Clue Software
Security GRC Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role specifics
Salary range: £60,000 – 70,000
Reporting to: Chief Information Officer
Key stakeholders: Platform and Development, Product, Sales and Onboarding, IT Operations, Legal Counsel and DPO, People team, our managed security operations provider, customer security and assurance teams
Organisational Framework Level: Level 3 – Professional Specialist
Eligible to obtain UK security clearance (SC). UK-based.
Minimum requirement of 2 days per week in our Bristol office
About you/ Job Summary
As a Security Governance, Risk and Compliance Analyst, you keep our information security management system current, evidenced and moving. Clue supplies software to UK public sector, Sports and law enforcement, and those customers expect us to show, not just say, that our controls work. You will administer our ISO 27001 ISMS day to day, maintain the risk register, lead customer security assurance, run the supplier assessment cycle and coordinate the record-keeping and communications when an incident occurs. The CISO leads the security function, sets direction, and holds accountability; the Security Engineering team and IT own the technical controls. Your job is to do the work between them intelligently: know where every piece of evidence lives, what we have promised each customer, what is due next, and who needs chasing.
At Clue we are actively adopting AI to improve our products and workflows. You will bring curiosity and a willingness to use AI tools to work faster and more accurately, while knowing where they should not be trusted.
Key Accountabilities
ISMS and certification
- Administer the information security policy, set: review schedule, publication and acknowledgement records, with the CISO approving changes.
- Maintain ISO 27001:2022 certification: statement of applicability, evidence library, internal audit scheduling and external audit coordination.
- Work with IT to maintain security accreditations such as Cyber Essentials Plus and our ISO accreditations, plus the evidence set for the NCSC Cyber Assessment Framework where customers require it.
- Maintain the security exceptions register, tracking time-limited approvals and named risk sponsors.
- Pen-test and crisis simulation exercise management and coordination, alongside the CISO.
Risk management
- Maintain the risk register and apply the scoring model set by the CISO. Keep entries current, sponsored and treated.
- Prepare and coordinate the monthly risk register review with executive risk sponsors, and track treatment plans to closure.
- Draft register entries from audit findings, incident lessons, threat assessments and customer requirements, for CISO review, each with a proposed owner.
- Maintain the list of security-related product roadmap requests and coordinate prioritisation between the CISO and Product.
Customer assurance and contractual compliance
- Lead customer security assurance: draft questionnaire responses, assemble evidence packs and handle due diligence requests, drawing technical input from the DevSecOps Engineer and IT Operations.
- Maintain the single record of every security commitment made to a customer.
- Carry out compliance checks of customer environments before go-live and report the results to the CISO for sign-off.
- Track our obligations under CCS framework security schedules and G-Cloud 15 Call-Off Schedule 9A, and maintain the evidence for each.
- Produce customer-facing assurance reporting, including the monthly vulnerability report within five working days of month end.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Security operations governance
- Coordinate the day-to-day relationship with our managed security operations provider: track service levels, prepare monthly service reviews and maintain the detection improvement backlog.
- Track vulnerability remediation against contractual windows, record exceptions and report performance.
- Maintain the protective monitoring standard and the logging and monitoring evidence an assurance review will test.
- Keep a record of threat intelligence intake from NCSC and other sources, and of the actions taken.
Incident management
- Act as incident coordinator: convene the response channel, keep the record, apply the severity matrix and escalation path without discretion, and track actions to closure. The CISO chairs incidents and coordinates Clue response.
- Prepare and track customer and regulatory notifications, including any contractual out of hours customer notification and the UK GDPR 72-hour ICO window, with Legal and the DPO.
- Maintain the incident register, organise post-incident reviews and track corrective actions.
- Maintain the annual crisis exercise plan and organise the exercises.
Third-party risk management
- Operate the supplier assurance process and platform: onboard, tier and reassess suppliers on a risk-based cycle.
- Keep a named executive sponsor recorded for each material supplier and chase their review obligations.
People, access and awareness
- Draft security awareness and training requirements and assure delivery with the People team.
- Support the People Director with the vetting policy and collect the evidence that personnel security controls operate.
- Collect and check access governance evidence: review schedules, privileged access records and joiner, mover and leaver records.
- Support the Security Champions network with process guidance.
Governance and reporting
- Organise the governance cadence: weekly security governance, fortnightly Security Steering Group, monthly risk review and quarterly Information Security Management Forum. Agendas, papers, minutes and actions.
- Draft sponsor and board-level reporting for the CISO, sourced and consistent across documents.
- Track every security action to a named owner and a date, and report status without spin.
Key role measures
- ISO 27001 certification maintained with no major nonconformities; audit findings closed within agreed date
- Risk register currency: every entry reviewed within its cycle, sponsored, and with a live treatment plan
- Customer assurance turnaround: questionnaires and evidence requests answered within agreed SLAs with no unsupported commitments
- Vulnerability remediation reported accurately against contractual windows, with exceptions recorded
- Incident notifications made within contractual and regulatory windows; post-incident actions closed
- Supplier coverage: all material suppliers tiered, assessed and sponsored


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Experience and skills
Our ideal candidate would have experience in the following areas:
Information security management
- Working within an ISO 27001 ISMS through certification or surveillance audits, ideally in a SaaS organisation.
- Maintaining a risk register and working with senior risk owners to keep entries current and treated.
- Keeping exceptions, policies and evidence to an audit-ready standard.
Customer and public sector assurance
- Responding to customer security questionnaires and due diligence, ideally for UK public sector customers.
- Working knowledge of CCS framework security schedules, G-Cloud Schedule 9A, Cyber Essentials Plus and the NCSC Cyber Assessment Framework.
- Good understanding of data protection and UK GDPR, including Articles 28 and 33.
Supplier and service governance
- Tracking a managed service or supplier against contract and service levels and preparing service reviews.
- Third-party risk management, including experience of a TPRM platform (desirable).
Incident management
- Coordinating security incidents, keeping records and preparing customer or regulatory notifications.
Technical literacy
- Enough understanding of cloud, SIEM and vulnerability management to read a service report or scan output and ask the right questions. You will not be writing detection rules.
Communication and ways of working
- Clear, precise written English. Your reports and evidence will be read by customers, auditors and executives.
- Organised and self-directed, able to keep several governance cycles moving in parallel and chase others to dates politely and persistently.
Qualifications
- ISO 27001 Lead Implementer or Lead Auditor, CISM, CRISC, CISMP or equivalent (desirable).
Diversity, Equity and Inclusion
If you’re excited about this role but your experience doesn’t align perfectly, we encourage you to apply anyway and tell us more about yourself. You may be just the right candidate for this or other roles.
We believe that seeing the world from all sorts of angles makes life better for all. We want you to know that the things that make you an individual, like your identity, age, ethnicity, religion, ability and background, are things that we choose to celebrate and support.
We are a scale-up company, and as we continue to grow, we are passionate that having a diverse, inclusive and authentic workplace will remain at our core. We are creating an inclusive environment where our people can thrive.
Our values are aligned and at the heart of everything we do. We are respectful, united, rigorous, relentless and ethical.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London