Cyber GRC Analyst (Cyber Policy & Governance)

Cyber GRC Analyst (Cyber Policy & Governance)

Full-Time No working from home possible
I

Are you passionate about shaping cyber security strategy and governance within a complex, highly regulated environment?

We are working with a major organisation responsible for operating and protecting nationally important infrastructure. As part of continued investment in cyber resilience, they are seeking a GRC Analyst to support the development and implementation of cyber security policy, governance, and assurance activities across a diverse technology landscape.

Whilst the job title is GRC Analyst, the primary focus of the role is developing, maintaining and improving Cyber Security Policies , working closely with stakeholders across the business to ensure they remain aligned to regulatory requirements, industry best practice and organisational objectives.

This is an opportunity to influence cyber strategy at an enterprise level, working with senior stakeholders, regulators, and technical teams to strengthen security and resilience across both traditional IT and operational environments.

The Role

As a GRC Analyst , you will play a key role in developing, maintaining, and enhancing cyber security policies, standards, and governance frameworks. You will provide expert guidance on regulatory compliance, emerging cyber risks, and industry best practice while supporting the organisation's long-term cyber resilience objectives.

Key responsibilities will include:

  • Developing and maintaining cyber security policies, standards, and governance frameworks aligned to recognised industry best practice.
  • Providing expert advice and guidance to technology, security, risk, and leadership teams.
  • Monitoring changes in legislation, regulation, and the threat landscape to ensure policies remain current and effective.
  • Working closely with internal stakeholders across technology, operations, legal, risk, and compliance functions.
  • Supporting cyber governance activities, audits, assurance reviews, and regulatory engagements.
  • Contributing to incident response planning, lessons learned activities, and continuous policy improvement.
  • Identifying strategic cyber risks and recommending appropriate mitigation measures.

About You

To be successful in this role, you'll have experience within Cyber Governance, Risk & Compliance (GRC), Information Security or Cyber Security, together with an interest in developing and improving cyber security policies within a regulated environment.

You will ideally have:

  • Experience developing, reviewing or managing cyber security policies, standards, procedures or governance frameworks.
  • Strong knowledge of recognised cyber security frameworks such as ISO 27001, NIST, or the Cyber Assessment Framework (CAF).
  • Experience supporting compliance, risk management, governance or information assurance programmes.
  • Excellent stakeholder management and communication skills, with the ability to translate technical concepts into clear business and policy language.
  • Experience engaging with senior stakeholders, external partners, or regulatory bodies.
  • The ability to balance security requirements with operational and business objectives.

Desirable Experience

  • Experience within critical infrastructure, utilities, defence, energy, engineering, transport, manufacturing, or other highly regulated sectors.
  • Understanding of Operational Technology (OT) and Industrial Control Systems (ICS) security.
  • Knowledge of cyber resilience requirements within critical national infrastructure environments.
  • Professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor.

What's on Offer

  • Opportunity to influence cyber strategy within a nationally significant organisation.
  • Exposure to complex cyber security and governance challenges.
  • Collaborative and supportive working environment.
  • Ongoing professional development and certification support.
  • Competitive salary and comprehensive benefits package.

If you're looking to make a meaningful impact in a role that combines cyber security, policy development , governance, and strategic stakeholder engagement, we'd like to hear from you.


TPBN1_UKTJ

Cyber GRC Analyst (Cyber Policy & Governance) employer: IBEX RECRUITMENT LTD

Join a leading global consulting firm renowned for its exceptional cyber practices, where you will be part of a dynamic team dedicated to tackling high-stakes cyber incidents. With a strong emphasis on employee development and a collaborative work culture, this role offers unique opportunities for growth, mentorship, and impactful contributions to client success. Located in the UK, you'll benefit from working alongside over 200 specialists in a supportive environment that values innovation and excellence.

I

Contact Details:

IBEX RECRUITMENT LTD Recruitment Team