Haystack
← Back to Jobs
Full time
Technology
IR

Cyber GRC Analyst (Cyber Policy & Governance)

IBEX RECRUITMENT LTDNorth West England, UK🇬🇧United KingdomPosted 2 Sept 2026

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
North West England, UK, United Kingdom
Posted
Yesterday
Stakeholder Management

Job Description

Are you passionate about shaping cyber security strategy and governance within a complex, highly regulated environment?

We are working with a major organisation responsible for operating and protecting nationally important infrastructure. As part of continued investment in cyber resilience, they are seeking a GRC Analyst to support the development and implementation of cyber security policy, governance, and assurance activities across a diverse technology landscape.

Whilst the job title is GRC Analyst, the primary focus of the role is developing, maintaining and improving Cyber Security Policies, working closely with stakeholders across the business to ensure they remain aligned to regulatory requirements, industry best practice and organisational objectives.

This is an opportunity to influence cyber strategy at an enterprise level, working with senior stakeholders, regulators, and technical teams to strengthen security and resilience across both traditional IT and operational environments.

The Role

As a GRC Analyst, you will play a key role in developing, maintaining, and enhancing cyber security policies, standards, and governance frameworks. You will provide expert guidance on regulatory compliance, emerging cyber risks, and industry best practice while supporting the organisation's long-term cyber resilience objectives.

Key responsibilities will include:

  • Developing and maintaining cyber security policies, standards, and governance frameworks aligned to recognised industry best practice.
  • Providing expert advice and guidance to technology, security, risk, and leadership teams.
  • Monitoring changes in legislation, regulation, and the threat landscape to ensure policies remain current and effective.
  • Working closely with internal stakeholders across technology, operations, legal, risk, and compliance functions.
  • Supporting cyber governance activities, audits, assurance reviews, and regulatory engagements.
  • Contributing to incident response planning, lessons learned activities, and continuous policy improvement.
  • Identifying strategic cyber risks and recommending appropriate mitigation measures.

About You

To be successful in this role, you'll have experience within Cyber Governance, Risk & Compliance (GRC), Information Security or Cyber Security, together with an interest in developing and improving cyber security policies within a regulated environment.

You will ideally have:

  • Experience developing, reviewing or managing cyber security policies, standards, procedures or governance frameworks.
  • Strong knowledge of recognised cyber security frameworks such as ISO 27001, NIST, or the Cyber Assessment Framework (CAF).
  • Experience supporting compliance, risk management, governance or information assurance programmes.
  • Excellent stakeholder management and communication skills, with the ability to translate technical concepts into clear business and policy language.
  • Experience engaging with senior stakeholders, external partners, or regulatory bodies.
  • The ability to balance security requirements with operational and business objectives.

Desirable Experience

  • Experience within critical infrastructure, utilities, defence, energy, engineering, transport, manufacturing, or other highly regulated sectors.
  • Understanding of Operational Technology (OT) and Industrial Control Systems (ICS) security.
  • Knowledge of cyber resilience requirements within critical national infrastructure environments.
  • Professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor.

What's on Offer

  • Opportunity to influence cyber strategy within a nationally significant organisation.
  • Exposure to complex cyber security and governance challenges.
  • Collaborative and supportive working environment.
  • Ongoing professional development and certification support.
  • Competitive salary and comprehensive benefits package.

If you're looking to make a meaningful impact in a role that combines cyber security, policy development, governance, and strategic stakeholder engagement, we'd like to hear from you.



Similar jobs