Salary – Between £54,600 - £65,520 + annual bonus & benefits
Work Level – WL2
Location – Edinburgh, Reigate, Glasgow, Newcastle. Permanent.
Office Attendance - Our roles are hybrid; however, you should be able to travel to our office, 1-3 days per week for this position.
Closing Date - Applications close 6th August at 5pm
We’re looking for a Governance, Risk and Compliance Analyst to join our Insurance, Money & Services team.
Reporting to the Lead GRC Manager, the role provides hands on analytical, coordination and reporting support across security risk management, policy compliance, assurance activity, and regulatory obligations. The role is a key entry to mid-level position for developing strong technical and risk judgement within a GRC function.
You’ll play a critical role in supporting the day-to-day delivery of Information Security Governance, Risk and Compliance activities, contributing to the effective operation of the enterprise security GRC framework.
What you’ll be doing
• Support the operation of the Information Security GRC framework, helping to maintain governance processes, procedures and supporting documentation.
• Assist with security risk assessments for projects, technologies, suppliers and business processes.
• Help document risks clearly, ensuring accurate articulation, scoring and alignment to defined risk appetite.
• Maintain risk registers and supporting tooling, ensuring data quality and completeness.
• Coordinate evidence collection for internal audit, external audit and independent assurance activity.
• Track security findings, issues and remediation actions through to closure, escalating risks or slippage where required.
• Support the maintenance and communication of information security policies and standards.
• Assist with monitoring policy compliance and control effectiveness, identifying themes, trends and control gaps for escalation.
• Support delivery of security awareness initiatives, including administration, tracking and reporting of mandatory security training.
• Support the GRC Manager produce accurate and timely GRC reporting and dashboards, supporting the preparation of materials for governance forums and reviews.
We need you to have (minimum experience)
• GRC fundamentals
o An understanding of information security governance, risk and compliance concepts.
o Experience in information security, risk management, compliance, audit or a related analytical role.
o Exposure to security risk assessments, audits or control frameworks, whether formal or informal.
• Risk assessment and reporting
o Ability to support structured security risk assessments and documentation.
o Strong attention to detail, with the ability to produce accurate, complete and well-structured outputs.
o Ability to produce clear reports, dashboards and supporting analysis.
• Assurance, policy and controls
o Experience supporting audit, assurance and remediation activity.
o Understanding of how policies, standards and controls help manage information security risk.
o Awareness of information security and data protection frameworks such as ISO 27001 or NIST CSF.
• Stakeholder engagement
• Ability to work effectively with security, technology, risk, audit and business colleagues.
• Clear communication skills, with the ability to explain issues and findings using appropriate support and evidence.
• A collaborative mindset and willingness to learn, develop and take ownership of assigned tasks.
• Certifications:
o Degree or equivalent experience in information security, risk management, IT or a related discipline
o ISO 27001 Foundation or Internal Auditor would be beneficial
o CISA, CRISC or equivalent risk/audit certification would also be beneficial
o Security or risk management foundation qualifications would be desirable
We don’t expect you to tick every box, and if you feel you hit most of the brief, it’s worth exploring to further develop your career here with us.
What’s in it for you
• Prepare for your retirement with our colleague pension scheme.
• Virtual GP Service for you and your family 365 days a year.
• Performance related annual bonus.
• Indulge in a generous holiday allowance with a minimum of 7.2 weeks, with the opportunity to buy more.
• Embrace the benefits of our Colleague Clubcard, enjoy a 10% discount that increase to 15% every payday. As an added perk, we’ll give you a second card to share with someone else.
• Benefit from our family-oriented initiatives, encompassing enhanced maternity leave pay, a shared parental leave policy, and a generous 8-week paid paternity leave.
• A place to get on - take advantage of our ongoing learning opportunities and award-winning training, to help you achieve the job and career you want.
• Take part in our Buy as you Earn and Save as your Earn share schemes.
Everyone’s welcome
We want all our colleagues to always feel welcome and be themselves. We’re committed to building a more inclusive workplace and celebrating everything that makes colleagues unique, and value the richness and diversity this brings to our business. A more diverse business helps us deliver on our purpose to serve our customers, communities, and planet a little better every day.
Interviews
We also know the importance of balancing work with life’s other commitments. Please talk to us at interview about the flexibility you need, as we’re committed to exploring part time and flexible working opportunities, at every level of the organisation.
Interviews are expected to be held shortly after closing date.