Position Overview
Senior Governance, Risk and Compliance (GRC) Analyst – London. Hybrid work arrangement: 3 days in office.
Responsible for supporting and maintaining the News UK Cyber GRC Program, collaborating with the BISO and central GRC function. Tasks include developing and maintaining cybersecurity policies, standards, guidelines and processes to ensure compliance and effective risk management.
Responsibilities
- Work with key internal and external stakeholders to ensure compliance with PCI DSS, Privacy and GDPR, and related audit and assessment requirements.
- Assist in risk assessment processes and report on enterprise‑wide and third‑party security controls.
- Support implementation of key security initiatives across the organisation.
- Support management of audits, external assessments and assurance processes, including PCI DSS and NIST CSF.
- Develop and manage meaningful metrics to measure and track cyber risks and the effectiveness of the governance, risk and compliance function.
- Conduct compliance readiness assessments and assurance activities against policies, standards and requirements.
- Track technology and cyber‑related audit findings and actions.
- Assist with the development of measurable cybersecurity standards that align with policy control objectives.
- Support user and specialist education and awareness exercises for employees.
- Assist with third‑party security assessments against industry standards and News UK control standards.
- Maintain the cybersecurity risk register.
Qualifications
- 6+ years’ experience within Cyber Security or related fields.
- Demonstrated experience in governance, risk and compliance in dynamic, complex cyber security, technology and business environments.
- Strong knowledge of industry frameworks and standards such as NIST CSF, PCI DSS and ISO 27001.
- Good working knowledge of cloud infrastructure, especially AWS.
- Experience in a SOX compliance environment is desirable.
- Strong oral and written communication skills.
- Qualification in Information Security, Computer Science, Engineering or a similar discipline.
- Professional security certifications such as CISSP, CISM, CISA, CRISC or similar preferred.
Equal Opportunity Statement
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status or any other protected characteristic.
#J-18808-Ljbffr…
