Dunelm
Governance, Risk & Compliance (GRC) Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Overview
Home. There’s no place like it.
And there’s no feeling like helping people create the joy of feeling truly at home. At Dunelm, that’s what we do. We’re the UK's number one choice for homewares because we make home life lovelier for our customers. And we’ve crafted a workplace that feels just as welcoming – where you can bring your ideas, be yourself, and feel right at home.
Work your way, together
We're a hybrid business, which means you'll have flexibility alongside time together with your team. In this role, you can expect minimum 1 day per week in our Leicester office.
We are seeking an experienced Governance, Risk & Compliance (GRC) Analyst to join our Information Security team within a FTSE 250 retail organisation. This role is responsible for developing, implementing and continually improving the organisation's cyber security governance, risk and compliance capabilities, ensuring alignment with business objectives, regulatory obligations and industry best practice.
Working collaboratively across technology, digital, retail operations, finance, legal, procurement, HR and other business functions, you will help strengthen the organisation's cyber security maturity, support regulatory compliance and embed security into everyday business processes.
The successful candidate will have a strong understanding of cyber security frameworks, governance principles and risk management, combined with excellent stakeholder management and communication skills.
Join our Cyber Security Team and be at the forefront of protecting our business. You’ll contribute to safeguarding our operations and drive positive change and in a business where you can build a long-term career that always promises to challenge and excite.
What you'll be doing
Governance & Compliance
- Develop, maintain and continually improve our Information Security Management System.
- Support and maintain compliance with:
- PCI DSS eCommerce and Card present payment channels.
- NIST Cyber Security Framework (CSF) 2.0
- UK Data Protection Act 2018 and relevant EU data privacy legislation.
- Other relevant regulatory and industry requirements such as Provision 29, Cyber Essentials and Cyber Essentials Plus.
- Support evidence collection for compliance activities.
- Monitor emerging legislation and regulatory changes, assessing business impact.
- Support the implementation of security governance across all business functions.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Risk Management
- Administer the Cyber Security risk register toolset.
- Facilitate cyber risk assessments across projects, business initiatives and operational services.
- Support risk owners throughout the cyber security risk lifecycle.
- Enhance risk reporting for senior leadership and executive committees.
Third Party Risk Management
- Oversee the supplier cyber security assurance process.
- Conduct security assessments of suppliers, partners and third parties.
- Help to highlight supply chain risks and recommend appropriate mitigation.
- Track supplier security due diligence.
- Monitor ongoing supplier compliance throughout the contract lifecycle.
Security Governance
- Develop and maintain Information Security policies, standards, procedures and supporting guidance.
- Ensure documentation remains current, aligned with business objectives and regulatory requirements.
- Support governance forums and security steering committees.
- Produce reports for senior management and executive stakeholders.
- Assist in maintaining security exceptions and risk acceptance processes.
Security Awareness & Culture
- Help develop cyber security awareness programmes.
- Contribute to phishing simulations and awareness campaigns.
- Review effectiveness of these measures through reporting and behavioural metrics.
- Promote a positive security culture across stores, support centres and digital teams.
- Support onboarding and annual security training programmes.
Metrics & Continuous Improvement
- Develop governance and compliance KPIs and KRIs.
- Administer metrics addressing:
- Compliance status
- Audit findings
- Risk posture
- Third-party assurance
- Policy compliance
- Security awareness completion
- Security maturity
- Benchmark organisational maturity against recognised frameworks.
- Drive continual improvement initiatives across governance and compliance processes.
Business Partnership
- Act as a trusted advisor to business stakeholders.
- Work closely with relevant stakeholders across the business.
- Provide pragmatic security advice supporting business innovation while managing cyber risk.
- Support projects by embedding security governance from inception.
What we'll look for in you
You will need to be a self-starter with ability to work at pace across multiple business levels and with stakeholders across all levels of seniority.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Essential Skills & Experience
- Experience in a Governance, Risk & Compliance, Information Security or Cyber Security role.
- Strong understanding of:
- Cyber Security Risk
- NIST Cyber Security Framework (CSF) 2.0
- PCI DSS
- UK GDPR and Data Protection Act 2018
- Experience conducting cyber risk assessments.
- Experience with third-party security assurance programmes.
- Experience writing policies, standards and governance documentation.
- Experience supporting audits and regulatory compliance activities.
- Experience producing security metrics and executive reporting.
- Excellent stakeholder management skills.
- Strong analytical and problem-solving ability.
- Excellent written and verbal communication skills.
- Ability to influence stakeholders at all organisational levels.
Desirable Experience
- Experience within a FTSE 250 or large enterprise environment.
- Experience in retail, eCommerce or omnichannel businesses.
- Familiarity with cloud security.
- Knowledge of Secure by Design principles.
- Experience with GRC platforms (e.g. LogicGate, OneTrust, Archer or AuditBoard).
- Experience supporting security framework certification programmes (e.g. ISO27001).
- One or more of the following professional Cyber Security certifications is preferred:
- ISO/IEC 27001 Lead Implementer or Lead Auditor
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Privacy Professional Europe (CIPP/E)
- PCI Professional (PCIP)
- Internal Security Assessor (PCI - ISA)
- NIST Cyber Security Framework Practitioner
Behaviours/Values
Our shared values of 'act like owners', 'keep listening and learning', 'long term thinking', and 'stronger together' help ensure we are always finding better ways of doing things and spending our time focusing on what’s important.
- Excellent communication skills
- Collaboration across all business functions and tech teams
- Customer focussed
- Responsible and show integrity
- Self-motivated, calm persona, attention to detail
- Ability to deliver under pressure
- Ability to keep up to date on latest cyber-threats and skills using available study tools, partners, etc
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London