At a Glance
- Tasks: Drive governance, risk, and compliance evolution with innovative technology solutions.
- Company: Join a forward-thinking company focused on modernising GRC practices.
- Benefits: Competitive salary, flexible working, and opportunities for professional growth.
- Other info: Collaborative environment with a focus on continuous improvement and impactful outcomes.
- Why this job: Be at the forefront of integrating AI and automation in GRC processes.
- Qualifications: Experience in information security governance and a passion for tech innovation.
The predicted salary is between 63000 - 77000 £ per year.
We are seeking a Senior GRC Analyst to help drive the evolution of our governance, risk and compliance capability from periodic assessment towards continuous, measurable assurance that directly informs business and technology decision making. The role spans both our internal technology initiatives and practical GRC support to our client base.
You will work closely with the teams that build and operate our technology estate, developing sufficient understanding of those environments to assess risk credibly and translate it into a risk position that leadership can act upon. You will concisely articulate your ideas to stakeholders at all levels and influence outcomes in support of enterprise projects.
You will be confident working across the major information security frameworks and standards, including ISO 27001, NIST and SOC 2, and able to shape risk, compliance and control decisions in a way that keeps both us and our clients secure without slowing the business down.
We are actively modernising the way assurance is delivered, with particular emphasis on automation and the practical application of AI to improve control efficacy and reduce manual effort. This role will be central to that work, and we are looking for a practitioner motivated by evolving how GRC is delivered rather than by maintaining existing processes through traditional methods.
If you have a positive mindset and can map risk to business value with a practical, adaptable and innovative approach, then this is the role for you.
Key Responsibilities- Risk Management: Work closely with technology teams and clients to develop an accurate and current understanding of the risk picture, and articulate and report on it consistently and effectively to both technical and executive audiences.
- Framework Implementation: Plan, implement and maintain a security program aligned to CIS Controls v8 and other framework requirements in a manner appropriate to the environment, taking a practical and proportionate approach.
- Internal and Client Delivery: Provide security subject matter expertise across our internal technology initiatives, collaborating with project managers, business stakeholders and operational teams, and lead client GRC engagements end to end from gap assessment and framework implementation through to audit readiness and ongoing advisory.
- Measurement and Insight: Maintain a clear and current view of control effectiveness, risk trends and remediation progress, underpinned by tangible data points, and use it to inform business and technology planning decisions.
- Audit and Assurance: Plan and conduct internal and external compliance audits, coordinating with the wider Information Security function and external partners, and pursue remediation through to demonstrable risk reduction.
- Automation and AI: Identify assurance activity that is manual, repetitive or inefficient and lead the work to improve it, engaging technical teams and tooling to deliver measurable improvements in control efficacy and analyst capacity.
- Core GRC Services: Contribute to and mature the core services we provide, including third-party risk management, the policy and standards framework, and security awareness and training content, making each scalable, measurable and automated wherever practical.
- Function Development: Support the development of the wider Information Security function, evolving ways of working to solve problems in a collaborative environment.
- Relevant experience in a comparable role across information security governance, risk management, compliance and audit, with a demonstrable track record of delivered outcomes.
- Practical implementation experience with CIS Controls, ISO 27001 or equivalent frameworks within live operating environments, including the judgement required to apply them proportionately.
- Sufficient technical understanding to engage credibly with operational IT teams across a range of security domains including identity, networks, vulnerability management and configuration hardening.
- An active interest in AI and automation technologies in the context of a 'GRC Engineering' mindset.
- A risk-based mindset, prioritising on the basis of evidence and impact, with reporting produced to support decisions rather than to record activity.
- The ability to prioritise a complex and evolving workload against available capacity, and to communicate the impact of change clearly with smart escalations.
- The confidence to identify opportunities, influence change and challenge constructively at all levels whilst building positive relationships with key business stakeholders and operational leads.
- Willingness to travel internationally for business on occasion.
- Practical experience of introducing AI and automation into GRC processes.
- Certification in one or more of CISA, CRISC, CISSP, CISM, CGE-P, ISO 27001 Lead Auditor or Lead Implementer.
The above list of duties is not exclusive or exhaustive and the post holder will be required to undertake tasks that are reasonably expected within the scope and grading of the post.
GRC Senior Analyst employer: Recruitment
As a Senior Quantitative Modeller at our company, you will thrive in a dynamic and innovative work culture that values autonomy and collaboration. We offer competitive benefits, including professional development opportunities and a supportive environment for mentorship, ensuring your growth as an expert in mathematical and statistical modelling. Located in a vibrant area, our office fosters creativity and teamwork, making it an excellent place for those seeking meaningful and rewarding employment.
StudySmarter Expert Advice🤫
We think this is how you could land GRC Senior Analyst
✨Join Compliance Communities
Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!
✨Attend Industry Conferences
Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.
✨Leverage Your University Career Services
If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.
✨Showcase Your Knowledge Online
Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Recruitment looking for candidates who are engaged and informed.
We think you need these skills to ace GRC Senior Analyst
Some tips for your application 🫡
Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!
Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.
Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!
Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Recruitment. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!
How to prepare for a job interview at Recruitment
✨Master the Regulations
Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!
✨Show Your Analytical Skills
Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!
✨Know Your Tools
Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!
✨Align with Company Culture
Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Recruitment’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!