At a Glance
- Tasks: Join us as a GRC Analyst to ensure compliance and manage IT risks.
- Company: XO is a dynamic company focused on governance and security in technology.
- Benefits: Enjoy flexible working options, professional development opportunities, and a collaborative culture.
- Why this job: Make an impact by enhancing security practices and working with diverse teams.
- Qualifications: Bachelor’s degree in Information Security and 2-3 years of relevant experience required.
- Other info: Experience with GRC platforms and knowledge of privacy laws is a plus.
The predicted salary is between 36000 - 60000 £ per year.
We are seeking a dedicated and detail-oriented Governance, Risk and Compliance (GRC) Analyst to join our team. In this role, you will need to ensure that we meet regulatory obligations, align with frameworks and security standards, and manage and maintain IT risk across the organization and supply chain. You will collaborate with cross-functional teams within the organization as well work closely with external vendors, auditors and clients to embed GRC practices, maintain security controls and reassure adherence to frameworks and policies.
Your Responsibilities
- Maintain and improve our Information Security Management System (ISMS).
- Monitor compliance with security frameworks.
- Support the IT and Information Security policy lifecycle.
- Maintain the IT Security risk register.
- Manage risk and track risk mitigation across the various Teams within the organization’s technology department.
- Conduct security reviews and risk assessments of suppliers and partners.
- Complete audits for clients and assist in the review process with their corresponding audit teams.
- Coordinate internal and external audits.
- Audit internal processes for compliance.
- Work closely with the Privacy Analyst to assist with DPIAs, RoPAs and data subject workflows.
- Maintain the GRC platform.
- Maintain security awareness training platform and assist in the delivery of relevant training.
- Assist with the creation and maintenance of metrics relevant to control effectiveness and maturity.
- Stay up-to-date with relevant frameworks and regulatory requirements.
Required Skills, Qualifications, and Experience
- Bachelor’s degree in Information Security, or related field.
- Relevant certifications (e.g., ISO27001 Lead Implementer, CIPP, CRISC are a plus).
- At least 2-3 years of experience in GRC, Information Security, or related fields.
- Hands-on experience with GRC platforms, OneTrust is a bonus.
- Experience with risk management and risk assessment methodologies.
- Knowledge of frameworks like CIS 8.0, ISO 27001, NIST CSF, GDPR, NIS2, or similar.
- Experience in auditing, reporting, and investigating privacy breaches.
- Ability to interpret and apply complex legal and regulatory requirements.
- Experience working with cross-functional teams to implement privacy measures.
- Providing clear guidance and training to employees on privacy standards.
- Exposure to cloud-native environments and associated risk controls.
- Exposure in Artificial Intelligence systems and associated risk controls is a bonus.
- Strong understanding of privacy laws and frameworks (e.g., GDPR, CCPA).
Governance, Risk and Compliance Analyst employer: XO
Contact Detail:
XO Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Governance, Risk and Compliance Analyst
✨Tip Number 1
Familiarise yourself with the specific frameworks and regulations mentioned in the job description, such as ISO 27001 and GDPR. This knowledge will not only help you understand the role better but also demonstrate your commitment to compliance during interviews.
✨Tip Number 2
Network with professionals in the Governance, Risk and Compliance field. Attend relevant industry events or webinars to connect with others who work in GRC roles. This can provide valuable insights and potentially lead to referrals.
✨Tip Number 3
Gain hands-on experience with GRC platforms, especially OneTrust if possible. Familiarity with these tools can set you apart from other candidates and show that you're ready to hit the ground running.
✨Tip Number 4
Prepare for potential interview questions by reviewing common scenarios related to risk management and compliance. Think of examples from your past experiences where you successfully managed risks or ensured compliance, as this will showcase your practical knowledge.
We think you need these skills to ace Governance, Risk and Compliance Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in Governance, Risk and Compliance. Focus on specific projects or roles where you've managed risk, conducted audits, or worked with compliance frameworks.
Craft a Compelling Cover Letter: In your cover letter, express your passion for GRC and how your background aligns with the responsibilities outlined in the job description. Mention any relevant certifications and your experience with GRC platforms.
Showcase Relevant Skills: Emphasise your knowledge of frameworks like ISO 27001, GDPR, and NIST CSF. Provide examples of how you've applied these in previous roles to demonstrate your expertise.
Proofread Your Application: Before submitting, carefully proofread your application for any spelling or grammatical errors. A polished application reflects attention to detail, which is crucial for a GRC Analyst role.
How to prepare for a job interview at XO
✨Know Your Frameworks
Familiarise yourself with key frameworks like ISO 27001, NIST CSF, and GDPR. Be prepared to discuss how these frameworks apply to the role and how you have used them in past experiences.
✨Showcase Your Risk Management Skills
Prepare examples of how you've managed risk in previous roles. Highlight specific methodologies you've used for risk assessment and mitigation, as this will demonstrate your hands-on experience.
✨Understand the GRC Landscape
Research the latest trends and challenges in Governance, Risk, and Compliance. Being able to discuss current events or changes in regulations shows that you're proactive and engaged in the field.
✨Prepare for Scenario-Based Questions
Expect scenario-based questions where you'll need to demonstrate your problem-solving skills. Think about potential compliance issues or risk scenarios and how you would address them effectively.