Governance Risk & Compliance Analyst in Aberdeen

Governance Risk & Compliance Analyst in Aberdeen

Aberdeen Full-Time 40000 - 50000 £ / year (est.) Home office (partial)
Sword Group

At a Glance

  • Tasks: Join our team to manage governance, risk, and compliance activities across key regulations.
  • Company: Sword, a leader in business technology solutions for the Energy, Public, and Finance sectors.
  • Benefits: Enjoy flexible working, personalised career development, and a fantastic benefits package.
  • Other info: We value diversity and encourage all applicants to apply, regardless of experience.
  • Why this job: Make a real impact in cybersecurity while growing your skills in a supportive environment.
  • Qualifications: Experience in governance, risk, compliance, or cybersecurity is essential.

The predicted salary is between 40000 - 50000 £ per year.

Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving real transformation change within our clients. We use proven technology, specialist teams and domain expertise to build solid technical foundations across platforms, data and business applications. We have a passion for using technology to solve business problems, working in partnership with our clients to help in achieving their goals.

We are delighted to present a newly created opportunity for a Governance, Risk & Compliance Analyst to join our internal security team. Reporting directly to the Sword Group CISO, you will help run and maintain Sword’s governance, risk, and compliance activities across key regulatory, certification, and client requirements. This is a hands-on role suited to someone who can take ownership, drive progress, and deliver practical outcomes across compliance, risk management, and assurance. You will support and maintain compliance with frameworks and obligations including GDPR, NIS2, ISO 27001, the UK Cyber Security Resilience Bill, Cyber Essentials, and risk management, while contributing to continuous improvement across Sword’s security and compliance practices. We are looking for someone with enough practical experience to lead and coordinate key compliance activities globally, particularly across GDPR, ISO 27001, and Cyber Essentials.

Key Responsibilities:

  • Security Governance: Support the development, maintenance, and improvement of security policies, standards, and procedures, helping to keep Sword aligned with ISO 27001, NIS2, and other relevant obligations.
  • Risk Management: Support and maintain security risk management activities across suppliers, projects, and internal services, helping to identify risks, track treatment actions, and drive progress to completion.
  • Legal, Regulatory, and Contractual Requirements: Help track, interpret, and maintain compliance with relevant legal, regulatory, client, and contractual obligations, including GDPR, NIS2, and the UK Cyber Security Resilience Bill.
  • Data Protection: Lead and coordinate ongoing GDPR compliance activities globally by maintaining records, improving processes, working with stakeholders, and ensuring actions are progressed and completed.
  • Third-Party and Supply Chain Security: Support supplier and supply chain risk management activities, including reviews, due diligence, follow-up actions, and the maintenance of appropriate records and evidence.
  • Certification and Compliance Support: Lead and coordinate Sword’s ISO 27001 certification and Cyber Essentials activities, including evidence gathering, control tracking, stakeholder coordination, and follow-up of remediation actions.
  • Audit and Assurance: Support internal and external audit activity by preparing evidence, coordinating responses, tracking findings, and helping ensure actions are completed.
  • Business Resilience Support: Contribute to the maintenance and improvement of business continuity and disaster recovery arrangements, including documentation, review activity, and support for testing exercises.
  • Security Culture and Awareness: Support awareness, training, and communication activities that help colleagues understand and follow security policies, processes, and responsibilities.
  • Continuous Improvement: Take a practical, can-do approach to improving the GRC programme through steady progress, good organisation, and a focus on getting things done.

Requirements:

This role represents an outstanding opportunity for an individual with practical experience, or strong working knowledge, in governance, risk, compliance, or cyber security who is keen to keep building their expertise, takes ownership, and delivers results. You should have enough experience to lead and coordinate key compliance activities globally, particularly in GDPR, ISO 27001, and Cyber Essentials, with practical experience in running GDPR activities being essential. Supporting and maintaining governance, risk, and compliance activities aligned to industry standards and organisational objectives. Strong practical experience of frameworks, regulations, and obligations such as ISO 27001, GDPR, Cyber Essentials, NIS2, and the UK Cyber Security Resilience Bill, with the ability to apply these in a practical business context and coordinate related activities across a global organisation. Supporting risk assessments, control reviews, remediation tracking, and evidence management across projects, suppliers, and internal services. Experience contributing to audit, certification, or compliance activity, including evidence gathering, issue tracking, stakeholder coordination, and support for follow-up actions. Supporting supplier and supply chain assurance activity, including due diligence, review of responses, and follow-up of security actions. Good organisational, analytical, and problem-solving skills, with the ability to interpret requirements and help turn them into practical actions. Clear written and verbal communication skills, with the ability to work effectively with stakeholders across the business. Experience in a similar governance, risk, compliance, information security, or assurance role would be beneficial.

Qualifications and Personal Skills:

Relevant qualifications or certifications in ISO 27001, GDPR, Cyber Essentials, risk, audit, or information security would be beneficial, but practical experience leading and coordinating these activities globally is more important. Takes ownership, works proactively, and has a can-do attitude with a strong focus on following through and getting things done. Keen to learn, develop, and progress a career in governance, risk, and compliance. Well organised and able to manage competing priorities while maintaining momentum and attention to detail. Communicates clearly and works well with technical and non-technical colleagues to drive practical outcomes.

Benefits:

At Sword, our core values and culture are based on caring about our people, investing in training and career development, and building inclusive teams where we are all encouraged to contribute to achieve success. We offer comprehensive benefits designed to support your professional development and enhance your overall quality of life. In addition to a Competitive Salary, here's what you can expect as part of our benefits package:

  • Personalised Career Development: We create a development plan customised to your goals and aspirations, with a range of learning and development opportunities within a culture that encourages growth.
  • Flexible working: Flexible work arrangements to support your work-life balance. We can’t promise to always be able to meet every request, however, are keen to discuss your individual preferences to make it work where we can.
  • A Fantastic Benefits Package: This includes generous annual leave allowance, enhanced family friendly benefits, pension scheme, access to private health, well-being, and insurance schemes.

At Sword we are dedicated to fostering a diverse and inclusive workplace and are proud to be an equal opportunities employer, ensuring that all applicants receive fair and equal consideration for employment, regardless of whether they meet every requirement. If you don’t tick all the boxes but feel you have some of the relevant skills and experience we’re looking for, please do consider applying and highlight your transferable skills and experience. We embrace diversity in all its forms, valuing individuals regardless of age, disability, gender identity or reassignment, marital or civil partner status, pregnancy or maternity status, race, colour, nationality, ethnic or national origin, religion or belief, sex, or sexual orientation. Your perspective and potential are important to us. If we can do anything to help make the hiring process more accessible, please let our talent acquisition team know when you apply so we can support any adjustments.

Governance Risk & Compliance Analyst in Aberdeen employer: Sword Group

Sword is an exceptional employer that prioritises the growth and well-being of its employees, offering personalised career development plans and a flexible working environment to support work-life balance. With a strong commitment to diversity and inclusion, Sword fosters a collaborative culture where every team member is encouraged to contribute to success while enjoying a comprehensive benefits package that enhances overall quality of life.

Sword Group

Contact Details:

Sword Group Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Governance Risk & Compliance Analyst in Aberdeen

Join Compliance Communities

Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!

Attend Industry Conferences

Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.

Leverage Your University Career Services

If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.

Showcase Your Knowledge Online

Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Sword Group looking for candidates who are engaged and informed.

We think you need these skills to ace Governance Risk & Compliance Analyst in Aberdeen

Governance Risk & Compliance
GDPR
ISO 27001
Cyber Essentials
NIS2
UK Cyber Security Resilience Bill
Risk Management

Some tips for your application 🫡

Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!

Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.

Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!

Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Sword Group. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!

How to prepare for a job interview at Sword Group

Master the Regulations

Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!

Show Your Analytical Skills

Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!

Know Your Tools

Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!

Align with Company Culture

Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Sword Group’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!