IMT Resourcing Solutions
GRC Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
GRC Analyst – Information Security
6 Month Contract – Likely Extension
Cheltenham – 1 day per week onsite
Up to £350 per day – Inside IR35
We’re looking for an experienced GRC Analyst to support an established organisation with its information security governance, risk and compliance activity.
This is a hands-on role suited to someone with strong knowledge of security frameworks including ISO 27001 and NIST, who can work with technical and business teams to assess risk, maintain controls and support ongoing compliance.
Microsoft security experience would be particularly useful, especially across the wider Microsoft 365 and Azure security ecosystem.
The Role
You’ll work closely with security, technology and wider business stakeholders, with responsibilities including:
- Supporting the organisation’s ISO 27001 ISMS, including maintaining policies, controls and supporting evidence
- Working with security frameworks including ISO 27001, NIST CSF and CIS Controls
- Conducting and maintaining information security risk assessments
- Managing security risks, controls, actions and remediation plans
- Supporting internal and external security audits and assessments
- Reviewing existing security controls and identifying areas for improvement
- Maintaining security policies, standards, procedures and governance documentation
- Supporting third-party and supplier security assessments
- Tracking compliance against relevant security frameworks and organisational requirements
- Working with technical teams to ensure security controls are implemented effectively
- Producing security reporting, metrics and governance information for stakeholders
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What We’re Looking For
You’ll ideally have:
- Strong commercial experience within GRC, Information Security or Cyber Security
- Good working knowledge of ISO 27001
- Experience working with NIST, ideally NIST CSF
- Practical experience of security risk management and control assessments
- Experience supporting security audits and compliance activity
- Strong understanding of security policies, governance and assurance
- Experience working with technical and non-technical stakeholders
- The ability to take ownership of GRC activity rather than purely providing administrative support


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Experience with Microsoft security tooling would be highly desirable, particularly:
- Microsoft Purview
- Microsoft Defender
- Microsoft Sentinel
- Microsoft Entra ID
- Microsoft 365 and Azure security/compliance controls
Relevant certifications such as ISO 27001 Lead Implementer/Auditor, CISM, CRISC, CISSP or equivalent would be beneficial but aren't essential.
Contract Details
- Contract: Initial 6 months
- Location: Cheltenham – 1 day per week onsite
- Extension: Strong possibility of extension
- Day Rate: Up to £350 per day
- IR35: Inside IR35
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills