Our Client
The role
The Senior IT Cyber Governance, Risk & Compliance Analyst will support the development, implementation and oversight of the organisation’s IT governance, cyber risk and compliance activities. This role involves supporting IT and cyber risk assessments, compliance with relevant regulatory and control frameworks,
audit activity, and the identification and tracking of vulnerabilities, control gaps and remediation actions across IT systems and processes. The Senior IT Cyber Governance, Risk & Compliance Analyst will work closely with internal stakeholders to help ensure that IT and cyber activities are aligned with regulatory expectations, internal policies and good practice.
Key accountabilities
Compliance, Risk & Governance
- Support compliance with regulatory, IT, cyber security and control frameworks, including DORA, ISO 27001, NIST CSF, SOX and Cyber Essentials.
- Assist with identifying, assessing and managing IT, cyber and operational risks across systems, processes and third-party suppliers.
- Monitor emerging cyber, technology and resilience risks, supporting proactive risk management and escalation activities.
- Support regulatory inspections, internal and external audits, and third-party assurance reviews.
- Maintain and update the cyber risk register, tracking risks, issues, remediation actions and governance reporting.
- Coordinate cyber risk remediation activities arising from assessments, audits, incidents and control reviews.
- Support third-party security assurance, due diligence reviews and supplier remediation tracking.
- Coordinate user and privileged access reviews, working with system owners to strengthen access certification processes.
- Perform compliance monitoring and control testing against information security policies, standards and controls.
Policy, Training & Regulatory Compliance
- Support the development and maintenance of IT risk, cyber security and compliance policies, standards and procedures.
- Keep abreast of regulatory developments and assist in implementing required changes.
- Contribute to the delivery of governance, risk and compliance training and awareness programmes.
Reporting & Stakeholder Management
- Produce cyber risk, control effectiveness and remediation reporting for management and governance forums.
- Support the development and monitoring of key risk and performance indicators (KRIs/KPIs).
- Assist with breach notification, incident escalation and regulatory reporting activities, working closely with Legal, Data Protection and key stakeholders.
Skills & experience
- Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related field, or equivalent industry experience.
- Relevant certifications such as CRISC, CISA, CISM, ISO 27001 or CISSP are desirable, or a willingness to work towards similar qualifications.
- Minimum 5 years’ experience in IT Governance, Risk Management, Cyber Security, Information Security or a related discipline, with strong knowledge of control frameworks and compliance requirements.
- Good understanding of key technology domains, including infrastructure, applications, networking, cloud services, vulnerability management, incident management and access controls.
- Experience supporting audit, regulatory and compliance activities, including evidence gathering, issue tracking and remediation management. Exposure to SOX compliance and IT General Controls (ITGCs) is desirable.
- Previous experience within insurance, financial services or another regulated industry is advantageous.
- Strong communication and stakeholder management skills, with the ability to translate technical concepts into clear, business-friendly language for non-technical audiences.
- Excellent organisational skills, attention to detail and the ability to manage multiple priorities in a fast-paced environment
