×
Register Here to Apply for Jobs or Post Jobs. X

Cyber s Plus & GRC Analyst – Hybrid

Job in Liverpool, Merseyside, L1, England, UK
Listing for: Venturi
Full Time, Contract position
Listed on 2026-07-20
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security
Job Description & How to Apply Below
Position: Cyber Essentials Plus & GRC Analyst – Hybrid

Cyber Security Analysts – Cyber Essentials Plus & GRC

6-month contracts | Outside IR35 | Liverpool hybrid

We’re partnering with a major UK transportation and infrastructure organisation that is strengthening its cyber security capability as it expands into new regulated and defence-related sectors.

They are looking to hire multiple Cyber Security Analysts across two immediate work streams:

  • Cyber Essentials Plus and technical remediation
  • Cyber risk management and GRC

Both roles offer the opportunity to take genuine ownership of a defined security programme, working closely with technical teams and senior stakeholders to build and improve capability rather than simply maintain an existing service.

  • Initial six-month contract
  • Liverpool-based
  • Onsite every Monday and Tuesday
  • Immediate start preferred
  • One-stage interview process
  • Quick decisions for suitable candidates
Role 1:
Cyber Security Analyst

The organisation has completed an initial Cyber Essentials Plus gap assessment and now requires an experienced contractor to take ownership of the remediation and certification programme.

You will coordinate technical improvements, manage evidence and submissions, support the external assessment process and drive any findings through to closure.

This is not a SOC monitoring or Penetration Tester role. It requires someone who understands Cyber Essentials Plus and can lead the delivery activity surrounding it.

Responsibilities
  • Lead the Cyber Essentials Plus remediation programme
  • Review and progress an existing security gap analysis
  • Coordinate remediation across infrastructure, network and endpoint teams
  • Manage issues relating to patching, unsupported systems and secure configuration
  • Coordinate firewalling and network segmentation improvements
  • Gather and validate technical evidence
  • Manage statements and attestations within the submission
  • Liaise with assessors and respond to assessment queries
  • Support the scoping and coordination of penetration testing
  • Manage post-test findings, remediation and retesting
  • Maintain clear actions, ownership and delivery deadlines
  • Previous delivery of Cyber Essentials or Cyber Essentials Plus
  • Experience supporting a submission through to certification
  • Technical security remediation experience
  • Vulnerability and patch-management knowledge
  • Experience working with infrastructure, network and endpoint teams
  • Experience coordinating security testing and remediation
  • Ability to challenge stakeholders and drive actions through to completion

The second contractor will help establish a formal cyber risk management capability.

The organisation currently needs to create its cyber risk framework, risk assessment methodology, risk register, supporting policy and governance structure.

Although titled as an Analyst position, this role requires someone capable of working independently, drafting the approach and taking ownership of implementation.

Responsibilities
  • Design and implement a cyber risk management framework
  • Develop a consistent risk assessment methodology
  • Create and maintain a cyber risk register
  • Define risk scoring, ownership, treatment and escalation processes
  • Draft cyber risk policies, standards and supporting procedures
  • Conduct cyber and information security risk assessments
  • Establish governance forums and terms of reference
  • Prepare and facilitate cyber risk governance meetings
  • Work with technical and business stakeholders to assign and manage risks
  • Support risk assessments across IT and operational environments
  • Help embed a repeatable and sustainable risk-management process
  • Cyber or information security risk management
  • Strong knowledge of ISO 27001 and ISO 27005
  • Experience building or materially improving a cyber risk framework
  • Experience creating risk assessment methodologies
  • Policy and framework drafting experience
  • Experience establishing and running governance forums
  • Strong stakeholder-management and facilitation skills
  • Ability to translate technical findings into meaningful business risks
Desirable experience across either role Experience in any of the following would be beneficial:
  • Operational Technology
  • Critical National Infrastructure
  • NIS-regulated environments
  • Cyber Assessment Framework
  • Defence or government programmes
  • Transport, logistics, utilities, engineering or manufacturing
  • Complex, multi-site organisations

Sector experience is not essential where candidates can demonstrate strong, transferable delivery experience.

Applicants must be able to attend the Liverpool site 2 times per week.

Please apply with an up-to-date CV or contact me directly to discuss which workstream best matches your experience.

#J-18808-Ljbffr
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary