GRC Security Analyst Apprentice

Company: Financial Ombudsman Service
Apply for the GRC Security Analyst Apprentice
Location: London
Job Description:

Overview

Cyber GRC Analyst (Apprentice) for a Fixed term contract of 24 months to cover the lifetime of the apprenticeship, with potential for a permanent position on successful qualification. Contract: Initially a Fixed term contract for 24 months. Working hours: 35 hours per week. As an apprentice you will spend 20% of your time on off-the-job learning. Salary: £26,936. Location: London, Exchange Tower. Reporting to: Cyber Security Manager. Hybrid working and an office environment are available and encouraged. This apprenticeship role supports the Cyber GRC team to understand, assess and report on cyber risk across our people, processes and technology.

Responsibilities

  • Support internal reviews of cyber security policies, procedures and controls by gathering evidence and completing checklists against agreed standards (e.g., Cyber Essentials, ISO 27001, NIST) under supervision.
  • Help evaluate cyber controls by recording what is in place, noting exceptions, and escalating gaps or concerns to the assessor/lead.
  • Assist with reviewing systems, processes and data protection measures by gathering information from system owners and keeping evidence organised.
  • Help identify practical risk treatments (mitigations) for processes, technology, and outsourced products/services, and support tracking progress to closure.
  • Maintain assessment documentation (e.g., working papers, evidence logs, action trackers) so findings and follow-ups can be monitored and reported.
  • Work with colleagues across IT, Enterprise Risk, Data Protection and Information Security to gather information and support agreed improvements.
  • Support cyber risk assessments by helping identify threats, vulnerabilities and impacts, and capturing results in the agreed templates and risk register.
  • Stay curious about industry trends, common cyber threats, and relevant guidance, and share highlights with the team.
  • Support regular reporting by updating trackers and helping produce simple summaries of risk and control status (e.g., KPIs/KRIs), with guidance.

Minimum Criteria / Qualifications

  • You will have achieved three A levels or equivalent and GCSE English and Maths or have significant work experience in a relative field.
  • On enrolment onto the apprenticeship (September 2026) you will be at least 18 years of age; you will not be in full-time education or receiving funding for other learning programmes.
  • You will need a full UK Right to Work for the duration of the apprenticeship, and have valid and eligible residency status and be a resident in the UK for 3 years before the start of the apprenticeship.
  • In addition your CV should show an interest in cyber security, risk and compliance, with a willingness to learn; some experience documenting processes, following procedures, or working with evidence; and a basic understanding of what cyber security controls are (e.g., access control, patching, backups, MFA) or a willingness to learn quickly.

Benefits and Working Environment

We are a values-led organisation with a hybrid work policy. We offer flexibility, wellbeing support, growth opportunities and a diverse, inclusive culture. Benefits include 25 days holiday entitlement (plus ability to buy/sell days), pension, family-friendly policies, private medical insurance, and other voluntary benefits. The Financial Ombudsman Service is an equal opportunities employer and is Disability Confident. We encourage applications from underrepresented groups and provide reasonable adjustments on request.

#J-18808-Ljbffr…

Posted: June 12th, 2026