At a Glance
- Tasks: Support cyber security governance, risk management, and compliance activities.
- Company: Join South West Water, a leader in the UK water sector.
- Benefits: Up to £36,000 salary, generous holidays, health benefits, and ongoing training.
- Why this job: Make a real impact on cyber security while working towards a greener future.
- Qualifications: Strong understanding of cyber security principles and experience in audits.
- Other info: Diverse and inclusive culture with excellent career growth opportunities.
The predicted salary is between 28800 - 43200 £ per year.
Powered by Water, Driven by Purpose. South West Water keeps the South West flowing with safe, reliable drinking water and wastewater services across some of the UK’s most stunning landscapes. We’re proud to be part of Pennon Group, a leader in the UK water sector, working towards a greener future. Our goal? Net zero by 2030, supported by partnerships with Wildlife Trusts and National Parks.
Are you passionate about Cyber Security Governance, Risk Management and Compliance? We are seeking a proactive and knowledgeable Cyber Security GRC Analyst (up to £36,000 doe) to support and strengthen our organisation’s security posture. In this role, you will help ensure ongoing compliance with key security standards, manage governance frameworks, and contribute to the resilience of our cyber environment.
About the Role: As a Cyber Security GRC Analyst, you will play a central role in driving our governance, risk, and compliance activities. Reporting to the Cyber Security Compliance Manager, you will support internal reviews, risk assessments, policy development, and ongoing compliance with frameworks such as ISO 27001 and NIS Regulations. You’ll collaborate across the business to ensure risks are effectively managed, controls are embedded, and our security standards remain robust and continually improved.
Key Responsibilities:
- Plan, conduct, and document internal ISO 27001 audits across all areas of the Information Security Management System (ISMS), ensuring all controls and processes are regularly reviewed for effectiveness and compliance.
- Evaluate the effectiveness of information security policies, procedures, and controls, and identify areas for improvement or non-compliance.
- Develop and maintain an annual audit schedule to ensure comprehensive coverage of ISO 27001 requirements and continual improvement of the ISMS.
- Conduct and document internal audits and assessments aligned to ISO 27001 and NIS Regulations.
- Contribute to the development and maintenance of cyber security policies, standards, and procedures.
- Assist in maintaining the IT Security risk register, including identifying, assessing, and monitoring.
- Work closely with business stakeholders to gather evidence, close audit findings, and track corrective actions.
- Support security assurance activities, including penetration tests, vulnerability scans, and third party reviews.
- Promote strong cyber security awareness and contribute to a positive security culture.
- Ensure third party suppliers meet contractual and regulatory security requirements.
- Maintain compliance with relevant legislation and industry standards.
- Monitor adherence and enforce policies to safeguard organisational data.
- Ensure that data protection practices meet legal, regulatory, and standards requirements.
Why Governance, Risk & Compliance Matters: Effective GRC practices are essential for safeguarding sensitive information, maintaining customer trust, and protecting the organisation from regulatory, operational, and reputational risks. Regular internal ISO 27001 audits not only ensure ongoing certification but also drive continual improvement and resilience in our information security practices.
What We’re Looking For:
- Full UK driving licence.
- Strong understanding of cyber security principles, risks, and regulatory requirements.
- Familiarity with ISO 27001 or NIS or other cyber security standards and frameworks.
- Experience in conducting audits or assessments.
- Thrives in environments where clear governance, process adherence, and continual improvement are valued.
- Values the opportunity to help teams prepare for external audits or certifications.
- Excellent communication and relationship building skills.
- Excellent attention to detail.
- A collaborative, self-motivated approach with strong organisational abilities.
- Eligible for UK Government Security Clearance (SC).
Why You'll Love Working With Us: We know that the support and commitment of our staff is key to our success so you will receive the opportunity for ongoing development and training for a long-term career with us. In return, we offer an excellent range of benefits including:
- Annual salary of up to £36,000 depending upon experience.
- Generous holiday allowance plus bank holidays.
- A discretionary Bonus.
- Competitive Contributory Pension.
- Share-save Scheme.
- Various health benefits.
- Wellbeing support programmes.
- A range of Group Discounts.
- Cycle to Work Scheme.
- Financial support services.
- And plenty more!
Closing Date: 16th February. Please note that the successful candidate will be subject to a mandatory DBS check as part of the onboarding process. Be yourself, we like it that way. Together, we will build a culture of belonging, where inclusion is instinctive. Diversity is our strength and a reflection of our communities. We care, we value everyone, we celebrate uniqueness. Our core values which are essential to our success are:
- Be Rock Solid - Build trust and be trusted. Be the one we all look to and can depend on.
- Be You - We want you to bring your best every day. Be yourself and make your mark in your individual way.
- Be the Future - Embrace change. Drive Progress. Own the challenge.
GRC Analyst in Exeter employer: Source4b
Contact Detail:
Source4b Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land GRC Analyst in Exeter
✨Tip Number 1
Network like a pro! Reach out to current employees at South West Water on LinkedIn. Ask them about their experiences and any tips they might have for landing the GRC Analyst role. Personal connections can give you an edge!
✨Tip Number 2
Prepare for the interview by brushing up on ISO 27001 and NIS Regulations. Be ready to discuss how you've applied these frameworks in past roles. Show us your passion for cyber security and how you can contribute to our mission!
✨Tip Number 3
Don’t just wait for job openings—create your own opportunities! Follow South West Water on social media and engage with our posts. This shows your interest and keeps you on our radar when new positions pop up.
✨Tip Number 4
When you apply, make sure to highlight your collaborative skills. We value teamwork, so share examples of how you've worked with others to achieve compliance goals or improve security practices. Let’s see that proactive spirit!
We think you need these skills to ace GRC Analyst in Exeter
Some tips for your application 🫡
Tailor Your CV: Make sure your CV reflects the skills and experiences that align with the GRC Analyst role. Highlight your knowledge of cyber security principles and any relevant audit experience to catch our eye!
Craft a Compelling Cover Letter: Use your cover letter to tell us why you're passionate about Cyber Security Governance, Risk Management, and Compliance. Share specific examples of how you've contributed to similar projects in the past.
Showcase Your Attention to Detail: In the world of GRC, attention to detail is key! Make sure your application is free from typos and clearly structured. This will demonstrate your commitment to quality and thoroughness.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for this exciting opportunity to join our team!
How to prepare for a job interview at Source4b
✨Know Your Standards
Familiarise yourself with ISO 27001 and NIS Regulations before the interview. Be ready to discuss how these frameworks apply to the role of a GRC Analyst and share any relevant experiences you have in conducting audits or assessments.
✨Showcase Your Communication Skills
As a GRC Analyst, you'll need to collaborate with various stakeholders. Prepare examples of how you've effectively communicated complex information or built relationships in previous roles. This will demonstrate your ability to promote a positive security culture.
✨Be Proactive About Cyber Security
Express your passion for cyber security by discussing current trends or challenges in the field. Show that you're not just knowledgeable but also enthusiastic about contributing to the organisation's security posture and compliance efforts.
✨Prepare Questions
Have a few thoughtful questions ready to ask at the end of the interview. Inquire about the company's approach to risk management or how they support ongoing development for their staff. This shows your genuine interest in the role and the organisation.