Senior Governance Risk and Compliance Analyst
3 days ago
Job Description:
We are seeking a highly skilled and experienced Senior Governance Risk and Compliance (GRC) Analyst to assist customers in meeting their cybersecurity regulatory and legal requirements.This role will focus on Policy Development, Risk Assessment and Risk Management, Gap Analysis and Due Diligence.
Analysts will work with customers to develop formalized information security policies, analyze the efficacy of current policies and procedures, and evaluate the risks posed by third-party providers.
The ideal candidate will have a solid understanding of information security strategies suitable for small and mid-size businesses within the financial services sector coupled with a solid grasp.
Responsibilities (including but not limited to):
- Coordinating and working with clients to develop formalized Written Information Security Programs (WISPs)
- Performing cybersecurity due diligence assessments on client vendors
- Engaging with the cybersecurity engineering team to assist with client risk management and technical gaps with regulatory requirements.
- Assist with providing strategic guidance and oversight on regulatory and risk management procedures for multiple clients’ cybersecurity programs.
- Assisting clients in meeting regulatory requirements via policy review and testing (e.g., Incident Response tabletop exercises)
- Assisting clients with their own due diligence questionnaire and fielding cybersecurity and compliance questions
- Providing customized end-user security awareness training via presentations and simulated phishing campaigns
- Researching and keeping up to date with industry compliance regulations, most specifically within the investment and financial services space including FCA, SEC, and DORA.
- Build and maintain strong relationships with clients, understanding their unique compliance challenges and providing tailored solutions.
- Internally assess, evaluate, and make recommendations to management regarding the adequacy of the security policies and documentation.
- Serving as a lead resource for compliance-based information security gap assessments for various regulations and frameworks. (NIST CSF, CIS CSC v8, ISO27001, DORA, etc.)
Skills:
- Basic operational capabilities for the Office 365 stack (Microsoft Word, Excel, Outlook)
- Strong ability to direct self-work with excellent organizational and time management skills.
- Excellent verbal and written communication skills, especially when communicating technical concepts to non-technical audiences.
- Critical and creative thinking to strategize how to add value to customer engagements and improve processes
- Exceptional spelling and grammar skills for writing and proofreading documents.
- Ability to remain flexible as processes continuously improve.
- Proficiency in regulatory and security framework gap assessments.
- Proven expertise in the realm of identity and access management (IAM) leveraging solutions such as Privileged Identity Management (PIM) and conditional access policies.
- Experience working with cloud automation to include infrastructure as code and compliance as code.
- Experience configuring and supporting endpoint security tools (EDR, Encryption, Behavior Analysis)
- Strong attention to detail and well organized.
- Highly motivated to continuously learn, grow and innovate.
Qualifications:
Education:
- Bachelors’ Degree (Masters’ Preferred) in one of the following areas of concentration: Computer Science, Software Development, Information Technology, Cybersecurity.
Experience:
- 3+ years GRC experience including information security policy development and certification/regulatory gap analysis (such as ISO 27001, CIS CSC v8, etc.)
- Experience within the investment and financial services state preferred.
- ISACA CRISC, ISC2 CGRC, or CompTIA CySA+ preferred.
- Knowledge of Secure Software Development Life Cycle (SSDLC) practices is a plus.
- Automation and problem-solving skills a plus.
- Must be available to work 8am-5pm GMT Monday-Friday
Certifications:
- Relevant certifications such as CISM, CRISC, CGRC, CySA+, or Security+.
-
Edinburgh, United Kingdom Abacus Group Full timeJob Description:We are seeking a highly skilled and experienced Senior Governance Risk and Compliance (GRC) Analyst to assist customers in meeting their cybersecurity regulatory and legal requirements.This role will focus on Policy Development, Risk Assessment and Risk Management, Gap Analysis and Due Diligence.Analysts will work with customers to develop...
