Overview
We are seeking a mid-level Cyber Security GRC Analyst for a 6-month contract to augment our client's information security and compliance programme. In this role, you will work remotely and collaborate with internal stakeholders and IT suppliers to support Cyber Essentials Plus readiness, develop an ISO 27001-aligned information security framework, and contribute to SOC 2 preparation.
Responsibilities
- Develop and maintain security policies, controls, risk registers, and supporting documentation.
- Conduct gap assessments and track remediation actions.
- Gather and organise evidence for audits and external assessments.
- Collaborate with internal stakeholders and IT suppliers to enhance security controls.
- Facilitate knowledge transfer to junior team members to ensure internal process sustainability.
Requirements
- Practical experience in supporting ISO 27001 implementation or audit programmes.
- Familiarity with Cyber Essentials Plus and SOC 2 requirements.
- Hands-on experience with security documentation, risk assessments, and audit evidence.
- Strong communication skills and the ability to work independently.
- Experience in a GRC-focused delivery role is preferred.