×
Register Here to Apply for Jobs or Post Jobs. X

GRC Analyst

Job in Cheltenham, Gloucestershire, GL50, England, UK
Listing for: IMT Resourcing Solutions
Full Time position
Listed on 2026-08-28
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity, IT Consultant
Salary/Wage Range or Industry Benchmark: 42000 - 58000 GBP Yearly GBP 42000.00 58000.00 YEAR
Job Description & How to Apply Below

We’re looking for an experienced GRC Analyst to support an established organisation with its information security governance, risk and compliance activity.

This is a hands-on role suited to someone with strong knowledge of security frameworks including ISO 27001 and NIST, who can work with technical and business teams to assess risk, maintain controls and support ongoing compliance.

Microsoft security experience would be particularly useful, especially across the wider Microsoft 365 and Azure security ecosystem.

The Role

You’ll work closely with security, technology and wider business stakeholders, with responsibilities including:

  • Supporting the organisation’s ISO 27001 ISMS, including maintaining policies, controls and supporting evidence
  • Working with security frameworks including ISO 27001, NIST CSF and CIS Controls
  • Conducting and maintaining information security risk assessments
  • Managing security risks, controls, actions and remediation plans
  • Supporting internal and external security audits and assessments
  • Reviewing existing security controls and identifying areas for improvement
  • Maintaining security policies, standards, procedures and governance documentation
  • Supporting third-party and supplier security assessments
  • Tracking compliance against relevant security frameworks and organisational requirements
  • Working with technical teams to ensure security controls are implemented effectively
  • Producing security reporting, metrics and governance information for stakeholders
What We’re Looking For You’ll ideally have:
  • Strong commercial experience within GRC, Information Security or Cyber Security
  • Good working knowledge of ISO 27001
  • Experience working with NIST, ideally NIST CSF
  • Practical experience of security risk management and control assessments
  • Experience supporting security audits and compliance activity
  • Strong understanding of security policies, governance and assurance
  • Experience working with technical and non-technical stakeholders
  • The ability to take ownership of GRC activity rather than purely providing administrative support

Experience with Microsoft security tooling would be highly desirable, particularly:

  • Microsoft Purview
  • Microsoft Sentinel
  • Microsoft 365 and Azure security/compliance controls

Relevant certifications such as ISO 27001 Lead Implementer/Auditor, CISM, CRISC, CISSP or equivalent would be beneficial but aren't essential.

  • Contract:

    Initial 6 months
  • Extension:
    Strong possibility of extension
#J-18808-Ljbffr
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary