Tasks: Manage information security systems and ensure compliance with industry standards.
- Company: Join a dynamic scale-up focused on security for public sector and law enforcement.
- Benefits: Flexible working, competitive salary, and opportunities for professional growth.
- Other info: Diverse and inclusive workplace where your unique perspective is valued.
- Why this job: Make a real impact in security while working with cutting-edge technology.
- Qualifications: Experience in information security management and ISO 27001 is a plus.
The predicted salary is between 48661 - 59475 £ per year.
- Key stakeholders: Platform and Development, Product, Sales and Onboarding, IT Operations, Legal Counsel and DPO, People team, our managed security operations provider, customer security and assurance teams
- Organisational Framework Level: Level 3 – Professional Specialist
- Eligible to obtain UK security clearance (SC). UK-based.
- Minimum requirement of 2 days per week in our Bristol office
About you/ Job Summary
As a Security Governance, Risk and Compliance Analyst, you keep our information security management system current, evidenced and moving.
Clue supplies software to UK public sector, Sports and law enforcement, and those customers expect us to show, not just say, that our controls work.
You will administer our ISO 27001 ISMS day to day, maintain the risk register, lead customer security assurance, run the supplier assessment cycle and coordinate the record-keeping and communications when an incident occurs.
The CISO leads the security function, sets direction, and holds accountability; the Security Engineering team and IT own the technical controls.
Your job is to do the work between them intelligently: know where every piece of evidence lives, what we have promised each customer, what is due next, and who needs chasing.
At Clue we are actively adopting AI to improve our products and workflows.
You will bring curiosity and a willingness to use AI tools to work faster and more accurately, while knowing where they should not be trusted.
- Key Accountabilities
- ISMS and certification
- Administer the information security policy, set: review schedule, publication and acknowledgement records, with the CISO approving changes.
- Maintain ISO 27001:2022 certification: statement of applicability, evidence library, internal audit scheduling and external audit coordination.
- Work with IT to maintain security accreditations such as Cyber Essentials Plus and our ISO accreditations, plus the evidence set for the NCSC Cyber Assessment Framework where customers require it.
- Maintain the security exceptions register, tracking time-limited approvals and named risk sponsors.
- Pen-test and crisis simulation exercise management and coordination, alongside the CISO.
- Maintain the risk register and apply the scoring model set by the CISO. Keep entries current, sponsored and treated.
- Prepare and coordinate the monthly risk register review with executive risk sponsors, and track treatment plans to closure.
- Draft register entries from audit findings, incident lessons, threat assessments and customer requirements, for CISO review, each with a proposed owner.
- Maintain the list of security-related product roadmap requests and coordinate prioritisation between the CISO and Product.
- Customer assurance and contractual compliance
- Lead customer security assurance: draft questionnaire responses, assemble evidence packs and handle due diligence requests, drawing technical input from the Dev Sec Ops Engineer and IT Operations.
- Maintain the single record of every security commitment made to a customer.
- Carry out compliance checks of customer environments before go-live and report the results to the CISO for sign-off.
- Track our obligations under CCS framework security schedules and G-Cloud 15 Call-Off Schedule 9A, and maintain the evidence for each.
- Produce customer-facing assurance reporting, including the monthly vulnerability report within five working days of month-end.
- Security operations governance
- Coordinate the day-to-day relationship with our managed security operations provider: track service levels, prepare monthly service reviews and maintain the detection improvement backlog.
- Track vulnerability remediation against contractual windows, record exceptions and report performance.
- Maintain the protective monitoring standard and the logging and monitoring evidence an assurance review will test.
- Keep a record of threat intelligence intake from NCSC and other sources, and of the actions taken.
- Act as incident coordinator: convene the response channel, keep the record, apply the severity matrix and escalation path without discretion, and track actions to closure.
The CISO chairs incidents and coordinates Clue response.
- Prepare and track customer and regulatory notifications, including any contractual out of hours customer notification and the UK GDPR 72-hour ICO window, with Legal and the DPO.
- Maintain the incident register, organise post-incident reviews and track corrective actions.
