GRC Analyst

Contract or Temp in IT & Telecomms

Job Description

6 Month Contract | Up to £350 per day (inside) | Cheltenham 2 days per week

GRC Analyst (Contract)
Location: Cheltenham (Hybrid – 2 days per week onsite)
Contract: 6 months
Rate: Up to £350 per day (Inside IR35)

Our client, a leading organisation, is looking for a GRC Analyst to support its Governance, Risk & Compliance function. This contract has been created to help reduce a backlog of third-party vendor and application security assessments while supporting wider information security and compliance initiatives.

Working alongside an experienced cyber security team, you’ll play a key role in ensuring new technologies, software and suppliers meet the organisation’s security, compliance and risk standards before entering the business.

This is an excellent opportunity for someone with around 2+ years’ experience in Governance, Risk & Compliance who is looking to broaden their exposure across vendor risk, information security governance and compliance within a large enterprise environment.

What you’ll do

  • Conduct third-party supplier and software security due diligence assessments.
  • Review new applications and vendors as part of the software onboarding process.
  • Assess suppliers against established governance and risk frameworks.
  • Review security certifications including ISO 27001, SOC 2 and other recognised standards.
  • Complete risk assessments and Risk Acceptance documentation.
  • Respond to customer security questionnaires, audits and compliance requests.
  • Maintain GRC documentation, reporting and governance metrics.
  • Support Data Protection Impact Assessments (DPIAs) and Data Subject Access Requests (DSARs).
  • Contribute to the continual improvement of the Information Security Management System (ISMS).
  • Work closely with internal stakeholders and third-party suppliers to drive assessments through to completion.
  • Support the ongoing development of GRC processes, procedures and security awareness initiatives.

What we’re looking for

  • Around 2+ years’ experience within Information Security, Governance, Risk or Compliance.
  • Experience conducting third-party supplier or vendor risk assessments.
  • Knowledge of application or software onboarding processes.
  • Familiarity with Information Security Management Systems (ISMS).
  • Understanding of ISO 27001, NIST Cyber Security Framework and/or CIS Controls.
  • Experience completing security questionnaires and compliance assessments.
  • Knowledge of Data Protection processes, including DPIAs and DSARs.
  • Experience carrying out risk assessments and documenting risk acceptance.
  • Strong stakeholder management and communication skills.
  • Experience using Microsoft Office, SharePoint and Power BI.

Desirable

  • ISO 27001 Lead Implementer or Lead Auditor.
  • CIPP/E or another Data Protection qualification.
  • CRISC or similar Governance & Risk certification.

Why join?

  • 6-month contract with the potential to make an immediate impact.
  • Gain exposure to a broad range of GRC, vendor risk and compliance activities.
  • Work within an experienced and collaborative cyber security team.
  • Hybrid working with just 2 days per week onsite in Cheltenham.

Other jobs you may like