×
Register Here to Apply for Jobs or Post Jobs. X

Governance Risk and Compliance Analyst

Job in Glasgow, Glasgow City Area, G1, Scotland, UK
Listing for: University of Glasgow
Full Time position
Listed on 2026-08-23
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity
Salary/Wage Range or Industry Benchmark: 41000 - 46000 GBP Yearly GBP 41000.00 46000.00 YEAR
Job Description & How to Apply Below

Please note this vacancy is only open to current University of Glasgow employees only.

Job Purpose

The Governance Risk and Compliance Analyst will provide analytical expertise to inform the Cyber Risk and Assurance Manager and the wider Information Security Team.

The post holder will support the deployment and maturity of the Information Security Control Framework and provide analytical reporting to inform policy, governance, strategy and risk awareness.

The role will be responsible for developing and maintaining a catalogue of risks and controls processes and procedures across Information Services and will support the response to audit and University funding requests from an information security perspective. They will also support new and existing Information Security Resilience processes to ensure compliance is met internally.

If you are passionate about information security and have the expertise to drive our governance, risk, and compliance initiatives, we would love to hear from you!

We are holding an informal webinar on the 25th of August  to give interested candidates an opportunity to learn about Information Security at the University of Glasgow, as well as finding out about our current opportunity within the team. Whether you're an established tech professional or considering a pivot into cyber, this webinar will offer the opportunity to understand the role beyond the job advert.

You'll have the chance to meet the team (both career pivots ourselves!); understand the responsibilities and opportunities for growth in the role; and ask us about the role and application process.

Please register for this event Governance Risk and Compliance Analyst webinar – the latest date for registration is 12.15pm on the 25th August. If you are unable to attend the webinar, please note that a recording will be available following the webinar and will be sent to anyone who has registered.

If you would like to arrange an informal discussion about the role, please feel free to contact Caitlin Divers a

Main Duties and Responsibilities
  • Innovate and Support the development of University Information Security Risk, Policies and Frameworks.
  • Innovate to develop risk governance frameworks and influence key stakeholders to adopt them.
  • Manage a catalogue of information security controls, Risk registers, audit and action trackers and work in partnership with accountable stakeholders to ensure actions are followed through.
  • Provide regular reporting updates suitable for senior stakeholders (extensive use of PowerPoint required).
  • Analyse data to determine risk status and provide summaries to inform the wider team and a variety of stakeholders (includes extensive use of excel)
  • Conduct regular data analysis of our security monitoring systems, report on relationships between our security controls, operational incidents and vulnerabilities to provide transparency and inform decision-making.
  • Analyse legal documentation (such as university contracts), identify risk state and report findings to immediate team and relevant stakeholders.
  • Coordinating Risk Management forums including setting up and managing meeting cadences (extensive use of O365).
  • Partnership working with the Information Security teams to provide holistic and accurate reporting on our risk status.
  • Partnership working with the Information Services teams and broader University departments to make improvements to our Information Security Risks.
  • Support the Risk and Assurance Manager on all internal and external communications.
  • Liaise with internal/external partners to ensure our requirements are fully understood and tested.
  • Support the growth and maturity of the Information Security team through procurement processes.
  • Support the growth and maturity of all activities pertaining to Information Security Risk Governance & Compliance.
  • Knowledge, Qualifications, Skills and Experience Knowledge/Qualifications Essential:

    A1 Scottish Credit and Qualification Framework level 9, 10, 11 (Degree, Post Graduate Qualification) or equivalent, including being professionally qualified in relevant discipline, with a broad range of professional experience in a management role(s) OR Ability to…

    Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
    To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
     
     
     
    Search for further Jobs Here:
    (Try combinations for better Results! Or enter less keywords for broader Results)
    Location
    Increase/decrease your Search Radius (miles)
    0
    200
    Filters
    Education Level
    Experience Level (years)
    Posted in last:
    Salary