Pennon Group
Cyber Security GRC Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Powered by Water, Driven by Purpose
South West Water keeps the South West flowing with safe, reliable drinking water and wastewater services across some of the UK’s most stunning landscapes.
We’re proud to be part of Pennon Group, a leader in the UK water sector, working towards a greener future. Our goals? As well as lowering our carbon footprint, we’re working with partners to plant 300,000 trees, restore peatlands and supporting farmers and landowners to improve water quality and wildlife.
Whether you’re starting out or seeking a new challenge, our scale and ambition create opportunities for you to shape your own career.
Ready to make a splash? Join our team today.
Help protect critical services through effective cyber security governance
Are you passionate about cyber security, data governance and compliance? Do you enjoy translating complex security requirements into practical controls that make a real difference?
We're looking for a Cyber Security GRC Analyst to join our growing Cyber Security team. In this role, you'll play a key part in strengthening our cyber security posture through governance, risk management and compliance activities, while helping to ensure our information assets remain protected.
A significant focus of the role will be the administration and continual improvement of Microsoft Purview, ensuring effective data protection, information governance, data classification and compliance capabilities are embedded across the organisation.
Working closely with stakeholders across IT, Legal, Audit, Procurement and the wider business, you'll help shape security practices, drive compliance initiatives and support a positive security culture.
What you'll be doing:
As our Cyber Security GRC Analyst, you will:
- Administer, maintain and continuously improve Microsoft Purview capabilities, including:
- Data Loss Prevention (DLP)
- Information Protection
- Data Lifecycle Management
- Insider Risk Management
- Communication Compliance
- eDiscovery
- Compliance Manager
- Support the implementation and adoption of data classification and sensitivity labelling.
- Monitor security and compliance alerts, investigate findings and coordinate remediation activities.
- Develop and maintain security policies, controls and standards.
- Produce management reporting, dashboards and compliance metrics.
- Plan, conduct and document internal ISO 27001 audits.
- Support third-party risk management and supplier security assurance activities.
- Help maintain compliance with frameworks and regulations such as ISO 27001, NIS Regulations and Cyber Essentials.
- Support information security awareness initiatives and promote a strong security culture.
- Assist in security incident investigations and remediation activities.
- Work with business stakeholders to improve information governance practices and data ownership accountability.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What we're looking for:
- Experience administering or supporting Microsoft Purview and Microsoft 365 security and compliance solutions.
- Knowledge of Microsoft Purview capabilities, including DLP, Information Protection, Sensitivity Labels, Insider Risk Management, eDiscovery and Compliance Manager.
- Experience supporting data governance, information protection and compliance activities within a Microsoft 365 environment.
- An understanding of cyber security risk management, governance and control frameworks.
- Knowledge of information security standards such as ISO 27001, NIS Regulations and Cyber Essentials.
- Experience producing reports, managing stakeholders and supporting audit activities.
- Strong communication skills with the ability to influence and build relationships across diverse teams.
Essential
- 5 GCSEs (or equivalent), including Maths and English.
- Educated to degree level or able to demonstrate equivalent professional experience.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable
- Hands-on experience of Microsoft Purview administration and optimisation.
- Experience within information security, governance, risk or compliance functions.
- Knowledge of recognised security frameworks such as ISO 27001, NIST or Cyber Essentials.
- Ability to successfully obtain UK Government Security Clearance (SC).
Why join us?
This is an excellent opportunity to develop your cyber security governance and compliance career within a supportive environment. You'll gain exposure to enterprise-scale Microsoft security technologies, contribute to critical compliance programmes and play a meaningful role in protecting services, systems and data that matter.
- Generous holiday allowance plus bank holidays
- A discretionary Bonus
- Competitive Contributory Pension
- Share-save Scheme
- Various health benefits
- Wellbeing support programmes
- A range of Group Discounts
- Cycle to Work Scheme
Closing Date: 1st September 2026
We may close this vacancy early if we receive a high volume of applications. We encourage you to apply as soon as possible.
Please note that the successful candidate will be subject to a mandatory DBS check as part of the onboarding process.
Be yourself, we like it that way. Together, we will build a culture of belonging, where inclusion is instinctive. Diversity is our strength and a reflection of our communities. We care, we value everyone, we celebrate uniqueness.
Our core values, which are essential to our success, are:
- Be Rock Solid - Build trust and be trusted. Be the one we all look to and can depend on.
- Be You - We want you to bring your best everyday. Be yourself and make your mark in your individual way.
- Be the Future - Embrace change. Drive Progress. Own the challenge.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location