Cyber GRC Analyst
We're hiring a Cyber GRC Analyst to support enterprise-wide governance, risk and compliance activities across a complex technology environment.
This role will focus on cyber risk assessments, security control assurance, regulatory compliance, third-party risk management, and cyber resilience governance. You'll work closely with security, technology and business teams to help strengthen the organisations cyber security posture and ensure alignment with regulatory and industry standards.
Key responsibilities & duties include:
Perform cyber risk assessments across systems, projects, technology changes, and third-party suppliers
Conduct structured security control testing and assurance activities against internal and regulatory framework.
Support governance, risk, compliance, and cyber resilience activities including business continuity and disaster recovery oversight
Monitor compliance with cyber security policies, standards, and regulatory requirements including NIS2, GDPR, NIST CSF and ISO 27001
Support internal and external audits, regulatory inspections, and governance reporting
Track remediation activities, control maturity, and cyber risk metrics
Collaborate with technical and business stakeholders to ensure risks are identified, managed, and appropriately mitigated
Support the lifecycle management of cyber security policies, standards, and procedures
Contribute to continuous improvement initiatives across cyber governance and assurance processes
Required Experience:
5+ years’ experience in cyber security, risk management, governance, compliance, or technology assurance
Hands-on experience performing cyber risk assessments, control testing, or compliance assurance activities
Strong understanding of risk management principles and security governance practices
Experience with third-party risk management and supplier assurance
Familiarity with frameworks and standards such as NIST, ISO 27001, CIS, GDPR, and related regulatory requirements
Experience supporting audits, assurance reviews, or project/change risk assessments
Strong written communication and stakeholder management skills
Ability to manage multiple priorities and work independently in a fast-paced environment
Desirable Experience:
Experience within regulated industries such as aviation, finance, or critical infrastructure
Knowledge of secure-by-design principles, cloud security controls, and modern IT environments
Experience supporting resilience frameworks including BCM, disaster recovery, or cyber recovery
Familiarity with GRC platforms such as SureCloud, Archer, or ServiceNow GRC
Knowledge of Power BI
Relevant certifications such as CISSP, CISA, CRISC, or ISO 27001 Lead Auditor/Implementer