At a Glance
- Tasks: Support cybersecurity governance, risk, and compliance activities for leading clients.
- Company: Join UBDS Group, a dynamic and innovative tech organisation.
- Benefits: Enjoy competitive salary, private medical cover, and generous holiday allowance.
- Other info: Opportunities for training, mentorship, and career growth in a forward-thinking culture.
- Why this job: Make a real impact on cybersecurity while developing your skills in a collaborative environment.
- Qualifications: 3-5 years in Information Security or related fields; strong communication skills required.
The predicted salary is between 50000 - 65000 £ per year.
We are seeking an experienced Information Security Analyst to support the delivery of governance, risk, and compliance (GRC) services for one of our leading clients. Working closely with senior stakeholders, technology teams, and security leadership, you will play a key role in strengthening the organisation's cyber security posture through effective risk management, compliance assurance, and security governance activities. You will support the implementation and maintenance of recognised security frameworks and standards while helping to drive security improvements across business and technology functions. This is an excellent opportunity for a security professional, who is comfortable operating in a client-facing environment and can provide pragmatic, risk-based security advice.
Key Responsibilities
- Support the delivery of cybersecurity governance, risk, and compliance activities, ensuring alignment with frameworks including ISO 27001, NIST Cybersecurity Framework, Cyber Essentials, and GovAssure.
- Conduct information security risk assessments across business processes, programmes, projects, technology platforms, and third-party suppliers.
- Maintain security risk registers, track remediation actions, and support the effective management of cyber risk across business and technology functions.
- Produce high-quality security documentation, including policies, standards, compliance evidence, assessment reports, and executive-level reporting.
- Support internal and external audits, control reviews, assurance activities, and compliance assessments.
- Facilitate workshops and engage with stakeholders across technical, programme, operational, and leadership teams to gather requirements, collect evidence, and drive security initiatives.
- Support supplier assurance and third-party risk management activities.
- Assist with the development and continuous improvement of security governance processes and controls.
- Support in embedding security best practices, data governance, and Secure by Design principles across recovery, transformation, and operational workstreams.
- Contribute to security awareness, risk reporting, and governance activities across the client environment.
Skills & Experience
Essential
- 3–5 years' experience in Information Security, Cyber Security, Governance, Risk & Compliance, IT Audit, or Risk Management roles.
- Experience conducting information security risk assessments and control reviews.
- Strong understanding of information security governance and risk management principles.
- Working knowledge of ISO 27001 and information security management systems.
- Familiarity with security frameworks and standards including NIST Cybersecurity Framework and Cyber Essentials.
- Experience supporting audit, compliance, or assurance activities.
- Strong stakeholder engagement and communication skills.
- Excellent report writing, documentation, and presentation capabilities.
- Ability to communicate complex security concepts to both technical and non-technical audiences.
- Able to work in London 2-3 days per week.
Desirable
- Experience working within government, public sector, regulated, or enterprise environments.
- Knowledge of GovAssure assessments and public sector security requirements.
- Familiarity with cloud environments including Microsoft Azure and AWS.
- Experience using GRC platforms and risk management tooling.
- Understanding of Secure by Design and security architecture principles.
Certifications
One or more of the following would be advantageous: ISO 27001 Lead Implementer or Lead Auditor, Security+, CGRC, CISA, CRISC, CISSP (or Associate CISSP).
Benefits
Professionals choose to grow their careers at UBDS Group for its reputation as a dynamic and forward-thinking organisation that is deeply committed to both innovation and employee development. At UBDS Group, employees are given unique opportunities to work on cutting-edge projects across a diverse range of industries, exposing them to new challenges and learning opportunities that are pivotal for professional growth. The Group’s culture emphasises continuous improvement, offering ample training programs, mentorship, and the chance to gain certifications that enhance their skills and marketability. UBDS Group fosters a collaborative environment where creativity and innovation are encouraged, allowing employees to contribute ideas and solutions that have a tangible impact on the company and its clients. This combination of professional development, a culture of innovation, and the opportunity to make meaningful contributions makes UBDS Group an attractive place for those looking to advance their careers and be at the forefront of technological and operational excellence.
