SoTalent
Information Security GRC Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Information Security GRC Analyst
๐ Location: London Area, United Kingdom
๐ข Industry: Outsourcing and offshoring
๐ผ Work Setting: Hybrid
Are you passionate about information security governance, risk management, compliance, and helping organizations strengthen their security posture through effective controls and frameworks?
We are seeking an experienced Information Security GRC Specialist to support and enhance the organization's Governance, Risk, and Compliance (GRC) program. This role will focus on information security risk assessments, ISO 27001 implementation, third-party risk management, audit compliance, policy governance, and security awareness initiatives.
The ideal candidate combines strong risk management expertise, knowledge of security frameworks, regulatory compliance experience, and the ability to communicate technical security risks in clear business terms.
Key Responsibilities
Information Security Risk Management
- Conduct information security risk assessments in accordance with organizational policies and industry best practices.
- Evaluate threats, vulnerabilities, likelihood, and business impact to determine risk exposure.
- Maintain and update the corporate information security risk register.
- Work with stakeholders to develop and monitor corrective action plans.
- Monitor risk remediation activities and ensure risks are reduced to acceptable levels.
- Continuously improve risk assessment methodologies, processes, and documentation.
Governance, Risk & Compliance (GRC)
- Support enterprise GRC programs and governance activities.
- Prepare risk dashboards, metrics, and reports for senior leadership.
- Coordinate risk reviews and compliance assessments.
- Provide analysis and recommendations regarding security risk trends.
- Translate technical security issues into meaningful business risk language.
ISO 27001 Implementation & Compliance
- Support implementation, maintenance, and continuous improvement of the ISO 27001 Information Security Management System (ISMS).
- Ensure controls, policies, and procedures align with ISO 27001 requirements.
- Assist in certification readiness and compliance activities.
- Support internal audits and management reviews.
- Help drive ongoing compliance initiatives across the organization.
Reasons to use Rodeo
Iโm in my final year doing Economics and I donโt know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer โ it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) donโt need a masters. Letโs look at the ones youโd be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet โ that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant โ 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
Youโve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon โ deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme โ client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right โ and where to focus when applying.
Third-Party Risk Management
- Perform security assessments of vendors, suppliers, and third-party service providers.
- Evaluate third-party security controls, compliance posture, and risk exposure.
- Identify deficiencies and recommend remediation actions.
- Monitor third-party risk management activities and reporting.
Policy Management & Security Governance
- Develop, review, and maintain information security policies, standards, procedures, and guidelines.
- Ensure policies remain aligned with evolving regulatory and security requirements.
- Communicate policy updates and provide guidance to stakeholders.
- Promote consistent application of information security controls and governance practices.
Audit & Regulatory Compliance
- Support internal and external security audits.
- Track audit findings, recommendations, and remediation activities.
- Ensure timely closure of audit observations.
- Maintain compliance with applicable regulatory, legal, and organizational requirements.
- Assist with evidence gathering and compliance documentation.
Security Awareness & Training
- Develop and maintain security awareness programs.
- Deliver information security guidance and educational materials to employees.
- Support organization-wide security training initiatives.
- Promote a strong security culture across the business.
- Track participation and effectiveness of awareness activities.
Business Continuity & Resilience
- Support Business Continuity Planning (BCP) and IT Disaster Recovery (ITDR) initiatives.
- Participate in assessments and testing activities.
- Ensure continuity controls align with organizational requirements and risk management objectives.
- Contribute to resiliency planning and continuous improvement efforts.
Security Certifications & Continuous Improvement
- Assist in achieving and maintaining security certifications such as:
- ISO 27001
- Cyber Essentials Plus
- Other security assurance frameworks
- Support security improvement programs and governance initiatives.
- Stay current on evolving security regulations, standards, and industry best practices.
Incident & Investigation Support
- Assist with security investigations and risk-related analysis.
- Collaborate with technical security teams during incident management activities.
- Provide governance support during security events and remediation efforts.
- Help identify control improvements following incidents or assessments.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Qualifications
Required Education
- Bachelor's Degree in:
- Information Technology
- Computer Science
- Cyber Security
- Information Security
- Related Discipline
Required Certifications
- ISO 27001 Lead Implementer and/or Internal Auditor Certification.
- One or more of:
- CRISC
- CGRC
- CGEIT
Required Experience
- 5+ years of experience in:
- Information Security
- Governance, Risk & Compliance (GRC)
- Risk Management
- IT Security
- Experience implementing and maintaining ISO 27001 programs.
- Experience supporting Business Continuity and IT Disaster Recovery initiatives.
- Experience conducting:
- Risk Assessments
- Impact Assessments
- Third-Party Security Reviews
- Compliance Audits
- Strong understanding of GRC reporting and governance processes.
Required Skills
- Information Security Governance
- Risk Management
- Security Compliance
- Risk Assessment Methodologies
- Audit Management
- Policy Development
- Third-Party Risk Management
- Regulatory Compliance
- Security Awareness Programs
- Business Continuity Planning
- IT Disaster Recovery
Preferred Skills
- Knowledge of:
- NIST Frameworks
- Cyber Audit Methodologies
- Regulatory Security Standards
- Strong analytical and problem-solving abilities.
- Ability to simplify complex security concepts for business stakeholders.
- Experience presenting security risks and recommendations to senior leadership.
- Excellent written and verbal communication skills.
Core Competencies
- Information Security Governance
- Governance, Risk & Compliance (GRC)
- ISO 27001
- Risk Assessment & Risk Treatment
- Third-Party Risk Management
- Security Audits & Compliance
- Business Continuity & ITDR
- Policy & Control Management
- Security Awareness & Training
- Regulatory Compliance
- Audit Remediation
- Risk Reporting & Dashboards
- Stakeholder Management
- Information Security Program Management
โIt took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what Iโve been looking for.โ
Jessica, London
Skills
Location