IT GRC Senior Analyst
The Opportunity
A growing international organisation at a pivotal stage in its evolution as it matures its technology landscape, is seeking an experienced GRC focused Information Security professional, to play a key role in ensuring effective controls across their global environment are maintained.
Working closely with senior leadership and reporting into an established international GRC function, you will play a key role in strengthening and embedding compliance frameworks, identifying and mitigating technology risks, and ensuring governance activities remain practical, effective and aligned to business objectives.
The business employs a hybrid working policy where you will be expected to be onsite 2 days a week.
Unfortunately our client doesn't sponsor visas so you will need an indefinite right to work in the UK
The Role
Acting as a trusted advisor to stakeholders across technology, business operations and corporate functions, helping to balance risk management with business agility, you'll assess new systems, tools and business requirements, provide guidance on governance and control frameworks and support audit and assurance activities across a diverse international environment. You will:
- Develop, enhance and embed governance, risk and compliance frameworks.
- Assess technology, operational and information security risks and support mitigation activities.
- Support internal and external audits, compliance reviews and assurance programmes.
- Evaluate new systems, tools and business initiatives from a risk and compliance perspective.
- Maintain and improve policies, standards, controls and governance processes.
- Partner with stakeholders across multiple locations and functions to promote best practice.
- Support continuous improvement activities, reporting, metrics and compliance monitoring.
- Contribute to the ongoing development of a mature and scalable risk management culture.
The Person
As a collaborative and commercially aware Information Security professional who can translate compliance requirements into practical business outcomes, you will bring:
- Significant experience within IT Governance, Risk & Compliance, IT Audit, Information Security Compliance or a related discipline.
- Strong knowledge of recognised frameworks such as ISO 27001, PCI, SOX and privacy regulations.
- Experience identifying, assessing and managing technology and information security risks.
- The ability to influence stakeholders at all levels and build credibility quickly.
- Strong communication skills with both technical and non-technical audiences.
- A proactive, solutions-focused approach and the confidence to work with a high degree of autonomy.
IT Leadership and Cyber Security
Newcastle Office
DD: +44 191 269 0718
M: +44 750 122 4773
E: paul.newton@nigelwright.com