GRC Analyst (Security Governance & Configuration) in Glasgow
GRC Analyst (Security Governance & Configuration)

GRC Analyst (Security Governance & Configuration) in Glasgow

Glasgow Full-Time 50000 - 60000 £ / year (est.) Home office (partial)
C

At a Glance

  • Tasks: Shape security practices and enhance governance in a major energy network programme.
  • Company: Join Sword, a leader in business technology solutions across various sectors.
  • Benefits: Enjoy flexible working, personalised career development, and a fantastic benefits package.
  • Why this job: Make a real impact on security processes while collaborating with diverse teams.
  • Qualifications: Experience with cyber security standards and strong documentation skills required.
  • Other info: Embrace diversity and grow in an inclusive workplace that values your unique perspective.

The predicted salary is between 50000 - 60000 £ per year.

Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving transformational change within our clients. We use proven technology, specialist teams and domain expertise to build solid technical foundations across platforms, data, and business applications. We have a passion for using technology to solve business problems, working in partnership with our clients to help in achieving their goals.

About the role: As a GRC Analyst, you’ll play a key role in strengthening governance, risk, and compliance practices across a major energy network programme. This is a hands‑on role where you’ll help shape how secure configuration and change management are defined, documented, and embedded across the organisation. You’ll be working at the intersection of cyber security, governance, and business change—translating complex security standards into clear, practical processes that teams can understand and adopt.

From developing configuration management plans aligned to recognised standards, through to supporting rollout and communication across the business, your work will directly influence how security is applied in real-world operations. You’ll collaborate closely with security, change, and business teams, ensuring that governance processes are not only well-designed, but effectively implemented and understood. This is an opportunity to contribute to a high‑impact programme, bringing structure, clarity, and consistency to critical security practices.

As a GRC Analyst, you will:

  • Develop and document a Configuration Management Plan aligned to recognised standards such as NIST.
  • Define and document roles and responsibilities across the 2nd Line of Defence, ensuring clarity and accountability.
  • Support the rollout of configuration management processes, including communication, stakeholder engagement, and adoption.
  • Document secure configuration policy principles, translating technical requirements into clear, accessible guidance.
  • Review, refine, and communicate security policies to ensure alignment with organisational and regulatory expectations.
  • Gather and interpret configuration compliance reports from monitoring tools to support governance activities.
  • Enhance change management processes, including contributing to Change Advisory Board (CAB) inputs.
  • Work closely with business change and communications teams to embed new processes effectively.
  • Simplify complex security concepts into practical guidance for non‑technical stakeholders.
  • Maintain clear, structured documentation that supports ongoing governance and audit requirements.

Experience working with cyber security standards such as ISO 27001 or NIST frameworks (e.g. NIST 800‑53). Understanding of secure configuration principles and cyber security policy development. Experience writing policies, procedures, or governance documentation within a security context. Strong documentation skills, with the ability to produce clear, structured, and usable outputs. Ability to understand and map process flows, including defining roles and responsibilities (e.g. RACI models). Strong communication skills, with the ability to translate technical concepts into business-friendly language. Experience collaborating with cross‑functional teams, including security, change, and communications.

It would be great if you also had:

  • Experience developing or implementing a Configuration Management Plan.
  • Exposure to governance within large-scale transformation or regulated environments.
  • Familiarity with compliance reporting and monitoring tools.
  • Experience supporting change management processes or governance forums such as CAB.

At Sword, our core values and culture are based on caring about our people, investing in training and career development, and building inclusive teams where we are all encouraged to contribute to achieve success. We offer comprehensive benefits designed to support your professional development and enhance your overall quality of life. In addition to a Competitive Salary, here's what you can expect as part of our benefits package:

  • Personalised Career Development: We create a development plan customised to your goals and aspirations, with a range of learning and development opportunities within a culture that encourages growth.
  • Flexible working: Flexible work arrangements to support your work‑life balance.
  • A Fantastic Benefits Package: This includes generous annual leave allowance, enhanced family friendly benefits, pension scheme, access to private health, well‑being, and insurance schemes.

At Sword we are dedicated to fostering a diverse and inclusive workplace and are proud to be an equal opportunities employer, ensuring that all applicants receive fair and equal consideration for employment, regardless of whether they meet every requirement. If you don’t tick all the boxes but feel you have some of the relevant skills and experience we’re looking for, please do consider applying and highlight your transferable skills and experience. We embrace diversity in all its forms, valuing individuals regardless of age, disability, gender identity or reassignment, marital or civil partner status, pregnancy or maternity status, race, colour, nationality, ethnic or national origin, religion or belief, sex, or sexual orientation. Your perspective and potential are important to us.

GRC Analyst (Security Governance & Configuration) in Glasgow employer: Cyber Fraud Centre

Sword is an exceptional employer, offering a dynamic work environment where innovation meets collaboration. With a strong commitment to employee growth, we provide personalised career development plans and flexible working arrangements that promote a healthy work-life balance. Our inclusive culture, coupled with a comprehensive benefits package, ensures that every team member feels valued and empowered to contribute to meaningful projects within the energy sector.
C

Contact Detail:

Cyber Fraud Centre Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land GRC Analyst (Security Governance & Configuration) in Glasgow

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend events, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their values and how they align with your own. This will help you tailor your responses and show that you're genuinely interested in being part of their team.

✨Tip Number 3

Practice makes perfect! Conduct mock interviews with friends or use online platforms to get comfortable with common questions. The more you practice, the more confident you'll feel when it’s time to shine.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive about their job search!

We think you need these skills to ace GRC Analyst (Security Governance & Configuration) in Glasgow

Governance Risk and Compliance (GRC)
Configuration Management
Cyber Security Standards (ISO 27001, NIST)
Policy Development
Documentation Skills
Stakeholder Engagement
Change Management
Communication Skills
Cross-Functional Collaboration
Process Mapping
Compliance Reporting
Security Policy Review
Technical Translation
Structured Documentation

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with governance, risk, and compliance. Use keywords from the job description to show that you understand what we're looking for.

Showcase Your Documentation Skills: Since strong documentation skills are key for this role, include examples of policies or procedures you've written in the past. This will help us see how you can produce clear and structured outputs.

Keep It Clear and Concise: When writing your application, aim for clarity. Avoid jargon and make sure your points are easy to understand. We want to see how you can translate complex concepts into business-friendly language.

Apply Through Our Website: We encourage you to apply directly through our website. This way, we can ensure your application gets the attention it deserves and you can easily keep track of your application status.

How to prepare for a job interview at Cyber Fraud Centre

✨Know Your Standards

Familiarise yourself with key security frameworks like NIST and ISO 27001. Be ready to discuss how these standards apply to the role of a GRC Analyst and how you can help implement them effectively within the organisation.

✨Simplify Complex Concepts

Practice translating technical jargon into business-friendly language. During the interview, demonstrate your ability to communicate complex security principles clearly, as this will be crucial in your role when working with non-technical stakeholders.

✨Showcase Your Documentation Skills

Prepare examples of your previous work related to policy writing or governance documentation. Highlight your ability to create clear, structured outputs that align with organisational needs, as this is a key part of the GRC Analyst position.

✨Engage with Cross-Functional Teams

Be ready to discuss your experience collaborating with various teams, such as security, change management, and communications. Share specific examples of how you've successfully worked across functions to implement governance processes and enhance compliance.

GRC Analyst (Security Governance & Configuration) in Glasgow
Cyber Fraud Centre
Location: Glasgow

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>