- Company Name
- The Investigo Group
- Job Title
- Governance, Risk & Compliance (GRC) Analyst
- Job Description
-
Job Title: Governance, Risk & Compliance (GRC) Analyst
Role Summary: Provides expert support to the Security Team in developing, refining, and maintaining governance, risk, and compliance capabilities. Works closely with the Deputy Head of Security to strengthen the organisation’s ISO 27001‑aligned Information Security Management System (ISMS), drive risk management processes, ensure regulatory compliance, manage third‑party assurance, and implement a new GRC platform.
Expectations:
- Eligibility for a Security Check (SC) clearance; right to work in the UK; continuous UK residence for the last 5 years; willingness to undergo security vetting during onboarding.
- Ability to work remotely and collaborate across business functions.
- Proactive mindset, curiosity, and the ability to translate security requirements into practical, business‑aligned processes.
Key Responsibilities:
- Maintain and enhance the ISO 27001‑aligned ISMS, ensuring policies, procedures, and controls stay current and effective.
- Facilitate enterprise risk management by identifying, assessing, documenting, and tracking risks in the risk register.
- Support third‑party and supply‑chain risk assurance activities, including vendor assessments and continuous monitoring.
- Prepare for internal and external audits (ISO 27001, other standards) and assist in audit remediation.
- Contribute to the design, configuration, and ongoing management of the GRC platform.
- Collaborate with cross‑functional teams to embed governance and compliance practices into daily operations.
- Communicate risk and compliance status to stakeholders, providing clear, actionable recommendations.
Required Skills:
- Strong analytical and detail‑oriented approach to risk assessment and gap analysis.
- Knowledge of governance frameworks, ISO 27001, regulatory compliance, and third‑party risk management.
- Experience with GRC tools and documentation.
- Excellent written and verbal communication; ability to produce concise reports and presentations.
- Collaborative teamwork and stakeholder management.
- Continuous improvement mindset and proactive problem solving.
Required Education & Certifications:
- Bachelor’s degree in Information Security, Risk Management, Business Administration, or related field (or equivalent professional experience).
- Certifications such as ISO 27001 Lead Implementer/Assessor, CISSP, CISM, CRISC, or similar relevant credentials.
- Willingness to obtain or maintain the necessary security clearance.