-
Edinburgh, United Kingdom Abacus Group Full timeJob Description: We are seeking a highly skilled and experienced Senior Governance Risk and Compliance (GRC) Analyst to assist customers in meeting their cybersecurity regulatory and legal requirements.This role will focus on Policy Development, Risk Assessment and Risk Management, Gap Analysis and Due Diligence. Analysts will work with customers to develop...
-
Senior Risk Analyst
1 month ago
Edinburgh, Edinburgh, United Kingdom FNZ Group Full timeRole SummaryThe Senior Analyst, Conduct & Governance Risk will play a key role in supporting the implementation and application of the Risk Management Framework responsibilities. This includes identifying efficiencies and improvements in processes related to quality and timeliness, as well as conducting root cause and thematic analysis to improve the control...
-
Senior Governance Risk And Compliance Analyst
5 hours ago
City of Edinburgh, United Kingdom Abacus Group Full timeJob Description:We are seeking a highly skilled and experienced Senior Governance Risk and Compliance (GRC) Analyst to assist customers in meeting their cybersecurity regulatory and legal requirements.This role will focus on Policy Development, Risk Assessment and Risk Management, Gap Analysis and Due Diligence.Analysts will work with customers to develop...
-
Risk and Compliance Analyst
1 week ago
Edinburgh, Edinburgh, United Kingdom Tbwa ChiatDay Inc Full timeRisk and Compliance AnalystWe are seeking a highly motivated and detail-oriented Risk and Compliance Analyst to join our team in Edinburgh, UK. As a key member of our Partnership Oversight function, you will play a crucial role in overseeing the activities of our partners, ensuring they meet regulatory requirements and delivering successful compliance...
-
Analyst - Risk and Compliance
1 week ago
Edinburgh, Edinburgh, United Kingdom Clearwater Analytics Full timeJob SummaryWe are seeking a highly motivated and experienced Technical Risk and Compliance Analyst to join our Information Security team.The successful candidate will have a strong background in risk and compliance, excellent communication skills, and the ability to work collaboratively with cross-functional teams.Key Responsibilities:Develop and implement...
-
Edinburgh, Edinburgh, United Kingdom Phoenix Group Holdings Full timeWhat We're Looking ForWe are seeking a skilled Compliance Risk Analyst to join our Asset Management Oversight team at Phoenix Group Holdings. As a key member of our Business Control and Governance unit, you will play a critical role in identifying and mitigating potential risks within our portfolio.The successful candidate will possess strong analytical...
-
Technical Risk and Compliance Analyst
4 weeks ago
Edinburgh, United Kingdom Clearwater Analytics Full timeJob Description Clearwater Analytics is looking for a hands-on Technology Risk and Compliance Analyst within our growing Information Security team. This role will help drive the compliance and assurance efforts for Clearwater and assist with responding to third party security assessments and support quarterly access review testing. Acts as first point...
-
Technical Risk and Compliance Analyst
4 weeks ago
Edinburgh, United Kingdom Clearwater Analytics Full timeJob Description Clearwater Analytics is looking for a hands-on Technology Risk and Compliance Analyst within our growing Information Security team. This role will help drive the compliance and assurance efforts for Clearwater and assist with responding to third party security assessments and support quarterly access review testing. Acts as first point...
-
Technical Risk and Compliance Analyst
3 weeks ago
Edinburgh, United Kingdom Clearwater Analytics Full timeJob Description Clearwater Analytics is looking for a hands-on Technology Risk and Compliance Analyst within our growing Information Security team. This role will help drive the compliance and assurance efforts for Clearwater and assist with responding to third party security assessments and support quarterly access review testing. Acts as first point of...
-
Senior Tax Analyst
1 month ago
Edinburgh, Edinburgh, United Kingdom Trainline plc Full timeJob Title: Senior Tax AnalystWe are seeking a highly skilled Senior Tax Analyst to join our team at Trainline plc. As a Senior Tax Analyst, you will play a key role in providing tax advisory services to the business, ensuring compliance with tax laws and regulations, and driving process improvements.Key Responsibilities:Provide tax advisory services to the...
