Cyber Security GRC Analyst in Redhill

Cyber Security GRC Analyst in Redhill

Redhill Full-Time 45000 - 55000 £ / year (est.) No working from home possible
Tiger Resourcing Group

At a Glance

  • Tasks: Support cybersecurity assurance and manage risks during a major operational handover programme.
  • Company: Join a leading organisation focused on cybersecurity governance and compliance.
  • Benefits: Competitive salary, professional development, and opportunities for travel.
  • Other info: Collaborative environment with strong career growth potential.
  • Why this job: Make a real impact in cybersecurity while working on exciting transition projects.
  • Qualifications: Experience in cybersecurity governance and relevant certifications required.

The predicted salary is between 45000 - 55000 £ per year.

Cybersecurity GRC Analyst – Operational Handover Programme

Location

Redhill, Surrey

Working Pattern

Full-time

Role Overview

We are seeking an experienced Cybersecurity Governance, Risk and Compliance Analyst to support cybersecurity assurance, audit and risk-management activities across a major operational handover programme.

The role will provide oversight of the security implications associated with the transfer of services and systems, with particular focus on identifying and managing risks created during the transition process.

You will also support knowledge transfer and provide training to the incoming organisation’s security, risk-management and audit teams.

This is a key role within the programme, ensuring that appropriate cybersecurity controls, certifications and governance processes remain effective throughout the transition.

Key Responsibilities

  • Conduct cybersecurity risk assessments and security-control reviews across business applications, infrastructure and computer installations being transferred as part of the handover programme.
  • Identify security risks and recommend appropriate remediation or risk-treatment actions to programme management.
  • Maintain ISO 27001 and PCI-DSS certification and recertification activities throughout the programme.
  • Maintain programme and handover cybersecurity risk registers and associated treatment plans.
  • Ensure agreed security-support processes are followed throughout the handover programme.
  • Conduct ad-hoc internal security audits across relevant security-control areas, working closely with quality assurance, technology and service teams.
  • Document security non-compliances, agree remediation actions with the programme leadership team and monitor progress through to completion.
  • Design and, where required, implement security policies, standards, guidelines, processes and procedures.
  • Ensure continued compliance with the organisation’s Information

Security Management System, ISO 27001, PCI-DSS, contractual obligations and relevant legislation.

  • Review handover-related change requests and assess their potential impact on existing security controls and mechanisms.
  • Ensure planned technical changes do not unnecessarily compromise or weaken existing cybersecurity controls.
  • Produce clear security, risk, compliance and audit reporting for the programme leadership team.
  • Provide input into wider cybersecurity, business-continuity and contingency-planning activities.
  • Support knowledge transfer and training for the incoming organisation’s security risk-management and audit personnel.
  • Work collaboratively with internal teams, customers, suppliers, security vendors and programme partners.
  • Travel to other operational sites and data centres where required.
  • Comply with all relevant company policies, including the code of conduct, quality, security, health and safety, and environmental procedures.

Essential Qualifications

A recognised information-security certification, such as

  • CISA, CISM or CRISC
  • CISSP
  • BCS CISMP
  • IISP certification or equivalent

Desirable Qualifications

  • Degree in information security, computer science, engineering, mathematics, encryption or another relevant discipline, or equivalent professional experience.
  • Information privacy or data-protection qualifications, such as

CIPP/E or CIPM.

  • Payment Card Industry Security Standards Council certification, such as ISA or QSA.
  • ITIL, PRINCE2 Foundation or TOGAF certification.
  • Relevant infrastructure or networking vendor certifications.

Essential Experience and Knowledge

  • Strong experience within cybersecurity governance, risk, audit and compliance management.
  • Experience working within a complex IT, technology or operational environment.
  • Thorough understanding of information-security audit methodologies and control-assessment techniques.
  • Experience operating and auditing an ISO 27001-compliant

Information Security Management System.

  • Experience managing PCI-DSS certification, recertification and audit activities.
  • Experience implementing or operating within a PCI-DSS-compliant security environment.
  • Strong knowledge of cybersecurity technologies, controls, frameworks and risk-management methodologies.
  • Experience assessing cybersecurity implications within formal change-management processes.
  • Demonstrable stakeholder-management experience, including leading consultations, workshops and presentations.
  • Experience creating and maintaining security policies, standards, procedures, guidance, processes and awareness materials.
  • Experience managing security risks, remediation plans, audit findings and compliance actions through to completion.

Desirable Experience

  • Experience working with additional security, risk and compliance frameworks, including:
  • PCI P2PE
  • PCI POI PTS
  • NIST security and risk frameworks
  • GDPR and wider data-protection legislation
  • Experience within transactional revenue, embedded systems, smartcards, mobile payments, open-payment systems or EMVCo environments.
  • Experience using cybersecurity governance, risk and compliance platforms.
  • Experience using IT service-management tools.
  • Familiarity with vulnerability-management and security-operations tooling.
  • Experience working with quality-management systems and external audit standards such as ISO 9001.
  • Previous experience supporting a complex operational handover, transition or service-transfer programme.

Cyber Security GRC Analyst in Redhill employer: Tiger Resourcing Group

At Tiger Resourcing Group, we pride ourselves on being an excellent employer that fosters a collaborative and innovative work culture. Our team members enjoy competitive benefits, opportunities for professional growth, and the chance to work on cutting-edge technology in the vibrant UK tech landscape. Join us to be part of a supportive environment where your contributions are valued and your career can thrive.

Tiger Resourcing Group

Contact Details:

Tiger Resourcing Group Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Security GRC Analyst in Redhill

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Tiger Resourcing Group, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Tiger Resourcing Group

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Tiger Resourcing Group. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Cyber Security GRC Analyst in Redhill

Cybersecurity Governance
Risk Management
Compliance Management
ISO 27001
PCI-DSS
Security Risk Assessments
Internal Security Audits

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Tiger Resourcing Group insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Tiger Resourcing Group that you’re committed to staying ahead in the game.

How to prepare for a job interview at Tiger Resourcing Group

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Tiger Resourcing Group to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Tiger Resourcing Group.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.