GRC Analyst in Exeter

GRC Analyst in Exeter

Exeter Full-Time 35000 £ / year No home office possible
S

At a Glance

  • Tasks: Drive governance, risk, and compliance activities in cyber security.
  • Company: Join South West Water, a leader in the UK water sector.
  • Benefits: Up to £36,000 salary, generous holidays, health benefits, and training opportunities.
  • Why this job: Make a real impact on cyber security while supporting a greener future.
  • Qualifications: Understanding of cyber security principles and experience in audits.
  • Other info: Collaborative environment with excellent career growth and development.

Powered by Water, Driven by Purpose. South West Water keeps the South West flowing with safe, reliable drinking water and wastewater services across some of the UK’s most stunning landscapes. We’re proud to be part of Pennon Group, a leader in the UK water sector, working towards a greener future. Our goals? As well as lowering our carbon footprint, we’re working with partners to plant 300,000 trees, restore peatlands and support farmers and landowners to improve water quality and wildlife.

Are you passionate about Cyber Security Governance, Risk Management and Compliance? We are seeking a proactive and knowledgeable Cyber Security GRC Analyst (up to £36,000 doe) to support and strengthen our organisation's security posture. In this role, you will help ensure ongoing compliance with key security standards, manage governance frameworks, and contribute to the resilience of our cyber environment.

About the Role: As a Cyber Security GRC Analyst, you will play a central role in driving our governance, risk, and compliance activities. Reporting to the Cyber Security Compliance Manager, you will support internal reviews, risk assessments, policy development, and ongoing compliance with frameworks such as ISO 27001 and NIS Regulations. You’ll collaborate across the business to ensure risks are effectively managed, controls are embedded, and our security standards remain robust and continually improved.

Key Responsibilities:

  • Plan, conduct, and document internal ISO 27001 audits across all areas of the Information Security Management System (ISMS), ensuring all controls and processes are regularly reviewed for effectiveness and compliance.
  • Evaluate the effectiveness of information security policies, procedures, and controls, and identify areas for improvement or non-compliance.
  • Develop and maintain an annual audit schedule to ensure comprehensive coverage of ISO 27001 requirements and continual improvement of the ISMS.
  • Conduct and document internal audits and assessments aligned to ISO 27001 and NIS Regulations.
  • Contribute to the development and maintenance of cyber security policies, standards, and procedures.
  • Assist in maintaining the IT Security risk register, including identifying, assessing, and monitoring.
  • Work closely with business stakeholders to gather evidence, close audit findings, and track corrective actions.
  • Support security assurance activities, including penetration tests, vulnerability scans, and third party reviews.
  • Promote strong cyber security awareness and contribute to a positive security culture.
  • Ensure third party suppliers meet contractual and regulatory security requirements.
  • Maintain compliance with relevant legislation and industry standards.
  • Monitor adherence and enforce policies to safeguard organisational data. Ensures that data protection practices meet legal, regulatory, and standards requirements.

Why Governance, Risk & Compliance Matters: Effective GRC practices are essential for safeguarding sensitive information, maintaining customer trust, and protecting the organisation from regulatory, operational, and reputational risks. Regular internal ISO 27001 audits not only ensure ongoing certification but also drive continual improvement and resilience in our information security practices.

What We’re Looking For:

  • Full UK driving licence.
  • Strong understanding of cyber security principles, risks, and regulatory requirements.
  • Familiarity with ISO 27001 or NIS or other cyber security standards and frameworks.
  • Experience in conducting audits or assessments.
  • Thrives in environments where clear governance, process adherence, and continual improvement are valued.
  • Values the opportunity to help teams prepare for external audits or certifications.
  • Excellent communication and relationship building skills.
  • Excellent attention to detail.
  • A collaborative, self-motivated approach with strong organisational abilities.
  • Eligible for UK Government Security Clearance (SC).

Why You’ll Love Working With Us: We know that the support and commitment of our staff is key to our success so you will receive the opportunity for ongoing development and training for a long-term career with us. In return, we offer an excellent range of benefits including:

  • Annual salary of up to £36,000 depending upon experience.
  • Generous holiday allowance plus bank holidays.
  • A discretionary Bonus.
  • Competitive Contributory Pension.
  • Share-save Scheme.
  • Various health benefits.
  • Wellbeing support programmes.
  • A range of Group Discounts.
  • Cycle to Work Scheme.
  • Financial support services.
  • And plenty more!

GRC Analyst in Exeter employer: South West Water

At South West Water, we pride ourselves on being an excellent employer, offering a supportive work culture that values employee development and well-being. As part of the Pennon Group, we provide our GRC Analysts with opportunities to grow their careers while contributing to meaningful environmental initiatives in one of the UK's most beautiful regions. With competitive salaries, generous benefits, and a commitment to fostering a positive workplace, we invite you to join us in making a difference.
S

Contact Detail:

South West Water Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land GRC Analyst in Exeter

✨Tip Number 1

Network like a pro! Reach out to current employees at South West Water on LinkedIn or other platforms. Ask them about their experiences and any tips they might have for landing the GRC Analyst role.

✨Tip Number 2

Prepare for the interview by brushing up on ISO 27001 and NIS Regulations. We want you to show off your knowledge and how you can contribute to our governance, risk, and compliance activities.

✨Tip Number 3

Don’t just focus on your technical skills; highlight your communication and relationship-building abilities. We value collaboration, so be ready to share examples of how you've worked with teams in the past.

✨Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining our team at South West Water.

We think you need these skills to ace GRC Analyst in Exeter

Cyber Security Governance
Risk Management
Compliance
ISO 27001
NIS Regulations
Internal Audits
Information Security Management System (ISMS)
Policy Development
Risk Assessment
Communication Skills
Attention to Detail
Organisational Abilities
Stakeholder Engagement
Analytical Skills
Problem-Solving Skills

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the GRC Analyst role. Highlight your experience with cyber security principles, ISO 27001, and any relevant audits you've conducted. We want to see how your skills align with our goals!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Share your passion for cyber security and why you’re excited about working with us at South West Water. Let us know how you can contribute to our mission of a greener future.

Showcase Your Attention to Detail: As a GRC Analyst, attention to detail is key. In your application, make sure there are no typos or errors. This shows us that you take pride in your work and understand the importance of compliance and governance.

Apply Through Our Website: We encourage you to apply through our website for a smoother process. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates from our team!

How to prepare for a job interview at South West Water

✨Know Your Standards

Make sure you brush up on ISO 27001 and NIS Regulations before your interview. Understanding these frameworks will not only show your knowledge but also demonstrate your commitment to compliance and governance, which is crucial for the GRC Analyst role.

✨Showcase Your Audit Experience

Be ready to discuss any previous experience you have with conducting audits or assessments. Prepare specific examples of how you've evaluated policies or identified areas for improvement, as this will highlight your practical skills and attention to detail.

✨Communicate Effectively

Since excellent communication skills are a must, practice articulating your thoughts clearly. Think about how you can explain complex cyber security concepts in simple terms, as you'll need to collaborate with various stakeholders across the business.

✨Demonstrate Your Passion

Let your enthusiasm for cyber security and governance shine through. Share why you're passionate about protecting sensitive information and how you can contribute to fostering a positive security culture within the organisation.

GRC Analyst in Exeter
South West Water
Location: Exeter

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

S
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>