The Governance, Risk, Compliance (GRC) and Vulnerability Assessment Analyst supports the account's cyber security governance, risk management, compliance, assurance, and vulnerability management activities within a complex and highly regulated environment.
This role contributes to ensuring that security controls, processes, and governance frameworks are effective, auditable, and aligned to industry standards including ISO 27001, Cyber Essentials Plus, GDPR, NIST, and contractual security obligations.
The Analyst provides security oversight, assurance, and risk-based guidance across projects, operational services, and technology changes while supporting secure-by-design principles through governance and design review activities.
Working closely with technical and business stakeholders, the successful candidate will help identify, assess, manage, and report security risks appropriately, while supporting continual improvement initiatives that enhance the overall security posture of the account.
If you are successfully offered this position, you will go through a series of pre-employment checks, including identity, nationality (single or dual) or immigration status, employment history going back 3 continuous years, and unspent criminal record check (known as Disclosure and Barring Service)