At a Glance
- Tasks: Support and maintain the Information Security Management System while managing risks effectively.
- Company: Join a respected professional services firm with a focus on governance, risk, and compliance.
- Benefits: Enjoy a hybrid work model, stability, and opportunities for professional growth.
- Why this job: Gain hands-on experience in a high-profile role that makes a real impact.
- Qualifications: 2-3 years in business analysis or GRC, with knowledge of ISO 27001.
- Other info: Collaborative environment with a chance to work across various teams.
The predicted salary is between 30000 - 42000 £ per year.
Our client, a professional services firm, are seeking a talented individual to join their Governance, Risk and Compliance team on a contract basis. This is an excellent entry-level contract opportunity to gain hands-on experience supporting and maintaining a robust Information Security Management System (ISMS) in line with ISO 27001, while contributing directly to day-to-day risk management in a high-profile professional services organisation. You will work closely with IT, legal, compliance, and business stakeholders to protect critical operations, manage risks effectively, and support secure business growth. With a long-term assignment on the horizon, this role offers real stability and development potential in a respected firm.
Job Type: Contract
Working arrangement: Hybrid – 2-3 days a week in the office
Office Location: Central London
The Role
- Support and maintain the organisation’s ISMS in alignment with ISO 27001 controls and clauses
- Assist in risk treatment planning, track remediation efforts, and contribute to continuous improvement
- Maintain and review the Statement of Applicability (SoA), ensuring effective implementation of controls
- Provide valuable input for management reviews and drive ISMS improvement actions
- Conduct regular risk assessments and reviews across systems, vendors, and business processes
- Identify, evaluate, and prioritise information security and operational risks
- Maintain and update the risk register, including clear ownership, mitigation strategies, and timelines
- Collaborate with control owners to assess residual risk and document risk decisions
- Communicate risks to stakeholders with clear, actionable recommendations and business context
- Work closely with IT, legal, and compliance teams to enable secure and compliant business operations
What We’re Looking For
- 2-3 years’ relevant experience in business analysis and governance, risk, compliance, or information security
- Practical understanding of ISO 27001 frameworks, risk assessment methodologies, and ISMS maintenance
- Experience maintaining risk registers, tracking remediation, and supporting risk treatment plans
- Strong analytical skills with the ability to evaluate risks, prioritise issues, and provide clear recommendations
- Excellent communication skills to engage stakeholders and present risks in a business-friendly way
- Collaborative mindset and comfort working across teams (IT, legal, compliance)
- Prior exposure to professional services, financial services, or regulated environments is advantageous
- Motivated self-starter eager to develop expertise in GRC and information security
Junior GRC Business Analyst employer: Computappoint
Contact Detail:
Computappoint Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Junior GRC Business Analyst
✨Tip Number 1
Network like a pro! Reach out to folks in the GRC space on LinkedIn or at industry events. A friendly chat can open doors that applications alone can't.
✨Tip Number 2
Prepare for interviews by brushing up on ISO 27001 and risk management concepts. We want you to be able to discuss how you can contribute to maintaining an ISMS with confidence!
✨Tip Number 3
Showcase your analytical skills during interviews. Be ready to share examples of how you've evaluated risks or contributed to compliance efforts in past roles or projects.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search.
We think you need these skills to ace Junior GRC Business Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Junior GRC Business Analyst role. Highlight any relevant experience you have in governance, risk, and compliance, especially if you've worked with ISO 27001 before. We want to see how your skills match what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about GRC and how your background makes you a great fit for our team. Keep it concise but engaging – we love a good story!
Show Off Your Analytical Skills: In your application, don’t forget to showcase your analytical skills. Mention specific examples where you've evaluated risks or contributed to risk management. We’re keen to see how you approach problem-solving!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re serious about joining our awesome team!
How to prepare for a job interview at Computappoint
✨Know Your ISO 27001 Basics
Make sure you brush up on the key principles of ISO 27001 before your interview. Understanding how it relates to information security management systems will show that you're serious about the role and ready to contribute from day one.
✨Showcase Your Analytical Skills
Prepare examples of how you've evaluated risks or prioritised issues in past experiences. Whether it's through coursework or previous jobs, being able to articulate your analytical thought process will impress the interviewers.
✨Communicate Clearly
Practice explaining complex concepts in a simple way. Since you'll be working with various stakeholders, demonstrating your ability to communicate risks and recommendations clearly will be crucial for success in this role.
✨Be Ready to Collaborate
Think of instances where you've worked across teams, especially in IT, legal, or compliance settings. Highlighting your collaborative mindset will show that you're a team player who can thrive in a hybrid work environment.