Cyber Essentials Plus & GRC Analyst – Hybrid Liverpool

Cyber Essentials Plus & GRC Analyst – Hybrid Liverpool

Liverpool Full-Time 50000 - 65000 Β£ / year (est.) No working from home possible
Venturi

At a Glance

  • Tasks: Lead cyber security projects and enhance risk management frameworks in a dynamic environment.
  • Company: Major UK transportation and infrastructure organisation focused on cyber security.
  • Benefits: Competitive pay, hybrid work model, and quick hiring process.
  • Other info: Immediate start available with excellent career growth opportunities.
  • Why this job: Make a real impact in cyber security while working with cutting-edge technology.
  • Qualifications: Experience in cyber security, risk management, and strong stakeholder engagement skills.

The predicted salary is between 50000 - 65000 Β£ per year.

  • Cyber Security Analysts – Cyber Essentials Plus & GRC
  • 6-month contracts | Outside IR35 | Liverpool hybrid

We’re partnering with a major UK transportation and infrastructure organisation that is strengthening its cyber security capability as it expands into new regulated and defence-related sectors.

They are looking to hire multiple Cyber Security Analysts across two immediate workstreams:

  • Cyber Essentials Plus and technical remediation
  • Cyber risk management and GRC

Both roles offer the opportunity to take genuine ownership of a defined security programme, working closely with technical teams and senior stakeholders to build and improve capability rather than simply maintain an existing service.

  • Initial six-month contract
  • Liverpool-based
  • Onsite every Monday and Tuesday
  • Immediate start preferred
  • One-stage interview process
  • Quick decisions for suitable candidates
  • Role 1: Cyber Security Analyst

The organisation has completed an initial Cyber Essentials Plus gap assessment and now requires an experienced contractor to take ownership of the remediation and certification programme.

You will coordinate technical improvements, manage evidence and submissions, support the external assessment process and drive any findings through to closure.

This is not a SOC monitoring or Penetration Tester role. It requires someone who understands Cyber Essentials Plus and can lead the delivery activity surrounding it.

Responsibilities

  • Lead the Cyber Essentials Plus remediation programme
  • Review and progress an existing security gap analysis
  • Coordinate remediation across infrastructure, network and endpoint teams
  • Manage issues relating to patching, unsupported systems and secure configuration
  • Coordinate firewalling and network segmentation improvements
  • Gather and validate technical evidence
  • Manage statements and attestations within the submission
  • Liaise with assessors and respond to assessment queries
  • Support the scoping and coordination of penetration testing
  • Manage post-test findings, remediation and retesting
  • Maintain clear actions, ownership and delivery deadlines
  • Previous delivery of Cyber Essentials or Cyber Essentials Plus
  • Experience supporting a submission through to certification
  • Technical security remediation experience
  • Vulnerability and patch-management knowledge
  • Experience working with infrastructure, network and endpoint teams
  • Experience coordinating security testing and remediation
  • Ability to challenge stakeholders and drive actions through to completion

The second contractor will help establish a formal cyber risk management capability.

The organisation currently needs to create its cyber risk framework, risk assessment methodology, risk register, supporting policy and governance structure.

Although titled as an Analyst position, this role requires someone capable of working independently, drafting the approach and taking ownership of implementation.

Responsibilities

  • Design and implement a cyber risk management framework
  • Develop a consistent risk assessment methodology
  • Create and maintain a cyber risk register
  • Define risk scoring, ownership, treatment and escalation processes
  • Draft cyber risk policies, standards and supporting procedures
  • Conduct cyber and information security risk assessments
  • Establish governance forums and terms of reference
  • Prepare and facilitate cyber risk governance meetings
  • Work with technical and business stakeholders to assign and manage risks
  • Support risk assessments across IT and operational environments
  • Help embed a repeatable and sustainable risk-management process
  • Cyber or information security risk management
  • Strong knowledge of ISO 27001 and ISO 27005
  • Experience building or materially improving a cyber risk framework
  • Experience creating risk assessment methodologies
  • Policy and framework drafting experience
  • Experience establishing and running governance forums
  • Strong stakeholder-management and facilitation skills
  • Ability to translate technical findings into meaningful business risks

Desirable experience across either role

Experience in any of the following would be beneficial

  • Operational Technology
  • Critical National Infrastructure
  • NIS-regulated environments
  • Cyber Assessment Framework
  • Defence or government programmes
  • Transport, logistics, utilities, engineering or manufacturing
  • Complex, multi-site organisations

Sector experience is not essential where candidates can demonstrate strong, transferable delivery experience.

Applicants must be able to attend the Liverpool site 2 times per week.

Please apply with an up-to-date CV or contact me directly to discuss which workstream best matches your experience.

#J-18808-Ljbffr

Cyber Essentials Plus & GRC Analyst – Hybrid Liverpool employer: Venturi

As an Azure Integrations Engineer in Manchester, you'll be part of a dynamic team driving a significant technology transformation. Our company fosters a collaborative work culture that values innovation and professional growth, offering hybrid working arrangements to ensure a healthy work-life balance. With opportunities for continuous learning and development, you will play a crucial role in shaping modern cloud-native integrations while enjoying the benefits of working in a vibrant city known for its rich culture and community spirit.

Venturi

Contact Details:

Venturi Recruitment Team

We think you need these skills to ace Cyber Essentials Plus & GRC Analyst – Hybrid Liverpool

Cyber Essentials Plus
Technical Remediation
Cyber Risk Management
GRC (Governance, Risk Management, and Compliance)
Vulnerability Management
Patch Management
Network Segmentation