GRC Analyst in Cheltenham

GRC Analyst in Cheltenham

Cheltenham Full-Time 63000 - 77000 £ / year (est.) No working from home possible
I

At a Glance

  • Tasks: Support information security governance, risk, and compliance activities in a hands-on role.
  • Company: Established organisation with a focus on information security.
  • Benefits: Competitive salary, potential for contract extension, and professional development opportunities.
  • Other info: Collaborate with technical and business teams in a dynamic environment.
  • Why this job: Make a real impact on security frameworks and work with cutting-edge technology.
  • Qualifications: Experience in GRC, ISO 27001, and security risk management.

The predicted salary is between 63000 - 77000 £ per year.

We’re looking for an experienced GRC Analyst to support an established organisation with its information security governance, risk and compliance activity.

This is a hands-on role suited to someone with strong knowledge of security frameworks including ISO 27001 and NIST, who can work with technical and business teams to assess risk, maintain controls and support ongoing compliance.

Microsoft security experience would be particularly useful, especially across the wider Microsoft 365 and Azure security ecosystem.

The Role

You’ll work closely with security, technology and wider business stakeholders, with responsibilities including:

  • Supporting the organisation’s ISO 27001 ISMS, including maintaining policies, controls and supporting evidence
  • Working with security frameworks including ISO 27001, NIST CSF and CIS Controls
  • Conducting and maintaining information security risk assessments
  • Managing security risks, controls, actions and remediation plans
  • Supporting internal and external security audits and assessments
  • Reviewing existing security controls and identifying areas for improvement
  • Maintaining security policies, standards, procedures and governance documentation
  • Supporting third-party and supplier security assessments
  • Tracking compliance against relevant security frameworks and organisational requirements
  • Working with technical teams to ensure security controls are implemented effectively
  • Producing security reporting, metrics and governance information for stakeholders
  • What We’re Looking For

You’ll ideally have

  • Strong commercial experience within GRC, Information Security or Cyber Security
  • Good working knowledge of ISO 27001
  • Experience working with NIST, ideally NIST CSF
  • Practical experience of security risk management and control assessments
  • Experience supporting security audits and compliance activity
  • Strong understanding of security policies, governance and assurance
  • Experience working with technical and non-technical stakeholders
  • The ability to take ownership of GRC activity rather than purely providing administrative support
  • Experience with Microsoft security tooling would be highly desirable, particularly:
  • Microsoft Purview
  • Microsoft Sentinel
  • Microsoft 365 and Azure security/compliance controls

Relevant certifications such as ISO 27001 Lead Implementer/Auditor, CISM, CRISC, CISSP or equivalent would be beneficial but aren't essential.

  • Contract: Initial 6 months
  • Extension: Strong possibility of extension
  • #J-18808-Ljbffr

GRC Analyst in Cheltenham employer: IMT Resourcing Solutions

Join a forward-thinking organisation that prioritises information security and compliance, offering a collaborative work culture where your expertise as a GRC Analyst will be valued. With a focus on employee growth, you will have access to ongoing training and development opportunities, particularly in the latest Microsoft security tools and frameworks. Located in a vibrant area, this role not only provides meaningful work but also the chance to make a significant impact within the organisation's security landscape.

I

Contact Details:

IMT Resourcing Solutions Recruitment Team

We think you need these skills to ace GRC Analyst in Cheltenham

ISO 27001
NIST CSF
CIS Controls
Information Security Risk Management
Security Audits
Compliance Activity
Security Policies and Governance