GRC Analyst - Cyber Security

Permanent
Technology
Experienced
GRC Analyst
London
Remote
£50000 - £60000 per annum

Position: GRC Analyst - Cyber Security

Type: Permanent

Location: Remote, UK-based

Salary: £50-60K

We're seeking a GRC Analyst to strengthen pour client's governance, risk and compliance capability. The organisation is committed to maintaining robust security standards and regulatory compliance across its operations.

This is a fully remote role offering real visibility and the opportunity to influence security maturity across a diverse environment.

The Role

As a Cyber Security GRC Analyst, you will support and enhance the organisation's security governance framework, risk management processes, and compliance activities.

Working closely with IT, security and business stakeholders, you'll help identify and mitigate risk, maintain compliance with key regulatory requirements (including PCI DSS and GDPR), and contribute to building a strong culture of security awareness.

Key Responsibilities

  • Information Security Frameworks - Support ongoing alignment with ISO 27001, ISO 22301 and NIST standards.
  • Risk Management - Conduct security risk assessments and contribute to the continuous improvement of the risk management framework.
  • Third-Party Risk Management (TPRM) - Assist in overseeing supplier and supply chain security assurance processes.
  • Security Awareness - Support initiatives that promote a positive and proactive security culture.
  • Policy & Governance - Contribute to the development and maintenance of security policies, standards and procedures.
  • Control Assurance - Assess security controls and provide recommendations for improvement.
  • Compliance Activities - Support PCI DSS compliance requirements and collaborate with relevant stakeholders on GDPR adherence.
  • Business Continuity & Disaster Recovery - Assist with BC/DR planning, testing and documentation.

About You

  • Proven experience in a Cyber Security GRC or Information Security Analyst role
  • Strong understanding of recognised security frameworks (ISO 27001, NIST, etc.)
  • Experience supporting PCI DSS and GDPR compliance
  • Exposure to third-party risk management processes
  • Strong analytical skills with the ability to engage effectively with technical and non-technical stakeholders
  • Relevant certifications such as CISM, CISSP or CISA (desirable but not essential)

Why Apply?

  • Fully remote working
  • Opportunity to develop within a growing and evolving security function
  • Exposure to a complex, multi-site and digitally enabled environment
  • A role offering genuine influence across governance, risk and compliance activities

If you're looking to build your GRC career within a business that takes security seriously and offers real scope for progression, we'd be keen to speak with you.

Apply now or get in touch for a confidential discussion.

Similar Jobs

£40000 - £50000 per annum
Remote
Position: Marketing Operations Analyst Type: Permanent Location: Remote - occasional travel to London Salary: £40-50K
£50000 - £60000 per annum
Remote
Position: GRC Analyst - Cyber Security Type: Permanent Location: Remote, UK-based Salary: £50-60K
£27000 - £31000 per annum
London
Position: IT Support Engineer - 1st Line Location: Onsite, Acton Type: Permanent Salary: £27-31K
£600 - £700 per day
Berkshire
We are working with a large, technology-driven organisation seeking a Senior Software Product Engineer to join its Shared Services function. This role will focus on expanding and enhancing Amazon Connect capabilities, delivering innovative contact centre solutions that provide measurable value across the wider business.
Position: Threat Defence Delivery Manager Location: London/Hybrid Type: Contract, Inside IR35, 6 Months Rate: £700-725 p/day
Position: Identity & Access Management Workstream Lead (IAM/IDAM) Location: London/Hybrid Type: Contract, Inside IR35, 6 Months Rate: £700-725 p/day
£60000 - £85000 per annum
Cambridgeshire
The Role You'll conduct original research in areas such as probabilistic models, active learning and Bayesian optimisation, while collaborating closely with other researchers and applied teams. The role blends academic-quality research with practical application, including contributions to product development and customer-facing research projects.
Azure Cloud Consultant - Security Type: Contract, 6 months, Inside IR35 Location: Ipswich 3 days p/week, 2 days remote
10% pension, private healthcare + more
Cambridgeshire
The Role You'll work within multi-disciplinary teams of scientists and engineers to research, design and deploy cutting-edge machine learning systems. Projects span early-stage research through to working prototypes, covering the full ML lifecycle - from data preparation and rapid prototyping to model development, evaluation and deployment. This is a hands-on role for someone who enjoys tackling novel, technically challenging problems and applying ML in real-world or constrained environments.
£400 - £500 per day
Suffolk
Tec Partners are working with a world-leading technology client who are currently looking for an experienced Cyber Security Consultant, with a strong background in Penetration Testing. As a Cyber Security Consultant, you will draw on your Penetration Testing background to deliver risk analysis reporting, reporting into senior leadership.
€100000 - €120000 per annum
Berlin
We're looking for an experienced sales leader to own revenue growth and scale our client's presence with global life science enterprises. This is a founding role where you'll work hands-on to close major deals while building out the sales function from scratch. If you have a track record of selling 7-figure SaaS deals and love creating predictable revenue at scale, this is for you.
€80000 - €120000 per annum
Berlin
Kuro is building the AI automation platform for construction companies. We help construction professionals to utilize their biggest data source - the 95% of unstructured data. As a Founding Forward Deployed Engineer, you will work directly on real customer problems, often in close collaboration with enterprise stakeholders.