- Maintain the annualcrisis exercise plan and organise the exercises.
- Third-party risk management
- Operate the supplier assurance process and platform: onboard, tier and reassess suppliers on a risk-based cycle.
- Keep a named executive sponsor recorded for each material supplier and chase their review obligations.
- People, access and awareness
- Draft security awareness and training requirements and assure delivery with the People team.
- Support the People Director with the vetting policy and collect the evidence that personnel security controls operate.
- Collect and check access governance evidence: review schedules, privileged access records and joiner, mover and leaver records.
- Support the Security Champions network with process guidance.
- Governance and reporting
- Organise the governance cadence: weekly security governance, fortnightly Security Steering Group, monthly risk review and quarterly Information Security Management Forum.
Agendas, papers, minutes and actions.
- Draft sponsor and board-level reporting for the CISO, sourced and consistent across documents.
- Track every security action to a named owner and a date, and report status without spin.
- Key role measures
- ISO 27001 certification maintained with no major nonconformities; audit findings closed within agreed date
- Risk register currency: every entry reviewed within its cycle, sponsored, and with a live treatment plan
- Customer assurance turnaround: questionnaires and evidence requests answered within agreed SLAs with no unsupported commitments
- Vulnerability remediation reported accurately against contractual windows, with exceptions recorded
- Incident notifications made within contractual and regulatory windows; post-incident actions closed
- Supplier coverage: all material suppliers tiered, assessed and sponsored
Experience and skills
Our ideal candidate would have experience in the following areas
- Information security management
- Working within an ISO 27001 ISMS through certification or surveillance audits, ideally in a Saa S organisation.
- Maintaining a risk register and working with senior risk owners to keep entries current and treated.
- Keeping exceptions, policies and evidence to an audit-ready standard.
- Customer and public sector assurance
- Responding to customer security questionnaires and due diligence, ideally for UK public sector customers.
- Working knowledge of CCS framework security schedules, G-Cloud Schedule 9A, Cyber Essentials Plus and the NCSC Cyber Assessment Framework.
- Good understanding of data protection and UK GDPR, including Articles 28 and 33.
- Supplier and service governance
- Tracking a managed service or supplier against contract and service levels and preparing service reviews.
- Third-party risk management, including experience of a TPRM platform (desirable).
- Coordinating security incidents, keeping records and preparing customer or regulatory notifications.
- Technical literacy
- Enough understanding of cloud, SIEM and vulnerability management to read a service report or scan output and ask the right questions. You will not be writing detection rules.
- Communication and ways of working
- Clear, precise written English. Your reports and evidence will be read by customers, auditors and executives.
- Organised and self-directed, able to keep several governance cycles moving in parallel and chase others to dates politely and persistently.
Qualifications
- ISO 27001 Lead Implementer or Lead Auditor, CISM, CRISC, CISMP or equivalent (desirable).
- Diversity, Equity and Inclusion
We believe that seeing the world from all sorts of angles makes life better for all.
We want you to know that the things that make you an individual, like your identity, age, ethnicity, religion, ability and background, are things that we choose to celebrate and support.
We are a scale-up company, and as we continue to grow, we are passionate that having a diverse, inclusive and authentic workplace will remain at our core.
We are creating an inclusive environment where our people can thrive.
Our values are aligned and at the heart of everything we do. We are respectful, united, rigorous, relentless and ethical.
#J-18808-Ljbffr
Security GRC Analyst employer: Clue Software
Clue Software is an excellent employer for those seeking a dynamic and innovative work environment. With a strong focus on automation and quality, employees are encouraged to grow their skills through continuous learning and collaboration within an agile team. The remote nature of the role offers flexibility, while the company's commitment to employee well-being and professional development makes it a rewarding place to build a career in software quality assurance.
StudySmarter Expert Advice🤫
We think this is how you could land Security GRC Analyst
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Clue Software, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Clue Software
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Clue Software. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Security GRC Analyst
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Clue Software insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Clue Software that you’re committed to staying ahead in the game.
How to prepare for a job interview at Clue Software
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Clue Software to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Clue Software.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.