Quick Overview
Job Description
Are you passionate about shaping cyber security strategy and governance within a complex, highly regulated environment?
We are working with a major organisation responsible for operating and protecting nationally important infrastructure. As part of continued investment in cyber resilience, they are seeking a GRC Analyst to support the development and implementation of cyber security policy, governance, and assurance activities across a diverse technology landscape.
Whilst the job title is GRC Analyst, the primary focus of the role is developing, maintaining and improving Cyber Security Policies, working closely with stakeholders across the business to ensure they remain aligned to regulatory requirements, industry best practice and organisational objectives.
This is an opportunity to influence cyber strategy at an enterprise level, working with senior stakeholders, regulators, and technical teams to strengthen security and resilience across both traditional IT and operational environments.
The Role
As a GRC Analyst, you will play a key role in developing, maintaining, and enhancing cyber security policies, standards, and governance frameworks. You will provide expert guidance on regulatory compliance, emerging cyber risks, and industry best practice while supporting the organisation's long-term cyber resilience objectives.
Key responsibilities will include:
- Developing and maintaining cyber security policies, standards, and governance frameworks aligned to recognised industry best practice.
- Providing expert advice and guidance to technology, security, risk, and leadership teams.
- Monitoring changes in legislation, regulation, and the threat landscape to ensure policies remain current and effective.
- Working closely with internal stakeholders across technology, operations, legal, risk, and compliance functions.
- Supporting cyber governance activities, audits, assurance reviews, and regulatory engagements.
- Contributing to incident response planning, lessons learned activities, and continuous policy improvement.
- Identifying strategic cyber risks and recommending appropriate mitigation measures.
About You
To be successful in this role, you'll have experience within Cyber Governance, Risk & Compliance (GRC), Information Security or Cyber Security, together with an interest in developing and improving cyber security policies within a regulated environment.
You will ideally have:
- Experience developing, reviewing or managing cyber security policies, standards, procedures or governance frameworks.
- Strong knowledge of recognised cyber security frameworks such as ISO 27001, NIST, or the Cyber Assessment Framework (CAF).
- Experience supporting compliance, risk management, governance or information assurance programmes.
- Excellent stakeholder management and communication skills, with the ability to translate technical concepts into clear business and policy language.
- Experience engaging with senior stakeholders, external partners, or regulatory bodies.
- The ability to balance security requirements with operational and business objectives.
Desirable Experience
- Experience within critical infrastructure, utilities, defence, energy, engineering, transport, manufacturing, or other highly regulated sectors.
- Understanding of Operational Technology (OT) and Industrial Control Systems (ICS) security.
- Knowledge of cyber resilience requirements within critical national infrastructure environments.
- Professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor.
What's on Offer
- Opportunity to influence cyber strategy within a nationally significant organisation.
- Exposure to complex cyber security and governance challenges.
- Collaborative and supportive working environment.
- Ongoing professional development and certification support.
- Competitive salary and comprehensive benefits package.
If you're looking to make a meaningful impact in a role that combines cyber security, policy development, governance, and strategic stakeholder engagement, we'd like to hear from you.
Similar jobs
- SR
Fire and Security Service Engineer
System Recruitment
Holbeck, Leeds🇬🇧£35k - £40k/yrHybrid1 week agoAdministrative - AM
Security Consultant
NewAnson McCade
London🇬🇧£45k - £100k/yrHybrid2 days agoAgileIoTTechnology - AM
Senior Security Architect
NewAnson McCade
Manchester, Greater Manchester🇬🇧£100k/yrHybrid2 days agoOWASPTCP/IPAgile+3Technology - RH
Senior Security Systems Engineer
NewRecruitment Helpline Ltd
Maidstone, Kent🇬🇧£42k/yrOn-siteYesterdayTechnology - TE
Cyber Security Engineer
NewTeksystems
Yorkshire And The Humber🇬🇧HybridYesterdayAzureHTTPSStakeholder ManagementTechnology - HA
Senior Cyber Software Engineer Technical Lead
Hackajob Ltd
Charing Cross, Central London🇬🇧Remote3 weeks agoC#C++Java+4Technology