Employee Benefits
- Training – All team members are offered a number of options in terms of personal development, whether it is technical led, business acumen or methodologies.
- Private medical cover for you and your spouse/partner, offered via Vitality.
- Discretionary bonus based on a blend of personal and company performance.
- Holiday – You will receive 25 Days holiday, plus 1 day for Birthday and 1 day for your work anniversary in addition to UK bank holidays.
- Electric Vehicle leasing with salary sacrifice.
- Contributed Pension Scheme.
- Death in service cover.
About UBDS Group
At UBDS Group our mission is to support entrepreneurs who are setting new standards with technology solutions across cloud services, cybersecurity, data and AI, ensuring that every investment advances our commitment to innovation, making a difference, and creating impactful solutions for organisations and society.
Equal Opportunities
We are an equal opportunities employer and do not discriminate on the grounds of gender, sexual orientation, marital or civil partner status, pregnancy or maternity, gender reassignment, race, colour, nationality, ethnic or national origin, religion or belief, disability or age.
Information Security GRC Analyst in London employer: UBDS Group
UBDS Group is an exceptional employer, renowned for its commitment to innovation and employee development. With a collaborative work culture that encourages creativity, employees have the opportunity to engage in cutting-edge projects while benefiting from extensive training programs and mentorship. Located in London, the company offers a dynamic environment where professionals can thrive, advance their careers, and make meaningful contributions to both the organisation and its clients.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security GRC Analyst in London
✨Tip Number 1
Network like a pro! Reach out to your connections in the cybersecurity field and let them know you're on the hunt for an Information Security GRC Analyst role. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Get your interview game on point! Research common interview questions for GRC roles and practice your responses. Be ready to showcase your experience with frameworks like ISO 27001 and NIST, and don’t forget to highlight your stakeholder engagement skills.
✨Tip Number 3
Show off your expertise! Create a portfolio of your past work, including risk assessments and compliance documentation. This will not only demonstrate your skills but also give you something tangible to discuss during interviews.
✨Tip Number 4
Apply through our website! We’ve got some fantastic opportunities waiting for you at UBDS Group. By applying directly, you’ll ensure your application gets the attention it deserves, and you’ll be one step closer to joining a dynamic team committed to innovation.
We think you need these skills to ace Information Security GRC Analyst in London
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Information Security GRC Analyst role. Highlight your experience with frameworks like ISO 27001 and NIST, and showcase any relevant projects or achievements that align with the job description.
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your skills can help strengthen our clients' security posture. Be sure to mention your experience in risk assessments and stakeholder engagement.
Showcase Your Communication Skills:Since this role involves engaging with various stakeholders, make sure to demonstrate your strong communication skills in your application. Use clear and concise language, and if possible, include examples of how you've effectively communicated complex security concepts in the past.
Apply Through Our Website:We encourage you to apply through our website for a smoother application process. This way, we can easily track your application and ensure it gets the attention it deserves. Plus, it shows you're keen on joining us at StudySmarter!
How to prepare for a job interview at UBDS Group
✨Know Your Frameworks
Make sure you’re well-versed in the key security frameworks mentioned in the job description, like ISO 27001 and NIST. Brush up on how these frameworks apply to governance, risk, and compliance, as you’ll likely be asked to discuss them in detail.
✨Prepare Real-World Examples
Think of specific instances where you've conducted risk assessments or managed compliance activities. Be ready to share these examples during the interview to demonstrate your hands-on experience and problem-solving skills.
✨Engage with Stakeholders
Since the role involves working closely with various stakeholders, prepare to discuss how you’ve successfully engaged with different teams in the past. Highlight your communication skills and ability to convey complex security concepts to both technical and non-technical audiences.
✨Show Your Passion for Security
Express your enthusiasm for information security and continuous improvement. Discuss any relevant certifications you have or are pursuing, and mention how you stay updated on industry trends and best practices. This will show your commitment to the field and your potential value to the company.