Live opening · Posted 10 hours ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
GRC Security Analyst
Governance, Risk & Compliance | Group Security Team
Purpose of the Job
As a GRC Security Analyst within the Group Security team, you will support the organisation's information
security governance, risk, and compliance functions. The role bridges security policy, application access
governance, vulnerability reporting, and executive-level security reporting, ensuring that security controls
are well documented, consistently applied, and clearly communicated across the business.
You will work closely with the Security Team, Cybersecurity Engineering, Infrastructure, and other IT
groups to maintain policy alignment with recognised security frameworks, support external audit activity,
track vulnerability remediation, and produce reporting that gives leadership clear visibility into the
organisation's security and risk posture.
Key Responsibilities
Information Security Governance and Compliance
● Maintain and update security policies in line with recognised security frameworks.
● Work with the organisation's sponsored external auditors to support audit activities and evidence
requests.
● Support data protection and privacy practices across the organisation.
Application Security Governance
● Audit application account access on a regular basis to ensure appropriate access levels.
● Maintain application access documentation, ensuring records remain accurate and current.
● Support onboarding documentation and provisioning processes for new applications and users.
Vulnerability Reporting and Management
● Maintain systems reporting and tracking of IT security compliance.
● Filter vulnerability scan reports to identify findings by risk level and device.
● Create vulnerability reports segmented by application.
● Meet with system and application owner groups to guide and track remediation progress.
Security Reporting
● Gather security reports from multiple sources and extract critical statistics.
● Combine key statistics across reports into executive summary reporting.
● Identify security and risk trends from reporting data and escalate as appropriate.
Security Awareness
● Support security awareness training initiatives and related reporting.
Schedule & Meetings
● Schedule: Monday to Friday, hours to be determined (TBD).
● Weekly meetings with the Security Team and management to provide status updates.
● Frequent meetings with the Cybersecurity Engineer and Infrastructure team.
● Ad hoc meetings with other IT groups as needed.
Required Experience & Skills
● Excellent communication skills, able to engage effectively with managers and peers.
● Strong background in policy development and documentation.
● Demonstrated process improvement skills.
● Strong problem-solving ability.
Preferred Experience & Skills
● Experience developing policy documentation aligned to security frameworks such as NIST, ISO
27001, and Cyber Essentials.
● Experience with vulnerability tracking using Qualys.
Organisation-Specific Training
● Clarity Security
● Qualys
● KnowBe4
● CrowdStrike
● BitDefender
● Intune
● JAMF
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.