Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving real transformation change within our clients. We use proven technology, specialist teams and domain expertise to build solid technical foundations across platforms, data and business applications. We have a passion for using technology to solve business problems, working in partnership with our clients to help in achieving their goals. We are delighted to present a newly created opportunity for a Governance, Risk & Compliance Analyst to join our internal security team. Reporting directly to the Sword Group CISO, you will help run and maintain Sword’s governance, risk, and compliance activities across key regulatory, certification, and client requirements. This is a hands-on role suited to someone who can take ownership, drive progress, and deliver practical outcomes across compliance, risk management, and assurance. You will support and maintain compliance with frameworks and obligations including GDPR, NIS2, ISO 27001, the UK Cyber Security Resilience Bill, Cyber Essentials, and risk management, while contributing to continuous improvement across Sword’s security and compliance practices. We are looking for someone with enough practical experience to lead and coordinate key compliance activities globally, particularly across GDPR, ISO 27001, and Cyber Essentials. Key Responsibilities: Security Governance - Support the development, maintenance, and improvement of security policies, standards, and procedures, helping to keep Sword aligned with ISO 27001, NIS2, and other relevant obligations. Risk Management - Support and maintain security risk management activities across suppliers, projects, and internal services, helping to identify risks, track treatment actions, and drive progress to completion. Legal, Regulatory, and Contractual Requirements - Help track, interpret, and maintain compliance with relevant legal, regulatory, client, and contractual obligations, including GDPR, NIS2, and the UK Cyber Security Resilience Bill. Data Protection - Lead and coordinate ongoing GDPR compliance activities globally by maintaining records, improving processes, working with stakeholders, and ensuring actions are progressed and completed. Third-Party and Supply Chain Security - Support supplier and supply chain risk management activities, including reviews, due diligence, follow-up actions, and the maintenance of appropriate records and evidence. Certification and Compliance Support - Lead and coordinate Sword’s ISO 27001 certification and Cyber Essentials activities, including evidence gathering, control tracking, stakeholder coordination, and follow-up of remediation actions. Audit and Assurance - Support internal and external audit activity by preparing evidence, coordinating responses, tracking findings, and helping ensure actions are completed. Business Resilience Support - Contribute to the maintenance and improvement of business continuity and disaster recovery arrangements, including documentation, review activity, and support for testing exercises. Security Culture and Awareness - Support awareness, training, and communication activities that help colleagues understand and follow security policies, processes, and responsibilities. Continuous Improvement - Take a practical, can-do approach to improving the GRC programme through steady progress, good organisation, and a focus on getting things done.
Technical Analyst (Regulation & Compliance)
Eeze
Lead Security & Compliance Analyst
Evenergy
Senior Legal Operations and Compliance Analyst
The Economist Group
IT Compliance Analyst
UK Atomic Energy Authority
Graduate Compliance Analyst (Know Your Customer) KYC
Projectivegroup
GRC (Governance, Risk & Compliance) Analyst
Arden University