GRC Analyst – Controls Testing & Assurance
GRC Analyst – Controls Testing & Assurance

GRC Analyst – Controls Testing & Assurance

Full-Time 40000 - 50000 £ / year (est.) No home office possible
J

At a Glance

  • Tasks: Test and assess IT controls to ensure cybersecurity and compliance.
  • Company: Join JD Sports, a leading global retailer in sports fashion.
  • Benefits: Enjoy staff discounts and personal development opportunities.
  • Other info: Collaborate with diverse teams and enhance your career in a fast-paced setting.
  • Why this job: Make a real impact in a dynamic environment focused on innovation.
  • Qualifications: 2-5 years in controls testing or IT audit; relevant certifications preferred.

The predicted salary is between 40000 - 50000 £ per year.

Established in 1981 with a single store in the Northwest of England, the JD Group is a leading omni-channel retailer of Sports Fashion, Outdoors and Gyms with our colleagues working in stores across several retail fascias in many markets around the world. JD Sports Fashion Plc was listed on the London Stock Exchange in 1996 and has been a FTSE100 publicly quoted company since 2019 and continues to grow in the UK and internationally. We want to be the leading global omnichannel retailer in the sports and outdoor industry. To be a part of this successful company and help us to achieve this you will have the desire to ingrain our strategic goals of being a people‑led, innovative and customer‑focused organisation which provides operational excellence whilst identifying new areas of growth as part of our day to day objectives.

Role Purpose

The GRC Analyst will sit within the second line of defence and is responsible for testing and assessing the design and operating effectiveness of IT General Controls (ITGCs) and cybersecurity controls across JD Sports. The role is focused on executing control testing, evaluating evidence, identifying control gaps and supporting audit readiness. The GRC Analyst will work closely with Technology, Internal Controls and Audit teams to ensure that the JD Sports control environment meets regulatory audit and internal risk management and control requirements. This is a technically focused GRC role requiring a strong understanding of ITGC and cybersecurity frameworks, audit methodologies and enterprise IT environments. The successful candidate will be instrumental in supporting external audit readiness, identifying control gaps and driving remediation activity across JD Sports.

Key Responsibilities

  • Control Testing & Assurance
    • Plan, execute and document risk‑based testing of IT General Controls and cybersecurity controls across key domains including identity and access management, change management, computer operations and third‑party risk.
    • Assess controls for design adequacy and operating effectiveness in line with recognised frameworks such as COBIT, SOX ITGC, ISO 27001 and NIST.
    • Collect, review and evaluate control evidence, applying professional scepticism and audit rigour.
    • Identify control deficiencies and gaps, articulating root causes, risk impact and recommended remediation actions.
    • Maintain accurate and complete working papers and test documentation.
  • Control Framework & Oversight
    • Support the development and maintenance of the Technology Controls Framework and ITGC and cybersecurity control library, ensuring controls remain aligned to risk appetite and evolving business requirements.
    • Monitor and track control remediation activity, escalating overdue or high‑risk items to senior stakeholders in a timely manner.
    • Operate and provide input into Control Self‑Assessment (CSA) processes, contributing ITGC‑specific insight to the broader enterprise risk framework.
  • Audit Support & Stakeholder Management
    • Support the GRC Controls Lead with internal and external auditors during IT audit cycles, coordinating evidence requests, facilitating walkthrough and managing the audit relationship professionally.
    • Support preparation for inspections and audits, ensuring documentation and evidence packs are accurate, complete and audit‑ready.
    • Build effective working relationships and support cross‑functional collaboration with other teams and functions such as Technology, Internal Controls, Internal Audit, Enterprise Risk, Legal and Procurement.
  • Issue Management & Reporting
    • Support in the development of clear and concise testing reports and exception summaries for consumption by technical and non‑technical audiences, including senior management and board‑level committees.
    • Maintain GRC tooling, dashboards and metrics relating to ITGC and cybersecurity control coverage, testing progress, deficiency status and remediation timelines.
    • Present findings and recommendations with clarity and confidence, supporting informed risk‑based decision making.
    • Identify opportunities to improve the efficiency and effectiveness of the ITGC testing programme, including automation, tooling and methodology enhancements.
    • Support enhancements of GRC policies, standards and procedures relating to technology risk and control.
    • Stay current with changes to relevant regulatory requirements, audit standards and industry best practice.

