Governance, Risk and Compliance (GRC) Analyst
Governance, Risk and Compliance (GRC) Analyst

Governance, Risk and Compliance (GRC) Analyst

Manchester Full-Time 30000 - 50000 £ / year (est.) Home office (partial)
J

At a Glance

  • Tasks: Join our Cyber Security team to manage risks and ensure compliance with regulations.
  • Company: N Brown Group is a leading digital retailer committed to diversity and sustainability.
  • Benefits: Enjoy hybrid working, 24 days holiday, mental health support, and colleague discounts.
  • Why this job: Be part of a culture that values inclusion and continuous improvement in a trusted brand.
  • Qualifications: Strong communication skills and some technical knowledge are essential; experience with compliance frameworks preferred.
  • Other info: Flexible working hours and a vibrant office location in Manchester's Northern Quarter.

The predicted salary is between 30000 - 50000 £ per year.

We’re looking for a Governance, Risk and Compliance (GRC) Analyst to join our Cyber Security and Risk team here at N Brown Group. The Governance, Risk and Compliance team is responsible for the development and rollout of our security policies and procedures; for building an awareness programme to promote a strong security culture across the organisation; identifying and tracking risks in our supply chain; and for ensuring we maintain compliance with regulations such as the PCI DSS. The team works closely with 1st and 2nd line risk to develop suitable controls and metrics to ensure the Digital Operations department is operating within risk appetite, and track remediation tasks when it is not.

As a Governance, Risk and Compliance Analyst you will work across all these areas of the team’s responsibilities and help to identify ways to improve simplicity and efficiency. Although this isn’t a technical role, you will be expected to have sufficient technical expertise to understand technology risks and controls to mitigate them. You’ll be an excellent communicator, with the ability to simplify technical terms for the non-technical person and also manage and build relationships.

What will you do as a GRC Analyst at N Brown?

  • Support the risk management process by identifying and evaluating threats, and work with risk owners to understand the business impact and help develop treatment plans;
  • Track open risk remediation tasks and facilitate the approval process for risk acceptance requests, ensuring sufficient mitigating controls are in place;
  • Complete risk-based security due diligence on third-party providers during the initial contracting phase and at regular intervals;
  • Contribute to the development of control testing strategies, to ensure our security controls are operating effectively and achieving their purpose;
  • Help maintain compliance with applicable regulations such as the PCI DSS, assist in finding ways to streamline the assessment process;
  • Support the development and delivery of the security awareness training programme by working closely with colleagues across the business to promote a strong information security culture;
  • Design and delivery of regular communication materials over multiple channels;
  • Management and reporting of regular phishing simulation exercises;
  • Management and oversight of Penetration tests;
  • Drive adoption and adherence to Information Security policy, standards, and guidelines;
  • Evaluate requests for exceptions to policies and security compliance queries;
  • Integrate and transform information security policies, standards and procedures.

What skills and experience will you have?

  • Skilled in writing a range of documentation, relevant for the business, ranging from processes and procedures to reports, standards and frameworks;
  • Experience of applying policies and controls in an agile, cloud first organisation;
  • Sufficient technical knowledge to understand risks associated with technology platforms and the controls to mitigate them;
  • Able to constructively challenge processes and procedures to drive continuous improvement;
  • Experience of working within PCI DSS, or other compliance frameworks;
  • Excellent communication skills with the ability to build great relationships across the business and articulate security concepts to non-technical colleagues;
  • A proficient problem-solver that can work autonomously;
  • Knowledge of how to assist in the delivery of a security awareness programme across a large business.

What’s in it for you?

  • Hybrid working
  • 24 days holiday (+ 8 bank holidays)
  • Annual bonus scheme
  • Enhanced maternity and adoption leave
  • Company pension with up to 8% N Brown contribution
  • Mental Health support both internally and externally, including access to our wellbeing champions and counselling services
  • A range of financial wellbeing support
  • Colleague discount across all N Brown brands
  • Onsite café with subsidised rates and local restaurant discounts!
  • Life Assurance and Private Medical Insurance
  • Paid volunteer time – all our colleagues can take a full day paid to volunteer for a charity of their choice

N Brown – who we are and why work for us?

At N Brown, we’re committed to building a diverse workforce and creating an inclusive environment that values equality for all. Our vision is that by ‘championing inclusion, we’ll become the most loved and trusted fashion retailer’. Diversity, Equity, Inclusion and Belonging are, therefore, at the heart of our culture. We’re a forward-thinking digital retailer with a financial services proposition to be proud of. We’re customer-obsessed, serving them through three core brands: JD Williams, Simply Be, and Jacamo. We’re experienced, with over 160 years of trading under our belt. We’re inclusive, as we believe in fashion without boundaries; and we’re sustainable, striving to make as little impact on the planet as possible.

