Rodeo
Get started

Jobgether

Information Security Analyst, GRC

UK
Posted about 11 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Job Title: Information Security Analyst, GRC

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Information Security Analyst, GRC based in United Kingdom.

Join a remote-first security team operating at the intersection of cybersecurity, AI, compliance, and risk management.

You’ll help strengthen the organization’s security and trust function while supporting customers and prospects through complex security reviews.

The role combines technical security knowledge with governance, risk, compliance, and third-party risk management.

  • You’ll work closely with IT, Security, Engineering, Legal, Sales, and Customer teams to communicate security controls and manage risk effectively.
  • Your work will contribute to maintaining compliance with leading frameworks while improving how risks are identified, assessed, documented, and remediated.
  • You’ll also have opportunities to streamline and automate GRC processes as the organization scales.
  • This individual contributor role offers significant ownership and the potential to grow into a broader risk and compliance leadership scope.

Accountabilities

  • Support customers and prospects by completing technical security questionnaires, risk assessments, due-diligence requests, and security reviews.
  • Partner with Sales and Customer teams to clearly explain security controls, architecture, compliance posture, and risk management practices.
  • Assess and manage security risks associated with third-party vendors, SaaS providers, and service partners.
  • Investigate and resolve compliance alerts and support ongoing compliance activities using GRC tooling such as Vanta.
  • Maintain and continuously improve risk assessment frameworks, methodologies, processes, and supporting documentation.
  • Track identified risks through remediation in collaboration with relevant internal stakeholders.
  • Contribute to compliance initiatives aligned with frameworks and standards including SOC 2, FedRAMP 20x, ISO 27001, and ISO 42001.
  • Maintain accurate and well-structured risk registers, security policies, evidence, and other compliance documentation.
  • Coordinate risk management sessions and support ongoing risk governance processes.
  • Identify opportunities to simplify, streamline, and automate risk and compliance activities as the organization grows.
  • Support internal assurance activities, audits, customer reviews, and other security-related assessments.
  • Collaborate across IT, Security, Engineering, Legal, Sales, and Customer teams to ensure security and compliance requirements are understood and addressed.
  • Help strengthen the overall security and trust function through practical, scalable, and risk-based processes.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Requirements

  • 7+ years of experience in information security, risk, compliance, security assurance, or a related discipline.
  • Hands-on experience in a technical environment such as Engineering, IT, operational security, or a comparable function.
  • Proven experience completing or reviewing technical security questionnaires, customer security assessments, and due-diligence requests.
  • Strong knowledge of security, compliance, and data protection frameworks such as SOC 2, ISO 27001, NIST, GDPR, and HIPAA.
  • Practical experience conducting or supporting third-party and vendor security risk assessments.
  • Strong written and verbal communication skills, with the ability to explain complex security concepts clearly to both technical and non-technical audiences.
  • Highly organized and detail-oriented, with a pragmatic approach to identifying and managing risk.
  • Comfortable working independently and taking ownership in a fast-moving, remote-first startup environment.
  • Familiarity with modern AI tools and the ability to use them productively while appropriately managing associated risks.
  • Strong analytical and problem-solving skills, with the ability to balance security requirements against business priorities.
  • Experience in a SaaS or cybersecurity-focused organization is advantageous.
  • Experience handling GDPR Subject Access Requests is a plus.
  • Security or risk certifications such as CRISC or CISSP are valued.
  • Knowledge of cloud security best practices is beneficial.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Benefits

  • Competitive compensation: Attractive salary package aligned with experience and responsibilities.
  • Equity: Meaningful stock options providing an opportunity to participate in the organization’s growth.
  • Remote-first: Work remotely within the eligible European region.
  • Flexible environment: Work in a distributed environment designed to support autonomy and ownership.
  • Career growth: Opportunity to expand your responsibilities as the risk, compliance, and security function matures.
  • Expert collaboration: Learn from and work alongside experienced professionals in cybersecurity, AI, engineering, and security operations.
  • Meaningful impact: Contribute to the security and compliance foundation of an organization operating at the forefront of AI-driven cybersecurity.
  • Cross-functional exposure: Partner with teams across engineering, IT, legal, sales, customer success, and security.
  • International collaboration: Work with a globally distributed team and have regular opportunities to connect with colleagues in person.

How Jobgether Works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

United Kingdom

Sign up to applySee more jobs like this