Skills & Experience

  • 2-5 years of demonstrable experience in controls testing, IT audit, or GRC function within a fast‑paced and complex organisation.
  • Strong understanding of IT General Controls domains such as identity and access management, change management, computer operations, programme development and third‑party risk.
  • High‑level and working knowledge of cybersecurity control domains such as vulnerability management, incident response, logging and monitoring, data protection and encryption, cloud security and network security.
  • Ability to assess both control design and operating effectiveness.
  • Experience collecting, evaluating and challenging control evidence.
  • Ability to identify control weaknesses, articulate risk impact and develop actionable remediation recommendations.
  • Strong written and verbal communication skills, with the ability to produce clear and concise audit and assurance reports.
  • Organised and methodical approach to workload management, with the ability to manage multiple priorities and deadlines.
  • Relevant professional certifications such as CISA, CRISC, CISSP or equivalent.
  • Familiarity with audit frameworks and standards including COBIT, SOX ITGC, ISO 27001 and NIST.
  • Experience in a retail, e‑commerce or large global enterprise environments, supporting Big 4/external audit or internal audit engagements in an ICFR / SOX / IT control capacity.
  • Familiarity with GRC tooling platforms such as AuditBoard or similar.
  • Independence and objectivity: Operates with integrity and professional scepticism, providing impartial assurance regardless of organisational pressure.
  • Analytical thinking: Applies a structured, evidence‑based approach testing.
  • Stakeholder engagement: Builds credible and effective working relationships with first line teams, auditors and senior stakeholders.
  • Attention to detail: Maintains a high standard of accuracy in testing documentation, evidence review and reporting.
  • Continuous improvement: Seeks opportunities to improve processes and outcomes.

Benefits

Staff discount on JD Group and other brands; personal development opportunities.

GRC Analyst – Controls Testing & Assurance employer: JD Group Plc

JD Sports is an exceptional employer, offering a dynamic work environment at our Head Office in Bury, where innovation and collaboration thrive. Employees benefit from a strong focus on personal development, competitive staff discounts, and the opportunity to contribute to a leading global omnichannel retailer in the sports and outdoor industry. With a commitment to operational excellence and a people-led culture, JD Sports fosters growth and encourages employees to drive meaningful change within the organisation.
J

Contact Detail:

JD Group Plc Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land GRC Analyst – Controls Testing & Assurance

Tip Number 1

Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching JD Sports and understanding their values and goals. Tailor your answers to show how you can contribute to their mission of being a leading global omnichannel retailer.

Tip Number 3

Practice your responses to common interview questions, especially those related to controls testing and assurance. Use the STAR method (Situation, Task, Action, Result) to structure your answers effectively.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining the team at JD Sports.

We think you need these skills to ace GRC Analyst – Controls Testing & Assurance

IT General Controls (ITGC)
Cybersecurity Frameworks
Audit Methodologies
Control Testing
Risk Assessment
Evidence Evaluation
Control Gap Identification
Regulatory Compliance
Stakeholder Management
Communication Skills
Analytical Thinking
Attention to Detail
GRC Tooling Platforms
Continuous Improvement
Professional Certifications (CISA, CRISC, CISSP)

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the GRC Analyst role. Highlight your experience with IT General Controls and cybersecurity frameworks, as well as any relevant certifications. We want to see how your skills align with what we're looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about the role and how you can contribute to our goals at JD Sports. Keep it concise but impactful – we love a good story!

Showcase Your Analytical Skills: In your application, be sure to highlight your analytical thinking and attention to detail. We’re looking for someone who can assess control effectiveness and identify gaps, so give us examples of how you've done this in the past.

Apply Through Our Website: Don’t forget to apply through our website! It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re serious about joining our team at JD Sports.

How to prepare for a job interview at JD Group Plc

Know Your Frameworks

Make sure you brush up on key frameworks like COBIT, SOX ITGC, ISO 27001, and NIST. Being able to discuss these in detail will show that you understand the technical requirements of the GRC Analyst role and can apply them effectively.

Prepare for Control Testing Scenarios

Think about specific examples from your past experience where you've tested controls or identified gaps. Be ready to explain your thought process and how you approached remediation. This will demonstrate your practical knowledge and problem-solving skills.

Showcase Your Communication Skills

As a GRC Analyst, you'll need to communicate findings clearly to both technical and non-technical audiences. Practice explaining complex concepts in simple terms, and prepare to discuss how you've successfully collaborated with cross-functional teams in the past.

Stay Current with Industry Trends

Familiarise yourself with the latest trends in cybersecurity and regulatory changes. Being able to discuss recent developments will not only impress your interviewers but also show that you're proactive about staying informed in this fast-paced field.

GRC Analyst – Controls Testing & Assurance
JD Group Plc

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>