GRC Analyst
Contract or Temp in IT & TelecommsJob Description
6 Month Contract | Up to £350 per day (inside) | Cheltenham 2 days per week
GRC Analyst (Contract)
Location: Cheltenham (Hybrid – 2 days per week onsite)
Contract: 6 months
Rate: Up to £350 per day (Inside IR35)
Our client, a leading organisation, is looking for a GRC Analyst to support its Governance, Risk & Compliance function. This contract has been created to help reduce a backlog of third-party vendor and application security assessments while supporting wider information security and compliance initiatives.
Working alongside an experienced cyber security team, you’ll play a key role in ensuring new technologies, software and suppliers meet the organisation’s security, compliance and risk standards before entering the business.
This is an excellent opportunity for someone with around 2+ years’ experience in Governance, Risk & Compliance who is looking to broaden their exposure across vendor risk, information security governance and compliance within a large enterprise environment.
What you’ll do
- Conduct third-party supplier and software security due diligence assessments.
- Review new applications and vendors as part of the software onboarding process.
- Assess suppliers against established governance and risk frameworks.
- Review security certifications including ISO 27001, SOC 2 and other recognised standards.
- Complete risk assessments and Risk Acceptance documentation.
- Respond to customer security questionnaires, audits and compliance requests.
- Maintain GRC documentation, reporting and governance metrics.
- Support Data Protection Impact Assessments (DPIAs) and Data Subject Access Requests (DSARs).
- Contribute to the continual improvement of the Information Security Management System (ISMS).
- Work closely with internal stakeholders and third-party suppliers to drive assessments through to completion.
- Support the ongoing development of GRC processes, procedures and security awareness initiatives.
What we’re looking for
- Around 2+ years’ experience within Information Security, Governance, Risk or Compliance.
- Experience conducting third-party supplier or vendor risk assessments.
- Knowledge of application or software onboarding processes.
- Familiarity with Information Security Management Systems (ISMS).
- Understanding of ISO 27001, NIST Cyber Security Framework and/or CIS Controls.
- Experience completing security questionnaires and compliance assessments.
- Knowledge of Data Protection processes, including DPIAs and DSARs.
- Experience carrying out risk assessments and documenting risk acceptance.
- Strong stakeholder management and communication skills.
- Experience using Microsoft Office, SharePoint and Power BI.
Desirable
- ISO 27001 Lead Implementer or Lead Auditor.
- CIPP/E or another Data Protection qualification.
- CRISC or similar Governance & Risk certification.
Why join?
- 6-month contract with the potential to make an immediate impact.
- Gain exposure to a broad range of GRC, vendor risk and compliance activities.
- Work within an experienced and collaborative cyber security team.
- Hybrid working with just 2 days per week onsite in Cheltenham.
Other jobs you may like
-
Business Analyst – AI
- Gloucestershire