GRC Analyst

GRC Analyst

Full-Time 49500 - 60500 £ / year (est.) Working from home possible
R

At a Glance

  • Tasks: Help clients achieve security goals and compliance while enhancing cloud security protocols.
  • Company: Join Rhymetec, a forward-thinking tech company with a focus on inclusivity.
  • Benefits: Remote work, professional growth opportunities, and a supportive environment.
  • Other info: Flexible role with opportunities for client engagement and travel.
  • Why this job: Make a real impact in cybersecurity and work with cutting-edge technologies.
  • Qualifications: Experience in technology or cybersecurity, familiarity with compliance frameworks.

The predicted salary is between 49500 - 60500 £ per year.

GRC Analyst at Rhymetec

About the role Rhymetec is on the lookout for a GRC Analyst to enhance our growing team in the UK.

This role is pivotal in helping our clients achieve their security objectives and compliance requirements.

The ideal candidate will work closely with the Security Program Manager to set and meet security and compliance targets, while also contributing to the improvement of our internal cloud security protocols.

  • Key facts
  • Engagement: Full-time, Permanent

What you'll do

  • Organize and prepare agendas and materials for meetings with clients.
  • Engage in regular discussions with clients to assess progress and identify their needs.
  • Set up performance monitoring notifications across cloud platforms such as AWS, Azure, GCP, and Datadog.
  • Configure security alerts and Intrusion Detection Systems within AWS, GCP, and Azure environments.
  • Implement and manage various security applications to enhance client security postures.
  • Develop mobile device management solutions using tools like Jamf, Jumpcloud, Microsoft Endpoint Manager, and Hexnode.
  • Oversee compliance monitoring systems to ensure adherence to security standards.
  • Conduct internal audits and risk assessments, and prepare detailed reports based on findings.
  • Lead Incident Response Tabletop exercises with clients to enhance their preparedness.
  • Organize Business Continuity and Disaster Recovery drills to ensure client resilience.
  • Assist clients in converting compliance frameworks such as SOC 2 Type 2, ISO 27001, GDPR, and DORA into actionable steps.
  • Perform employee access reviews, evaluate Saa S vendor security, and conduct gap analyses.
  • Address and resolve bug and vulnerability reports submitted by security researchers.
  • Complete security questionnaires on behalf of clients to demonstrate compliance.
  • Draft and maintain documentation for clients' information security management systems and policies.
  • Collect and organize compliance evidence for various regulatory frameworks.
  • Lead audit engagements on behalf of clients to ensure compliance with necessary standards.
  • Communicate tasks effectively to client personnel and provide education on security best practices.

Requirements

  • Familiarity with various compliance and regulatory frameworks, including PCI, ISO/IEC, SOC 2, DORA, and GDPR.
  • A solid understanding of logical security, particularly in cloud security environments.
  • Knowledge of major cloud platforms (AWS, GCP, Azure) and the integration of security controls through Dev Ops and Infrastructure as a Service (Iaa S) methodologies.
  • Proven experience in customer service, with a focus on building and maintaining professional relationships.
  • Must Haves
  • A Bachelor's degree or equivalent experience in technology or cybersecurity.
  • Proficiency in German and/or French languages.
  • A minimum of 4 years of experience in technology or cybersecurity roles.
  • Flexibility and adaptability to meet changing work demands.
  • Willingness to travel up to two weeks per year for client engagements.
  • Nice to have
  • Experience with security frameworks and compliance tools.
  • Familiarity with risk management methodologies.
  • Previous experience in a client-facing role within a consultancy or security firm.

Skills & tools

  • Proficient in cloud security tools and platforms, including AWS, GCP, and Azure.
  • Familiarity with compliance management software and security assessment tools.
  • Strong analytical skills and attention to detail.
  • Excellent communication and interpersonal skills.
  • Practical notes
  • This position is remote, but candidates should be located in or around London for potential client meetings.
  • The role requires a proactive approach to problem-solving and the ability to work independently as well as part of a team.
  • Rhymetec offers a supportive work environment with opportunities for professional growth and development.
  • META Company: Rhymetec Title: GRC Analyst Listed location: London, England, United Kingdom

Rhymetec is committed to creating an inclusive workplace and is proud to be an equal opportunity employer.

We welcome applications from all qualified candidates, regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetic background, disability, age, or veteran status.

#J-18808-Ljbffr

GRC Analyst employer: Rhymetec

Rhymetec is an exceptional employer, offering a dynamic remote work environment that fosters collaboration and innovation in the fields of compliance and cybersecurity. With comprehensive benefits including company-funded private medical insurance, generous annual leave, and a commitment to employee wellbeing, Rhymetec prioritises the growth and development of its team members while promoting a diverse and inclusive workplace culture. Join us in London and be part of a mission-driven team dedicated to helping clients navigate the complexities of information security with confidence.

R

Contact Details:

Rhymetec Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land GRC Analyst

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Rhymetec, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Rhymetec

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Rhymetec. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace GRC Analyst

Cloud Security
Compliance Management
Risk Assessment
Incident Response
Business Continuity Planning
Disaster Recovery
Security Frameworks

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Rhymetec insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Rhymetec that you’re committed to staying ahead in the game.

How to prepare for a job interview at Rhymetec

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Rhymetec to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Rhymetec.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.