Rodeo
Get started

CRH

Cyber GRC Analyst- CRH International

Birmingham
Posted about 14 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Country: Netherlands

Req ID: 527327

Job Type: Full Time

Workplace Type: Hybrid

Seniority Level: Associate

About CRH

We are CRH, and we are committed to contributing to a more resilient and sustainable built environment. We understand the wider impact our businesses can make in supporting human activity. We continue to do this through the delivery of unique, superior building materials and products for use in road and critical utility infrastructure, commercial building projects and outdoor living solutions.

CRH (NYSE: CRH) is the leading provider of building materials solutions that build, connect and improve our world. Employing c.83,000 people at c.4,000 operating locations in 28 countries, CRH has market leadership positions in both North America and Europe. As the essential partner for transportation and critical utility infrastructure projects, complex non-residential construction and outdoor living solutions, CRH’s unique offering of materials, products and value-added services helps to deliver a more resilient and sustainable built environment. The company is ranked among sector leaders by Environmental, Social and Governance (ESG) rating agencies. A Fortune 500 company, CRH’s shares are listed on the NYSE and LSE.

Without you noticing our products, we are everywhere you live, work, and relax.

Our project portfolio includes some of the most sustainable and cutting-edge building projects around the world. Think of the asphalt on the Silverstone Grand Prix Circuit, the Paris Metro Rail project, but also the Louis Vuitton Museum in Paris, parts of the Burj Khalifa, and the Kennedy Space Centre.

Learn more about us through the following Link.

Position Overview

The Cyber GRC Analyst supports the delivery of cyber security governance, risk, and compliance across CRH International, operating within a hybrid technology model spanning centrally delivered platforms (UnITy) and independent Operating Companies (OpCos).

Reporting to the Senior GRC Manager, the role is responsible for translating security requirements into practical, risk-based controls and driving their consistent adoption across both central services and decentralised environments. The position acts as a key link between Group Information Security, central platform teams and OpCos, ensuring that security standards, risk management practices, and compliance requirements are effectively implemented and embedded across the organisation.

This role plays a critical part in reducing cyber risk at scale, enabling a consistent security posture while respecting the operational realities of a federated, multi-country business.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Key Tasks And Responsibilities

In this role, you will:

  • Develop and maintain cyber security policies, standards, and control frameworks, ensuring alignment with CRH Group requirements and applicability across both central platforms (UnITy) and OpCo-managed environments.
  • Drive consistent adoption of security standards across central technology services and OpCos, balancing global governance with local implementation models.
  • Provide risk-based guidance across both centrally delivered services and decentralised OpCo environments (e.g. IAM, network, endpoint, vulnerability management).
  • Perform and support cyber risk assessments across UnITy platforms and OpCos, maintaining risk registers and tracking remediation to reduce enterprise risk exposure.
  • Coordinate and support compliance and assurance activities, acting as a central interface between UnITy service teams, OpCos, and auditors.
  • Support the delivery of the CRH International cyber programme, ensuring alignment between central technology initiatives and OpCo execution.
  • Interpret and translate regulatory, legal, and contractual requirements into scalable and consistent controls applicable across both central and local operating models.
  • Support third-party and supply chain risk management across both centrally managed services and OpCo suppliers, ensuring consistent security expectations and remediation tracking.

Key Functional Competencies

You Possess The Following:

  • Strong understanding of cyber security frameworks (NIST CSF, ISO 27001, CIS)
  • Experience in risk management, control design, and audit support
  • Ability to translate technical risks into business impact
  • Strong stakeholder management across technical and non-technical audiences
  • Structured, pragmatic, and delivery-focused mindset
  • Experience operating in a federated or multi-entity organization
  • Exposure to third-party risk and regulatory environments
  • Familiarity with ServiceNow or similar GRC tooling
  • Security certifications (e.g. CISM, CRISC, ISO 27001)

Key Characteristics

For This Role You Should Be/have:

  • Pragmatic approach to GRC and willing to learn and adopt
  • Problem solver and resolves conflicts.
  • Looks for ways to innovate to improve the focus on the customer.
  • Motivated and can deal with resistance.
  • Coaches others to build on strengths and improve on weakness; listens to and encourages regular honest feedback.
  • An inclination to drill into detail and to take corrective action early and decisively.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Individual Competencies

You Are Able To:

  • Drive Results - Consistently achieving objectives, even under tough circumstances, pushing self and others to accomplish goals
  • Have Courage - Stepping up to address difficult issues, saying what needs to be said.
  • Cultivate Innovation - Creating new and better ways for the organisation to be successful
  • Collaborate - Building partnerships and working collaboratively with others to meet shared objectives

Experience / Education

  • 3-5 years’ experience in Information/IT security
  • Good to have certifications like CISM/CISSP/CRISC/GRCP/ISO27001 lead implementor
  • Fluency in both speaking and writing English.

Additional Information

  • Number of Managed Users: 33k+
  • Geographies Supported: 20+ Countries
  • Headcount within the IT Operations team: 60+
  • Headcount across European IT teams: 450+

What CRH Offers You

  • A culture that values opportunity for growth, development, and internal promotion
  • Highly competitive salary package
  • Comprehensive secondary benefits
  • Significant contribution to your pension plan
  • Health and wellness programs, including an on-site gym and fitness classes
  • Excellent opportunities to develop and progress with a global organization

Connect your future to CRH

We are curious to learn more about you. At CRH, we believe our mutual differences contribute to the healthy, productive, and enjoyable workspace we create. Please introduce yourself and send us your application. Following a positive review of your application, you will be invited to an introductory call with one of our Recruiters.

Is this role not for you, but do you know someone who would love to join the team? Please let us know!

CRH finds it important that vacancies are shared to individuals that may find them interesting and/or could be suitable for the role

Please contact our recruitment team at careers@crh.com.

CRH is an equal opportunity employer. We are committed to creating an inclusive work environment for all employees and actively encourage applications from all sectors of the community.

Benefits/perks listed above may vary depending on the nature of the employment with CRH and the country where you work.

Please note that we cannot accept any applications submitted through email for GDPR purposes. Candidates must apply through our job portal.

We do not accept candidate introductions for this position from recruitment agencies, unless you have been instructed to do so by our recruitment team.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Cyber Security Governance
Risk Management
Compliance
Control Design
Audit Support
Stakeholder Management
Third-Party Risk Management
NIST CSF
ISO 27001
CIS
ServiceNow
Vulnerability Management
IAM
Network Security
Endpoint Security

Location

Birmingham, England, United Kingdom

Sign up to applySee more jobs like this