Summary We are seeking a Senior GRC Analyst to help drive the evolution of our governance, risk and compliance capability from periodic assessment towards continuous, measurable assurance that directly informs business and technology decision making. The role spans both our internal technology initiatives and practical GRC support to our client base. You will work closely with the teams that build and operate our technology estate, developing sufficient understanding of those environments to assess risk credibly and translate it into a risk position that leadership can act upon. You will concisely articulate your ideas to stakeholders at all levels and influence outcomes in support of enterprise projects. You will be confident working across the major information security frameworks and standards, including ISO 27001, NIST and SOC 2, and able to shape risk, compliance and control decisions in a way that keeps both us and our clients secure without slowing the business down. We are actively modernising the way assurance is delivered, with particular emphasis on automation and the practical application of AI to improve control efficacy and reduce manual effort. This role will be central to that work, and we are looking for a practitioner motivated by evolving how GRC is delivered rather than by maintaining existing processes through traditional methods. If you have a positive mindset and can map risk to business value with a practical, adaptable and innovative approach, then this is the role for you. Key Responsibilities Risk Management: Work closely with technology teams and clients to develop an accurate and current understanding of the risk picture, and articulate and report on it consistently and effectively to both technical and executive audiences. Framework Implementation: Plan, implement and maintain a security program aligned to CIS Controls v8 and other framework requirements in a manner appropriate to the environment, taking a practical and proportionate approach. Internal and Client Delivery: Provide security subject matter expertise across our internal technology initiatives, collaborating with project managers, business stakeholders and operational teams, and lead client GRC engagements end to end from gap assessment and framework implementation through to audit readiness and ongoing advisory. Measurement and Insight: Maintain a clear and current view of control effectiveness, risk trends and remediation progress, underpinned by tangible data points, and use it to inform business and technology planning decisions. Audit and Assurance: Plan and conduct internal and external compliance audits, coordinating with the wider Information Security function and external partners, and pursue remediation through to demonstrable risk reduction. Automation and AI: Identify assurance activity that is manual, repetitive or inefficient and lead the work to improve it, engaging technical teams and tooling to deliver measurable improvements in control efficacy and analyst capacity. Core GRC Services: Contribute to and mature the core services we provide, including third-party risk management, the policy and standards framework, and security awareness and training content, making each scalable, measurable and automated wherever practical. Function Development: Support the development of the wider Information Security function, evolving ways of working to solve problems in a collaborative environment. Essential Experience and Capability Relevant experience in a comparable role across information security governance, risk management, compliance and audit, with a demonstrable track record of delivered outcomes. Practical implementation experience with CIS Controls, ISO 27001 or equivalent frameworks within live operating environments, including the judgement required to apply them proportionately. Sufficient technical understanding to engage credibly with operational IT teams across a range of security domains including identity, networks, vulnerability management and configuration hardening. Prior experience in a technical role is not essential, but a sound grasp of how modern technology environments are built and operated is. An active interest in AI and automation technologies in the context of a ‘GRC Engineering’ mindset. A risk-based mindset, prioritising on the basis of evidence and impact, with reporting produced to support decisions rather than to record activity. The ability to prioritise a complex and evolving workload against available capacity, and to communicate the impact of change clearly with smart escalations. The confidence to identify opportunities, influence change and challenge constructively at all levels whilst building positive relationships with key business stakeholders and operational leads. Willingness to travel internationally for business on occasion. Desirable Practical experience of introducing AI and automation into GRC processes. Certification in one or more of CISA, CRISC, CISSP, CISM, CGE-P, ISO 27001 Lead Auditor or Lead Implementer. The above list of duties is not exclusive or exhaustive and the post holder will be required to undertake tasks that are reasonably expected within the scope and grading of the post.
GRC Analyst – Digital & IT
Rollsroyce
GRC Analyst – Digital & IT
Rollsroyce
Security GRC Analyst
Lendable
Governance Risk and Compliance (GRC) Analyst
Assured Data Protection
GRC Analyst
Rhymetec
Lead Information Security Analyst, GRC
Cirrus