Cyber Security GRC Analyst
On-siteRedhill, England, United Kingdom
Job Summary
Conduct cybersecurity risk assessments and security-control reviews across business applications, infrastructure, and computer installations being transferred. Identify security risks, recommend remediation actions, and maintain ISO 27001 and PCI-DSS certification activities throughout the programme. Manage risk registers, treatment plans, and ad-hoc internal security audits while documenting non-compliances and monitoring remediation progress. Design and implement security policies, standards, and procedures to ensure compliance with the Information Security Management System and contractual obligations. Review handover-related change requests, assess impacts on existing controls, and produce clear security, risk, and audit reporting for leadership. Support knowledge transfer and training for the incoming organisation's security and audit teams. Travel to operational sites and data centres where required.
Required Qualifications
- A recognised information-security certification, such as: CISA, CISM or CRISC, CISSP, BCS CISMP, IISP certification or equivalent
- Strong experience within cybersecurity governance, risk, audit and compliance management
- Experience working within a complex IT, technology or operational environment
- Thorough understanding of information-security audit methodologies and control-assessment techniques
- Experience operating and auditing an ISO 27001-compliant Information Security Management System
- Experience managing PCI-DSS certification, recertification and audit activities
- Experience implementing or operating within a PCI-DSS-compliant security environment
- Strong knowledge of cybersecurity technologies, controls, frameworks and risk-management methodologies
- Experience assessing cybersecurity implications within formal change-management processes
- Demonstrable stakeholder-management experience, including leading consultations, workshops and presentations
- Experience creating and maintaining security policies, standards, procedures, guidance, processes and awareness materials
- Experience managing security risks, remediation plans, audit findings and compliance actions through to completion
- Travel to other operational sites and data centres where required
Desired Qualifications
- Degree in information security, computer science, engineering, mathematics, encryption or another relevant discipline, or equivalent professional experience
- Information privacy or data-protection qualifications, such as CIPP/E or CIPM
- Payment Card Industry Security Standards Council certification, such as ISA or QSA
- ITIL, PRINCE2 Foundation or TOGAF certification
- Relevant infrastructure or networking vendor certifications
- Experience working with additional security, risk and compliance frameworks, including: PCI P2PE, PCI POI PTS, ISO 22301, ISO 27005, ISO 31000, NIST security and risk frameworks, GDPR and wider data-protection legislation
- Experience within transactional revenue, embedded systems, smartcards, mobile payments, open-payment systems or EMVCo environments
- Experience using cybersecurity governance, risk and compliance platforms
- Experience using IT service-management tools
- Familiarity with vulnerability-management and security-operations tooling
- Experience working with quality-management systems and external audit standards such as ISO 9001
- Previous experience supporting a complex operational handover, transition or service-transfer programme
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.