Haystack
← Back to Jobs
Full time
Technology
CO

Cyber Governance Analyst

CommifyNottingham, England🇬🇧United KingdomPosted 25 Aug 2026

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Nottingham, England, United Kingdom
Posted
5 hours ago
PCI DSSSOC 2AuditingComplianceEmployee EngagementHIPAASourcing

Job Description

At Commify, we're not just a company, we're a globally connected team of innovators who love what we do. As a CPaaS leader with 25 years of groundbreaking experience, we're the force behind over 7 billion customer interactions each year, enabling businesses worldwide to connect via advanced channels like SMS, RCS, and complex mobile journeys.

Our culture is our core strength. Operating across the UK, EMEA, the USA, and Australia, we've fostered a truly diverse and connected environment, earning a consistent 4 out of 5 culture score in our employee engagement surveys. You'll join a vibrant team where your diverse experience makes a daily global impact.

We need talented people to grow a global company where everyone feels proud to belong, have a purpose and do their best to directly shape the digital future.

We are looking for a Security Governance Analyst with around 1 year of hands-on experience in information security, risk, or compliance to join our Cyber Security team. Working directly alongside our Cyber Security Manager, you will act as the operational driver of our Information Security Management System (ISMS) across more than 20 active global frameworks.

If you already have the fundamentals down and are looking for a role that offers serious breadth, high visibility, and clear career progression, this is your opportunity.

What You’ll Be Doing

  • Evidence & Audit Management: Sourcing, evaluating, and maintaining audit-ready technical evidence for frameworks like ISO 27001, PCI DSS, SOC 2, HIPAA, and Cyber Essentials.
  • Risk Register Ownership: Driving our technology risk action plans (~140+ items), proactively chasing technical teams, and escalating stalled risks to management.
  • Control Testing: Planning and executing routine testing across assigned frameworks to ensure internal teams comply with security standards.
  • Common Controls Framework (SCF): Mapping control evidence to the SCF to standardise responses and streamline audit workloads across multiple frameworks.
  • Security Culture & Awareness: Coordinating global security awareness training, managing phishing campaigns, and tracking completion rates across all territories.
  • Policy Rollout: Overseeing the distribution, communication, and acknowledgement tracking of updated IS policies.

What We’re Looking For

  • Experience: Circa 1 year of experience working in an information security, compliance, GRC, or IT auditing environment.
  • Framework Exposure: Familiarity with at least one major compliance standard (such as ISO 27001, Cyber Essentials, PCI DSS, or SOC 2).
  • Strong Organisational & Stakeholder Skills: Proven ability to manage multiple priorities, track action plans, and confidently challenge technical colleagues for updates.
  • Methodical Mindset: Sharp attention to detail with strong written skills for maintaining audit-proof documentation.
  • Bonus Points (Desirable): Experience with GRC tools or progress towards relevant certifications (e.g., CompTIA Security+, ISO 27001 Foundation).

Benefits

  • Competitive Salary (£30 - 40,000)
  • Company Bonus Scheme
  • Comprehensive healthcare cash plan
  • A generous 27 days of annual leave in addition to Bank Holidays
  • 2 Wellbeing leave days and 2 days dedicated to giving back to your community
  • Enjoy your birthday off!
  • Employer pension contribution at 5%
  • Death in service benefit (4 times your salary)
  • Annual award recognition
  • Fun monthly and quarterly social events
  • Opportunities for training and professional development
  • Flexible hybrid working arrangements

Similar jobs