Information Security GRC Analyst
Listed on 2026-09-26
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Information Security GRC Analyst (UK-based)
The GRC Analyst strengthens PCI Pal's central Information Security function by providing structured governance, risk and compliance analysis across audit, assurance, control management and strategic change. The role turns requirements, evidence, risks and delivery updates into accurate, traceable information that supports timely decisions by the GRC Lead and CISO.
The role works in close partnership with the Information Security Project Manager to track ongoing and strategic initiatives, maintain clear ownership and delivery visibility, and provide concise, evidence-based updates. It remains a GRC role: the Analyst provides assurance, analysis and tracking, while the Project Manager retains responsibility for project governance, planning and delivery coordination.
Job requirements- Relevant experience in GRC, information security compliance, risk management, internal audit or assurance.
- Working knowledge of at least one major framework, such as PCI DSS, ISO/IEC 27001, SOC 2 or NIST CSF, with the ability to apply requirements in practice.
- Experience reviewing policies, audit reports, control narratives and evidence, and translating findings into clear actions.
- Strong organization and tracking skills, including the ability to maintain plans, actions, risks, dependencies and status reporting across multiple concurrent initiatives.
- Strong written and verbal communication skills, with the ability to produce concise, accurate updates for operational and senior stakeholders.
- A collaborative working style and the confidence to challenge incomplete evidence, unclear ownership or unsupported status updates.
- Experience operating within a PCI DSS Level 1 service provider, regulated technology or cloud services environment.
- Familiarity with ISO/IEC 42001, ISO 9001, HIPAA/HITECH, Cyber Essentials or related assurance frameworks.
- Experience using GRC, audit, project tracking or evidence automation platforms, such as Drata, Jira, Service Now GRC, Archer or One Trust.
- Experience supporting programme governance, PMO reporting or strategic transformation initiatives in partnership with a Project Manager.
- Experience reviewing AI-generated content, data annotation, quality assurance or AI governance workflows.
- Relevant qualification or certification in information security, risk, audit, compliance or project delivery.
- Support the CISO, GRC Lead and wider Information Security team with risk, compliance and control analysis.
- Maintain governance artefacts including policies, standards, control mappings, risk registers, Statements of Applicability and supporting records.
- Review security policies, procedures, control narratives and evidence for accuracy, completeness, consistency and alignment with applicable frameworks.
- Identify control gaps, emerging risks and compliance issues, and provide practical recommendations with clear owners and target dates.
- Monitor relevant regulatory and industry developments, assess potential business impact and support the controlled update of affected requirements and documentation.
- Support internal and external audits, certification activity and customer assurance reviews, including evidence coordination, quality review and follow-up.
- Conduct control assessments, testing and evidence reviews, with clear findings and conclusions reported to the GRC Lead.
- Maintain audit plans, evidence requests, findings and remediation actions so that progress and closure are fully traceable.
- Challenge incomplete or unsupported evidence and work with control owners to resolve quality, scope and timing issues.
- Produce clear assurance reporting for the GRC Lead, CISO and relevant governance forums.
- Work in close partnership with the Information Security Project Manager to track ongoing, planned and strategic departmental initiatives against agreed milestones, dependencies, risks, actions and outcomes.
- Maintain accurate initiative trackers, action logs and reporting inputs, ensuring updates are supported by evidence and reflect the position agreed with accountable owners.
- Obtain and consolidate progress updates from Information Security and cross-functional stakeholders, highlighting overdue actions, delivery risks, control impacts and decisions required.
- Maintain clear linkage between identified risks, control deficiencies, audit findings, remediation work and closure evidence.
- Coordinate with Information Security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).