In May 2024 we were delighted to be named one of The Sunday Times Best Places to Work 2024. We work hard to create a happy and inclusive culture for everyone and we’re so proud to have made this list - as voted for by our very own colleagues!

Ways of Working

We offer hybrid working which varies across the business depending on the role you’re in. Our Head Office is located in the Northern Quarter in Manchester City Centre. So if you are travelling by train, tram or bus we’re perfectly located, plus we’re surrounded by cool cafes, trendy bars and the best places to eat! Our working hours are 36.17 per week and our core working hours are between 10am - 4pm. Given we don’t have strict working hours you can find the working pattern that’s right for you.

Our promise to you:

We’re an equal opportunity employer and value diversity. We do not discriminate based on race, religion, colour, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status.

What happens when you apply to a role at N Brown?

As soon as we receive your application, we’ll send you an email to let you know. We always aim to come back to you as soon as possible with an update and we really appreciate you taking the time to apply for a role with us. Good luck!

Governance, Risk and Compliance (GRC) Analyst employer: JD Williams

N Brown Group is an exceptional employer that prioritises a diverse and inclusive work culture, offering hybrid working arrangements and a comprehensive benefits package including 24 days of holiday, mental health support, and paid volunteer time. Located in the vibrant Northern Quarter of Manchester, employees enjoy a dynamic environment with access to trendy cafes and bars, while also having ample opportunities for professional growth within a forward-thinking digital retail company committed to sustainability and community engagement.
J

Contact Detail:

JD Williams Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Governance, Risk and Compliance (GRC) Analyst

✨Tip Number 1

Familiarise yourself with the PCI DSS regulations and other compliance frameworks mentioned in the job description. Understanding these will not only help you during interviews but also demonstrate your commitment to the role.

✨Tip Number 2

Brush up on your communication skills, especially in simplifying technical jargon for non-technical audiences. This is crucial for the GRC Analyst role, as you'll need to convey complex security concepts clearly.

✨Tip Number 3

Network with professionals in the Cyber Security and Risk field. Engaging with others in the industry can provide insights into best practices and may even lead to referrals or recommendations.

✨Tip Number 4

Stay updated on the latest trends and threats in cyber security. Being knowledgeable about current risks will show your proactive approach and readiness to tackle challenges in the GRC space.

We think you need these skills to ace Governance, Risk and Compliance (GRC) Analyst

Risk Management
Compliance Knowledge (PCI DSS and other frameworks)
Technical Understanding of Technology Risks
Documentation Skills
Communication Skills
Relationship Management
Problem-Solving Skills
Continuous Improvement Mindset
Security Awareness Training Development
Control Testing Strategies
Agile Methodologies
Phishing Simulation Management
Penetration Testing Oversight
Policy Evaluation and Exception Handling

Some tips for your application 🫡

Understand the Role: Before you start writing your application, make sure you fully understand the responsibilities and requirements of the Governance, Risk and Compliance (GRC) Analyst position. Tailor your application to highlight how your skills and experiences align with the specific tasks mentioned in the job description.

Highlight Relevant Experience: When detailing your work history, focus on experiences that relate directly to governance, risk management, and compliance. Mention any previous roles where you developed security policies, managed risks, or worked with compliance frameworks like PCI DSS.

Showcase Communication Skills: Since excellent communication is key for this role, provide examples of how you've successfully communicated complex technical concepts to non-technical stakeholders. This could be through reports, presentations, or training sessions.

Tailor Your CV and Cover Letter: Make sure your CV and cover letter are tailored specifically for the GRC Analyst role at N Brown Group. Use keywords from the job description and demonstrate your understanding of the company's values and culture, particularly around diversity and inclusion.

How to prepare for a job interview at JD Williams

✨Understand the Role

Make sure you thoroughly understand the responsibilities of a GRC Analyst. Familiarise yourself with key concepts like risk management, compliance frameworks, and security policies. This will help you answer questions confidently and demonstrate your knowledge.

✨Showcase Communication Skills

As an excellent communicator, you'll need to articulate complex security concepts to non-technical colleagues. Prepare examples of how you've simplified technical information in the past, and be ready to discuss your approach to building relationships across teams.

✨Prepare for Scenario-Based Questions

Expect scenario-based questions that assess your problem-solving skills and ability to handle risks. Think of specific situations where you've identified threats or improved processes, and be ready to explain your thought process and outcomes.

✨Demonstrate Continuous Improvement Mindset

The role requires a proactive approach to challenge existing processes. Be prepared to discuss how you've driven improvements in previous roles, particularly in relation to compliance and risk management, and how you can bring that mindset to N Brown.

Governance, Risk and Compliance (GRC) Analyst
JD Williams
J
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>