Haystack
← Back to Jobs
full time
Technology
IG

Information Security GRC Analyst

Inventum GroupFarringdon, Central London🇬🇧United KingdomPosted 25 Aug 2026

Quick Overview

Salary
£38k - £48k/yr
Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Farringdon, Central London, United Kingdom
Posted
Yesterday
Microsoft Office

Job Description

Information Security GRC Analyst<br />Location: London<br />Salary: £38,000-£48,000<br />Working Pattern: Hybrid About the Role<br />A London-based law firm is looking for a Information Security GRC Analyst to join its Risk and Information Security team.

This is a strong opportunity for someone at the early stages of their GRC career to build practical experience within a professional services environment, with exposure to ISO 27001, information security risk, compliance and assurance.

Key Responsibilities Support the administration and continual improvement of the Information Security Management System (ISMS).<br />Assist with ISO 27001 certification, surveillance and internal audit activities.<br />Coordinate audit evidence collection and track remediation actions.<br />Maintain information security policies, procedures, standards and governance documentation.<br />Support information security risk assessments, treatment plans and exception tracking.<br />Coordinate client security due diligence questionnaires and assurance requests.<br />Support supplier assurance and third-party risk assessments.<br />Produce information security metrics, dashboards and management reporting.<br />Support security awareness, communications and training activities.

Key Requirements Understanding of information security governance, risk and compliance principles.<br />Knowledge of ISO 27001 or other recognised information security frameworks.<br />Some experience within Information Security, GRC, Risk, Compliance or a related area.<br />Exposure to audits, compliance reviews or governance processes would be beneficial.<br />Understanding of supplier assurance or third-party risk management would be advantageous.<br />Experience producing reports, dashboards or management information.<br />Proficiency in Microsoft Office, particularly Excel, Word and PowerPoint.<br />Relevant information security or GRC qualifications, such as ISO 27001 Foundation or CISM, would be advantageous.Inventum Group is acting as an Employment Agency in relation to this vacancy

Similar jobs