At a Glance
- Tasks: Support risk management and compliance in a dynamic transport organisation.
- Company: Leading transport organisation with a focus on governance and risk.
- Benefits: Competitive salary, 5% bonus, hybrid work, and travel discounts.
- Other info: Great career growth and a supportive work culture.
- Why this job: Join a team making a real impact in information security and compliance.
- Qualifications: 4-5 years in governance, risk, or compliance roles; ISO27001/NIST knowledge.
The predicted salary is between 50000 - 55000 £ per year.
VIQU has partnered with a leading transport organisation to recruit a GRC Analyst to join their Finance and Information Security team. This is a fantastic opportunity for a GRC Analyst to take ownership of established governance frameworks, policies, and risk processes within a highly regulated environment. The GRC Analyst will play a key role in maintaining compliance, supporting audits, and embedding a strong risk-aware culture across the business.
Key Responsibilities of the GRC Analyst:
- Support and maintain the organisation’s risk management framework, including risk identification, assessment, and monitoring
- Facilitate risk assessments across business units and support mitigation planning
- Monitor risk trends, control effectiveness, and emerging threats, providing insights to senior stakeholders
- Support compliance programmes, ensuring adherence to regulatory and industry standards (e.g. ISO27001, NIST CSF)
- Coordinate internal and external audits, including evidence gathering and action tracking
- Contribute to governance policies, standards, and procedures development and review
- Produce clear governance and risk reports for leadership teams
- Support governance and assurance of technology change management processes
- Assist with risk, compliance, and security awareness initiatives across the organisation
Key Requirements of the GRC Analyst:
- 4-5 years experience in governance, risk, or compliance roles within regulated or critical environments
- Strong understanding of frameworks such as ISO27001 and NIST CSF
- Experience supporting audits, compliance reporting, and evidence management
- Ability to interpret regulatory requirements into practical controls and processes
- Excellent communication and stakeholder engagement skills
- Strong organisational skills with the ability to manage multiple priorities
- Experience within regulated sectors such as transport, utilities, financial services, or government
- Exposure to Operational Technology (OT) or Industrial Control Systems (ICS) (desirable)
- Relevant certifications (ISO27001 Lead Implementer/Auditor, CISMP, CRISC, CISM) (desirable)
- Degree in Information Security, Risk, Business, Law, or equivalent experience
Additional Information:
- Hybrid working: Initially 5 days onsite, reducing to 3 days onsite after probation
- 5% bonus
- 10% pension contribution
- Free Zone 1-6 travel for you and a nominated household member
- 75% discount on National Rail season tickets
Interview process: 2 stages (Face-to-face and virtual)
Apply today to speak with VIQU in confidence or contact Noah Yeoman at (url removed).
Hybrid GRC Analyst: ISO/NIST Focus + 5% Bonus employer: United Cerebral Palsy of Georgia
VIQU is an exceptional employer, offering a dynamic work culture that prioritises employee growth and development within the transport sector. With a strong focus on compliance and risk management, employees benefit from a hybrid working model, generous pension contributions, and significant travel discounts, making it an attractive place for professionals seeking meaningful and rewarding careers in Information Security.
Contact Details:
United Cerebral Palsy of Georgia Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Hybrid GRC Analyst: ISO/NIST Focus + 5% Bonus
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their governance frameworks and compliance needs. This will help you tailor your answers and show that you're genuinely interested in the role.
✨Tip Number 3
Practice makes perfect! Do mock interviews with friends or use online platforms. Focus on articulating your experience with ISO27001 and NIST CSF, as these are key for the GRC Analyst role.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who take the initiative to engage directly with us.
We think you need these skills to ace Hybrid GRC Analyst: ISO/NIST Focus + 5% Bonus
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the GRC Analyst role. Highlight your experience with ISO27001 and NIST CSF, and don’t forget to showcase your skills in risk management and compliance. We want to see how you can bring value to our team!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about governance and risk management. Share specific examples of your past experiences that align with the responsibilities listed in the job description. We love a good story!
Showcase Your Communication Skills:As a GRC Analyst, you'll need to engage with various stakeholders. Make sure your application reflects your excellent communication skills. Whether it's through your CV, cover letter, or any additional documents, clarity and professionalism are key!
Apply Through Our Website:We encourage you to apply directly through our website for the best chance of success. It’s super easy and ensures your application gets to the right people. Plus, we’re excited to see what you can bring to the table!
How to prepare for a job interview at United Cerebral Palsy of Georgia
✨Know Your Frameworks
Make sure you brush up on ISO27001 and NIST CSF before the interview. Being able to discuss these frameworks in detail will show that you understand the core of the role and can hit the ground running.
✨Prepare for Scenario Questions
Expect questions about how you've handled risk assessments or compliance issues in the past. Think of specific examples where you identified risks, implemented controls, or facilitated audits. This will demonstrate your practical experience.
✨Showcase Your Communication Skills
As a GRC Analyst, you'll need to engage with various stakeholders. Be ready to explain complex concepts in simple terms. Practise articulating your thoughts clearly and confidently, as this will be key during your interview.
✨Research the Company Culture
Understanding the transport organisation's values and culture can give you an edge. Tailor your responses to align with their mission and demonstrate how you can contribute to a strong risk-aware culture within the business.