×
Register Here to Apply for Jobs or Post Jobs. X

GRC Lead

Job in Inverness, Highland, IV2, Scotland, UK
Listing for: Capgemini
Full Time position
Listed on 2026-08-23
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 45000 - 65000 GBP Yearly GBP 45000.00 65000.00 YEAR
Job Description & How to Apply Below

About the job you're considering

The Governance, Risk, Compliance (GRC) and Vulnerability Assessment Analyst supports the account's cyber security governance, risk management, compliance, assurance, and vulnerability management activities within a complex and highly regulated environment.
This role contributes to ensuring that security controls, processes, and governance frameworks are effective, auditable, and aligned to industry standards including ISO 27001, Cyber Essentials Plus, GDPR, NIST, and contractual security obligations.

The Analyst provides security oversight, assurance, and risk-based guidance across projects, operational services, and technology changes while supporting secure-by-design principles through governance and design review activities.
Working closely with technical and business stakeholders, the successful candidate will help identify, assess, manage, and report security risks appropriately, while supporting continual improvement initiatives that enhance the overall security posture of the account.

If you are successfully offered this position, you will go through a series of pre-employment checks, including identity, nationality (single or dual) or immigration status, employment history going back 3 continuous years, and unspent criminal record check (known as Disclosure and Barring Service)

Your role
  • Support the maintenance and continuous improvement of the Cyber Security Governance Framework, ensuring alignment with organisational, client, and regulatory requirements.
  • Assist with security risk management activities, including risk identification, assessment, treatment, acceptance tracking, and ongoing monitoring.
  • Maintain the Security Risk Register, ensuring risks, actions, owners, and mitigations are accurately recorded, tracked, and reported.
  • Support the development, review, and maintenance of security policies, standards, and procedures aligned to ISO 27001, Cyber Essentials Plus, GDPR, and contractual obligations.
  • Assist with internal and external audit activities, including evidence collection, tracking remediation actions, and supporting responses to audit findings.
  • Conduct security assurance reviews and control assessments to identify compliance gaps, risks, and opportunities for improvement.
  • Support vulnerability management governance activities by monitoring vulnerability remediation progress, tracking risk treatment plans, and producing reports.
  • Produce security reporting and metrics covering risk, compliance, audit, incident, and vulnerability management activities for internal and client stakeholders.
  • Review security designs and technology changes against security policies, standards, and secure-by-design principles, escalating concerns where appropriate.
  • Support security awareness, training, and continual improvement initiatives that help strengthen security maturity and compliance across the account.
Your skills and experience
  • Experience working within a Cyber Security Governance, Risk & Compliance (GRC) environment.
  • Good understanding of security risk management frameworks and methodologies.
  • Experience supporting security governance, compliance, assurance, audit, or risk management activities.
  • Familiarity with security standards, certifications, and compliance frameworks, including:
    • ISO 27001
    • Cyber Essentials Plus
    • GDPR
    • NIST Cyber Security Framework
    • ITIL
  • Experience maintaining security risk registers, control frameworks, policies, standards, and compliance documentation.
  • Understanding of vulnerability management processes, remediation tracking, and security assurance activities.
  • Ability to analyse technical findings and communicate associated business risks.
  • Experience working with internal stakeholders, auditors, clients, and technical teams.
  • Strong analytical, reporting, documentation, and organisational skills.
  • Good communication and stakeholder management skills with the ability to work collaboratively across teams.
  • Ability to prioritise workload, manage multiple tasks, and work effectively within a regulated environment.
  • Relevant cyber security qualifications or willingness to work towards industry-recognised certifications (e.g. ISO 27001, Security+, ISC2 CC).

You can bring…

Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary