Job Title: GRC Security AnalystFunction / Department: InfoSecLocation: Milton KeynesReporting To: Stephen MarsdenDate: April 2026
Job Purpose
To support Governance, Risk and Compliance with Supplier Assurance and occasionally the Security Operations team. The role supports the management of information security risk by assessing control effectiveness, validating evidence, and articulating risk in a business‑focused manner.
Key Responsibilities
- Assist with daily checks of monitoring systems to ensure they remain healthy.
- Provide support to maintain metrics and reporting to ensure the security threats and trends impacting our business are understood and are raised to the Governance, Risk and Compliance team.
- Liaise with 3rd party companies to support various day‑to‑day aspects of our security systems.
- Involve in third‑party Supplier Assurance and Security Impact Assessments.
- Aid with the development of processes, maintenance, and improvement of runbooks.
- Undertake basic risk assessments with supervision and direction; support some complex risk analysis as part of a team.
- Assist with security education and awareness.
- Assist in preparing for and conducting compliance audits.
- Take part and assist in running Tabletop Exercises.
- Support the delivery of broader security initiatives and projects.
- Continual improvement of internal reporting.
- Input into policies and standards.
Strategic Responsibility
This role has no accountability for setting or inputting into a specific strategy.
Business Knowledge
- Work closely with the Assurance team on third‑party/supplier assurance and interact with the wider InfoSec team on various other projects; be familiar with third‑party/supplier assurance processes.
- Have required knowledge of penetration test assurance or vulnerability reporting and understand high‑level implications of the results.
- The role holder is not required to be hands‑on in operational security tooling but must engage effectively with technical teams such as SecOps.
Problem Solving
- Demonstrate a strong risk‑based assurance mindset, combining technical security knowledge with the ability to assess control effectiveness, challenge evidence, and articulate information security risk in a business context.
- Require straightforward common sense and initiative, combined with clear judgement and guidance from precedents; independence in work is key.
Decision Making
Make decisions within defined procedures and occasionally outside of established procedures but within a policy framework.
Communication
- Communicate across various levels, exchanging factual information and influencing skills as essential; produce clear, concise, evidence‑based assurance reports, risk statements, and recommendations.
- Communicate technical or security concepts in plain language to non‑technical stakeholders; present findings confidently to colleagues and senior management while providing constructive challenge and maintaining credibility and professional objectivity.
Innovation
Suggest improvements on existing procedures within areas of operation, including developing and adapting new or existing processes for increased quality/efficiency; continuously search for improvements in techniques that add value to the business and increase security.
Job Specifications
Degree/Professional Qualification: Recognised security qualification (Security+, CySA+ etc) ideal but not essential.
Knowledge:
- Understanding of using Third‑Party Risk Management (TPRM) Platforms.
- Familiarity working with Identity Governance platforms and processes.
- Ideally 3+ years of proven Information Technology experience with a good understanding of infrastructure and experience of Microsoft Azure and O365.
- A good awareness of information security best practices.
Skills/Ability:
- A team player who is hardworking and has self‑organisation and time‑management skills.
- Excellent attention to detail.
- Strong analytical and troubleshooting skills.
- Ability to remain calm under pressure and clearly communicate to all levels of management.
- Experience preferred with NIST CSF or similar framework.
- Ability to generate reports from interrogating system data, using Microsoft CoPilot and/or PowerShell; not essential but valuable.
#J-18808-Ljbffr…
