The Opportunity
We are seeking an experienced Senior IT Cyber Governance, Risk & Compliance Analyst to support the ongoing development and oversight of IT governance, cyber risk and compliance across a regulated organisation.
This is a broad role offering the opportunity to work closely with IT, Cyber Security, Risk, Legal, Compliance and wider business stakeholders. You will play an important role in identifying and managing technology and cyber risks, supporting regulatory compliance, coordinating audit activity and ensuring effective remediation of control gaps and vulnerabilities.
Key Responsibilities
- Support IT and cyber compliance across frameworks including DORA, ISO 27001, NIST CSF, SOX and Cyber Essentials.
- Identify, assess and monitor IT, cyber, security and operational risks.
- Maintain and develop the cyber risk register, tracking risks, issues and remediation activity.
- Support internal, external, regulatory and third-party audits, including evidence gathering and remediation tracking.
- Monitor emerging technology, cyber and operational resilience risks and escalate issues where appropriate.
- Support third-party and supplier security assurance, including due diligence and remediation tracking.
- Coordinate user access and privileged access reviews, supporting the transition towards automated access certification.
- Perform first-line compliance monitoring and control testing against information security policies and standards.
- Contribute to the development and maintenance of IT risk, cyber security and compliance policies, standards and procedures.
- Prepare risk, control and remediation reporting for senior management and governance forums.
- Support the development and monitoring of relevant IT risk and compliance KPIs.
- Assist with breach notification, escalation and regulatory reporting activities where required.
- Support the delivery of cyber risk, governance and compliance awareness and training.
You will bring:
- Strong knowledge of IT risk, governance, security and compliance frameworks.
- Experience supporting audits, regulatory reviews and compliance programmes.
- Good understanding of infrastructure, applications, networking, cloud, vulnerability management, incident management and access controls.
- Experience with SOX / IT General Controls (ITGCs) would be advantageous.
- Experience within financial services, insurance or another regulated sector would be beneficial.
- Strong analytical and problem-solving skills, with the ability to identify control gaps and drive remediation.
- Excellent communication skills and the ability to explain technical and risk-related matters to non-technical stakeholders.
- A relevant degree or equivalent professional experience.
- Professional qualifications such as CISA, CISM, CRISC, CISSP or ISO 27001 would be advantageous.
