
Security GRC Analyst
- Bristol Area
- Permanent
- Full-time
- Assisting in meeting compliance requirements within HL, such as PCI-DSS and in line with frameworks such as SWIFT CSCF, CSA CCM and NIST CSF.
- Assist with the technical security aspects of third-party security risk by conducting security due diligence and risk assessments for vendors, suppliers, partners, and contractors.
- Develop and mature processes and procedures for third party security risk management, including due diligence and third-party incident management.
- Work closely with stakeholders to provide advice in relation to third party information security risks, recommending risk mitigation strategies and/or advising on risk exceptions based on the business' risk appetite.
- Driving policy & standard governance processes including creating new policies and standards where required.
- Managing framework alignments, identifying gaps and engaging stakeholders to remediate.
- Managing Security process documentation including review scheduling.
- Maintaining the program of remediation for audit and assessment findings, including updating of task status, reporting of progress and escalation of issues and identifying opportunities for improvement.
- Proven experience in an Information Security role with a strong background in risk and compliance.
- Ideally experience must have been gained within a regulated industry with experience of securing cloud environments such as AWS & Azure.
- Must be experienced in liaising with stakeholders at all levels and be confident in influencing business areas to meet compliance requirements.
- Demonstrable experience of working with compliance and risk management in a NIST CSF (Preferable) or ISO27001 aligned environment, along with an understanding of PCI-DSS.
- Experience in managing supply chain risk, including due diligence, risk escalation and treatment.
- Good writing capabilities, analytical skills, including demonstrated experience identifying and communicating opportunities for improvement.
- Experience of identifying, articulating, managing and reporting Information Security risks and an understanding of risk management practices, aligned with industry best practice.
- Experience of creating, reviewing and updating Information Security related policies, procedures and standards.
- Discretionary annual bonus* and annual pay review
- 25 days* holiday plus bank holidays and 1-day additional Christmas closure
- Option to purchase an additional 5 days holiday**
- Flexible working options available, including hybrid working
- Enhanced parental leave
- Pension scheme up to 11% employer contribution
- Income Protection and Life insurance (4 x salary core level of cover)
- Private medical insurance*
- Health care cash plans - including optical, dental, and outpatient care
- Health screening programme
- Help@hand - confidential support including mental health counselling and remote GP
- Wellhub - unlimited access to fitness providers and wellness coach sessions
- Variety of travel to work schemes with bike storage and shower facilities
- Inhouse barista and deli serving subsidised coffee and sandwiches
- Two paid volunteering days per year
- dependant on role level