-
Risk Management Analyst
1 month ago
Edinburgh, Edinburgh, United Kingdom FNZ Group Full timeRole OverviewThe Second Line Risk team at FNZ Group is responsible for delivering, coordinating, and continuously developing an effective Risk Management Framework. This framework enables the company to identify, assess, control, and monitor risk, and manage it within the appetite of the business, clients, and regulators.The role of the Risk Management...
-
Information Security Analyst
2 weeks ago
Edinburgh, Scotland, United Kingdom Trustpilot Full timeOur vision is to be the universal symbol of trust, bringing consumers and businesses together through reviews. We are well on our way — but there’s still an exciting journey ahead. Join us at the heart of trust. We are seeking a mid-level Governance, Risk and Compliance analyst, working in our Information Security Team, to enable us to continue to...
-
Cyber Risk
6 months ago
Edinburgh, United Kingdom Scottish Further and Higher Education Funding Council Full time**Details**: **Reference number**: - 358563**Salary**: - £61,626 - £72,684- A Civil Service Pension with an average employer contribution of 27%**Job grade**: - Other- SFC Grade M1**Contract type**: - Fixed term**Length of employment**: - 12 Months**Type of role**: - Information Technology**Working pattern**: - Flexible working, Full-time,...
-
Head of Technology, Risk Management and Governance
6 months ago
Edinburgh, United Kingdom SSE Full timeSSE has big ambitions to be a leading energy company in a low carbon world. Following our commitment to invest £18 billion in low carbon projects to 2027, we have significant growth plans and are well on our way to achieving our ambition to build a world that's more sustainable and inclusive for you, your family, the community you live in and for...
-
Risk Modelling Analyst
1 week ago
Edinburgh, Edinburgh, United Kingdom Lloyds Bank plc Full timeAbout the RoleWe are seeking an experienced Risk Modelling Analyst to join our team at Lloyds Bank plc. As a key member of our audit function, you will play a critical role in delivering high-quality risk and control assurance activities.Key Responsibilities:Support the delivery of audits and lead evaluations of controls, applying proficient knowledge of...
-
Compliance & Governance Coordinator - Uk
6 months ago
Edinburgh, United Kingdom Mercy Corps Full time**Location**: Edinburgh, UK** **Position Status**: Full-time, Regular** **Salary**:starting circa 27,280 GBP - range flexible based on professional experience** **About Mercy Corps** Mercy Corps is powered by the belief that a better world is possible. To do this, we know our teams do their best work when they are diverse and every team member feels that...
-
Lead Risk Analyst
3 weeks ago
Edinburgh, Edinburgh, United Kingdom NatWest Group Full timeJoin us at NatWest Group as a Risk Modelling Lead AnalystYou will develop and maintain compliant and fit-for-purpose models used in the bank's risk framework, ensuring alignment with regulatory requirements.With your analytical expertise, you will provide clear and well-presented analysis, supporting informed business decisions.You will work collaboratively...
-
Technical Risk and Compliance Analyst
3 weeks ago
Edinburgh, United Kingdom Clearwater Analytics Full timeJob Description Clearwater Analytics is looking for a hands-on Technology Risk and Compliance Analyst within our growing Information Security team. This role will help drive the compliance and assurance efforts for Clearwater and assist with responding to third party security assessments and support quarterly access review testing. Responsibilities: Drive...
-
Technical Risk and Compliance Analyst
4 weeks ago
Edinburgh, United Kingdom Clearwater Analytics Full timeJob Description Clearwater Analytics is looking for a hands-on Technology Risk and Compliance Analyst within our growing Information Security team. This role will help drive the compliance and assurance efforts for Clearwater and assist with responding to third party security assessments and support quarterly access review testing. Responsibilities: ...