Governance, Risk and Compliance Analyst
Governance, Risk and Compliance Analyst

Governance, Risk and Compliance Analyst

London Full-Time 36000 - 60000 £ / year (est.) No home office possible
Go Premium
V

At a Glance

  • Tasks: Join us as a GRC Analyst to ensure compliance and manage IT risk.
  • Company: We are a forward-thinking organisation focused on security and compliance.
  • Benefits: Enjoy flexible working options, professional development, and a collaborative culture.
  • Why this job: Make an impact by enhancing security practices and working with diverse teams.
  • Qualifications: Bachelor’s degree in Information Security and 2-3 years of relevant experience required.
  • Other info: Experience with GRC platforms and knowledge of privacy laws is a plus.

The predicted salary is between 36000 - 60000 £ per year.

Job Profile

We are seeking a dedicated and detail-oriented Governance, Risk and Compliance (GRC) Analyst to join our team. In this role, you will need to ensure that we meet regulatory obligations, align with frameworks and security standards, and manage and maintain IT risk across the organization and supply chain. You will collaborate with cross-functional teams within the organization as well work closely with external vendors, auditors and clients to embed GRC practices, maintain security controls and reassure adherence to frameworks and policies.

Your Responsibilities

  • Maintain and improve our Information Security Management System (ISMS).
  • Monitor compliance with security frameworks.
  • Support the IT and Information Security policy lifecycle.
  • Maintain the IT Security risk register.
  • Manage risk and track risk mitigation across the various Teams within the organization’s technology department.
  • Conduct security reviews and risk assessments of suppliers and partners.
  • Complete audits for clients and assist in the review process with their corresponding audit teams.
  • Coordinate internal and external audits.
  • Audit internal processes for compliance.
  • Work closely with the Privacy Analyst to assist with DPIAs, RoPAs and data subject workflows.
  • Maintain the GRC platform.
  • Maintain security awareness training platform and assist in the delivery of relevant training.
  • Assist with the creation and maintenance of metrics relevant to control effectiveness and maturity.
  • Stay up-to-date with relevant frameworks and regulatory requirements.

Required Skills, Qualifications, and Experience

  • Bachelor’s degree in Information Security, or related field. Relevant certifications (e.g., ISO27001 Lead Implementer, CIPP, CRISC etc.) are a plus.
  • At least 2-3 years of experience in GRC, Information Security, or related fields.
  • Hands-on experience with GRC platforms, OneTrust is a bonus.
  • Experience with risk management and risk assessment methodologies.
  • Knowledge of frameworks like CIS 8.0, ISO 27001, NIST CSF, GDPR, NIS2, or similar.
  • Experience in auditing, reporting, and investigating privacy breaches.
  • Ability to interpret and apply complex legal and regulatory requirements.
  • Experience working with cross-functional teams to implement privacy measures.
  • Providing clear guidance and training to employees on privacy standards.
  • Exposure to cloud-native environments and associated risk controls.
  • Exposure in Artificial Intelligence systems and associated risk controls is a bonus.
  • Strong understanding of privacy laws and frameworks (e.g., GDPR, CCPA).

#J-18808-Ljbffr

Governance, Risk and Compliance Analyst employer: VistaJet

Join a forward-thinking organisation that prioritises employee development and fosters a collaborative work culture. As a Governance, Risk and Compliance Analyst, you will benefit from comprehensive training opportunities, a supportive team environment, and the chance to work on impactful projects that enhance our security posture. Located in a vibrant area, our company offers a dynamic workplace where innovation thrives and your contributions are valued.
V

Contact Detail:

VistaJet Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Governance, Risk and Compliance Analyst

✨Tip Number 1

Familiarise yourself with the specific frameworks and regulations mentioned in the job description, such as ISO 27001 and GDPR. This knowledge will not only help you during interviews but also demonstrate your commitment to the role.

✨Tip Number 2

Network with professionals in the GRC field through platforms like LinkedIn. Engaging with industry groups or forums can provide insights into current trends and challenges, making you a more informed candidate.

✨Tip Number 3

Consider obtaining relevant certifications if you haven't already. Certifications like ISO27001 Lead Implementer or CRISC can significantly enhance your profile and show your dedication to professional development.

✨Tip Number 4

Prepare for potential scenario-based questions in interviews by thinking about past experiences where you've managed risk or compliance issues. Being able to articulate these experiences clearly will set you apart from other candidates.

We think you need these skills to ace Governance, Risk and Compliance Analyst

Information Security Management System (ISMS)
Regulatory Compliance
Risk Management
Risk Assessment Methodologies
Security Frameworks (CIS 8.0, ISO 27001, NIST CSF, GDPR, NIS2)
Auditing Skills
Reporting Skills
Privacy Breach Investigation
Cross-Functional Collaboration
GRC Platforms (OneTrust)
Data Protection Impact Assessments (DPIAs)
Records of Processing Activities (RoPAs)
Security Awareness Training
Metrics Creation and Maintenance
Legal and Regulatory Interpretation
Cloud-Native Environment Risk Controls
Artificial Intelligence Risk Controls
Strong Understanding of Privacy Laws (GDPR, CCPA)

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in Governance, Risk and Compliance. Emphasise any specific projects or roles where you managed IT risk, conducted audits, or worked with security frameworks.

Craft a Compelling Cover Letter: In your cover letter, express your passion for GRC and detail how your skills align with the job requirements. Mention any relevant certifications and your experience with GRC platforms, especially if you have hands-on experience with OneTrust.

Showcase Relevant Skills: Clearly outline your knowledge of frameworks like ISO 27001, NIST CSF, and GDPR in your application. Provide examples of how you've applied these frameworks in previous roles to demonstrate your expertise.

Highlight Collaboration Experience: Since the role involves working with cross-functional teams, include examples in your application that showcase your ability to collaborate effectively with different departments, external vendors, and clients.

How to prepare for a job interview at VistaJet

✨Know Your Frameworks

Familiarise yourself with key frameworks like ISO 27001, NIST CSF, and GDPR. Be prepared to discuss how you've applied these in previous roles, as this will demonstrate your understanding of compliance and risk management.

✨Showcase Your Experience

Highlight your hands-on experience with GRC platforms, especially if you've worked with OneTrust. Share specific examples of how you've managed risks or conducted audits, as this will illustrate your practical knowledge.

✨Prepare for Scenario Questions

Expect scenario-based questions that assess your problem-solving skills in real-world situations. Think about past experiences where you had to navigate complex regulatory requirements or manage a compliance issue.

✨Emphasise Collaboration Skills

Since the role involves working with cross-functional teams, be ready to discuss how you've successfully collaborated with different departments. Highlight any experience you have in training employees on compliance standards, as this shows your ability to communicate effectively.

Governance, Risk and Compliance Analyst
VistaJet
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

V
  • Governance, Risk and Compliance Analyst

    London
    Full-Time
    36000 - 60000 £ / year (est.)

    Application deadline: 2027-08-01

  • V

    VistaJet

Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>