IT Security Governance, Risk & Controls Analyst
We are seeking an IT Security Governance, Risk & Controls Analyst to support the development, operation and continuous improvement of information security governance and risk management processes. In this role, you will help ensure that technology environments, business processes and third-party services are aligned with internal policies, regulatory expectations and recognised security frameworks. You will work closely with technology, risk, compliance, audit and business stakeholders to identify security risks, assess control effectiveness and support practical remediation plans.
Key responsibilities will include maintaining security policies, standards, procedures and control frameworks; coordinating periodic risk and control assessments; documenting risks, findings, action plans and exceptions; and monitoring progress through to resolution. You will support internal and external audits, provide evidence and responses, and help prepare management reporting on control performance, risk exposure and compliance activities. The role will also involve reviewing security requirements for projects, suppliers and technology changes, contributing to third-party risk assessments, and helping deliver awareness and governance initiatives. You may assist with control testing across areas such as access management, vulnerability management, incident response, data protection, business continuity and change management.
The successful candidate will have experience in information security governance, technology risk, IT controls, audit or compliance, with a sound understanding of frameworks such as ISO 27001, NIST, COBIT or CIS Controls. Relevant professional qualifications or certifications are desirable, as is experience working with GRC platforms, audit tools and reporting technologies. You will be analytical, organised and confident interpreting technical information, identifying gaps and communicating clearly with both technical and non-technical audiences. Strong stakeholder management, attention to detail and the ability to manage multiple priorities are essential. This is an opportunity to contribute to a mature and evolving security function while helping strengthen resilience, accountability and risk-aware decision-making across the organisation.
IT Security Governance, Risk & Controls Analyst
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- Security Engineer
- Security Analyst
- Security Architect
- Security Consultant
- IT Security Manager
- SOC Analyst
- Identity Access Management IAM
- Cyber Security Consultant
- Cloud Security
- Application Security
- Incident Response
- Penetration Tester
LATEST JOBS
- Offensive Security Researcher
- Cybersecurity Incident Respons...
- Data Protection Specialist (06...
- Offensive Security Engineer
- Cyber Controls Specialist
- Senior SOC Analyst
- Senior Security Software Devel...
- Solution Architect - Security
- Data Privacy & Protection Anal...
- SAP Security Architect and Tea...
- Cloud Security Specialist
- Security Consultant (Supply Ch...