Tiger Resourcing Group
Cybersecurity GRC Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role Overview
We are seeking an experienced Cybersecurity Governance, Risk and Compliance Analyst to support cybersecurity assurance, audit and risk-management activities across a major operational handover programme.
The role will provide oversight of the security implications associated with the transfer of services and systems, with particular focus on identifying and managing risks created during the transition process.
You will also support knowledge transfer and provide training to the incoming organisation’s security, risk-management and audit teams.
This is a key role within the programme, ensuring that appropriate cybersecurity controls, certifications and governance processes remain effective throughout the transition.
Key Responsibilities
- Conduct cybersecurity risk assessments and security-control reviews across business applications, infrastructure and computer installations being transferred as part of the handover programme.
- Identify security risks and recommend appropriate remediation or risk-treatment actions to programme management.
- Maintain ISO 27001 and PCI-DSS certification and recertification activities throughout the programme.
- Maintain programme and handover cybersecurity risk registers and associated treatment plans.
- Ensure agreed security-support processes are followed throughout the handover programme.
- Conduct ad-hoc internal security audits across relevant security-control areas, working closely with quality assurance, technology and service teams.
- Document security non-compliances, agree remediation actions with the programme leadership team and monitor progress through to completion.
- Design and, where required, implement security policies, standards, guidelines, processes and procedures.
- Ensure continued compliance with the organisation’s Information Security Management System, ISO 27001, PCI-DSS, contractual obligations and relevant legislation.
- Review handover-related change requests and assess their potential impact on existing security controls and mechanisms.
- Ensure planned technical changes do not unnecessarily compromise or weaken existing cybersecurity controls.
- Produce clear security, risk, compliance and audit reporting for the programme leadership team.
- Provide input into wider cybersecurity, business-continuity and contingency-planning activities.
- Support knowledge transfer and training for the incoming organisation’s security risk-management and audit personnel.
- Work collaboratively with internal teams, customers, suppliers, security vendors and programme partners.
- Travel to other operational sites and data centres where required.
- Comply with all relevant company policies, including the code of conduct, quality, security, health and safety, and environmental procedures.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Essential Qualifications
- A recognised information-security certification, such as:
- CISA, CISM or CRISC
- CISSP
- BCS CISMP
- IISP certification or equivalent
Desirable Qualifications
- Degree in information security, computer science, engineering, mathematics, encryption or another relevant discipline, or equivalent professional experience.
- Information privacy or data-protection qualifications, such as CIPP/E or CIPM.
- Payment Card Industry Security Standards Council certification, such as ISA or QSA.
- ITIL, PRINCE2 Foundation or TOGAF certification.
- Relevant infrastructure or networking vendor certifications.
Essential Experience and Knowledge
- Strong experience within cybersecurity governance, risk, audit and compliance management.
- Experience working within a complex IT, technology or operational environment.
- Thorough understanding of information-security audit methodologies and control-assessment techniques.
- Experience operating and auditing an ISO 27001-compliant Information Security Management System.
- Experience managing PCI-DSS certification, recertification and audit activities.
- Experience implementing or operating within a PCI-DSS-compliant security environment.
- Strong knowledge of cybersecurity technologies, controls, frameworks and risk-management methodologies.
- Experience assessing cybersecurity implications within formal change-management processes.
- Demonstrable stakeholder-management experience, including leading consultations, workshops and presentations.
- Experience creating and maintaining security policies, standards, procedures, guidance, processes and awareness materials.
- Experience managing security risks, remediation plans, audit findings and compliance actions through to completion.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable Experience
- Experience working with additional security, risk and compliance frameworks, including:
- PCI P2PE
- PCI POI PTS
- ISO 22301
- ISO 27005
- ISO 31000
- NIST security and risk frameworks
- GDPR and wider data-protection legislation
- Experience within transactional revenue, embedded systems, smartcards, mobile payments, open-payment systems or EMVCo environments.
- Experience using cybersecurity governance, risk and compliance platforms.
- Experience using IT service-management tools.
- Familiarity with vulnerability-management and security-operations tooling.
- Experience working with quality-management systems and external audit standards such as ISO 9001.
- Previous experience supporting a complex operational handover, transition or service-transfer programme.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location