Job description
Cybersecurity GRC Analyst – Operational Handover Programme Location: Redhill, Surrey Working Pattern: Full-time Role Overview We are seeking an experienced Cybersecurity Governance, Risk and Compliance Analyst to support cybersecurity assurance, audit and risk-management activities across a major operational handover programme.
The role will provide oversight of the security implications associated with the transfer of services and systems, with particular focus on identifying and managing risks created during the transition process. You will also support knowledge transfer and provide training to the incoming organisation’s security, risk-management and audit teams.
This is a key role within the programme, ensuring that appropriate cybersecurity controls, certifications and governance processes remain effective throughout the transition.
Key Responsibilities
Conduct cybersecurity risk assessments and security-control reviews across business applications, infrastructure and computer installations being transferred as part of the handover programme. Identify security risks and recommend appropriate remediation or risk-treatment actions to programme management. Maintain ISO 27001 and PCI-DSS certification and recertification activities throughout the programme.
Maintain programme and handover cybersecurity risk registers and associated treatment plans. Ensure agreed security-support processes are followed throughout the handover programme. Conduct ad-hoc internal security audits across relevant security-control areas, working closely with quality assurance, technology and service teams.
Document security non-compliances, agree remediation actions with the programme leadership team and monitor progress through to completion. Design and, where required, implement security policies, standards, guidelines, processes and procedures. Ensure continued compliance with the organisation’s Information Security Management System, ISO 27001, PCI-DSS, contractual obligations and relevant legislation.
Review handover-related change requests and assess their potential impact on existing security controls and mechanisms. Ensure planned technical changes do not unnecessarily compromise or weaken existing cybersecurity controls. Produce clear security, risk, compliance and audit reporting for the programme leadership team.
Provide input into wider cybersecurity, business-continuity and contingency-planning activities. Support knowledge transfer and training for the incoming organisation’s security risk-management and audit personnel. Work collaboratively with internal teams, customers, suppliers, security vendors and programme partners.
Travel to other operational sites and data centres where required. Comply with all relevant company policies, including the code of conduct, quality, security, health and safety, and environmental procedures. Essential Qualifications A recognised information-security certification, such as: CISA, CISM or CRISC CISSP BCS CISMP IISP certification or equivalent Desirable Qualifications Degree in information security, computer science, engineering, mathematics, encryption or another relevant discipline, or equivalent professional experience.
Information privacy or data-protection qualifications, such as CIPP/E or CIPM. Payment Card Industry Security Standards Council certification, such as ISA or QSA. ITIL, PRINCE2 Foundation or TOGAF certification. Relevant infrastructure or networking vendor certifications. Essential Experience and Knowledge Strong experience within cybersecurity governance, risk, audit and compliance management.
Experience working within a complex IT, technology or operational environment. Thorough understanding of information-security audit methodologies and control-assessment techniques. Experience operating and auditing an ISO 27001-compliant Information Security Management System. Experience managing PCI-DSS certification, recertification and audit activities.
Experience implementing or operating within a PCI-DSS-compliant security environment. Strong knowledge of cybersecurity technologies, controls, frameworks and risk-management methodologies. Experience assessing cybersecurity implications within formal change-management processes. Demonstrable stakeholder-management experience, including leading consultations, workshops and presentations.
Experience creating and maintaining security policies, standards, procedures, guidance, processes and awareness materials. Experience managing security risks, remediation plans, audit findings and compliance actions through to completion. Desirable Experience Experience working with additional security, risk and compliance frameworks, including: PCI P2PE PCI POI PTS ISO 22301 ISO 27005 ISO 31000 NIST security and risk frameworks GDPR and wider data-protection legislation Experience within transactional revenue, embedded systems, smartcards, mobile payments, open-payment systems or EMVCo environments.
Experience using cybersecurity governance, risk and compliance platforms. Experience using IT service-management tools. Familiarity with vulnerability-management and security-operations tooling. Experience working with quality-management systems and external audit standards such as ISO 9001. Previous experience supporting a complex operational handover, transition or service-transfer programme.