Senior IT Cyber GR&C Analyst
Our client is a leading global specialty (re)insurance business, recognised for its innovative approach to underwriting and strong reputation across international markets. With operations spanning multiple locations, the business focuses on delivering bespoke insurance and reinsurance solutions across a diverse portfolio of specialty risks. Combining underwriting expertise, entrepreneurial thinking, and a collaborative culture, they continue to drive growth while investing in technology, talent, and operational excellence
PURPOSE OF THIS ROLE
The Senior IT Cyber Governance, Risk & Compliance Analyst will support the development, implementation and oversight of the organisation's IT governance, cyber risk and compliance activities. This role involves supporting IT and cyber risk assessments, compliance with relevant regulatory and control frameworks, audit activity, and the identification and tracking of vulnerabilities, control gaps and remediation actions across IT systems and processes. The Senior IT Cyber Governance, Risk & Compliance Analyst will work closely with internal stakeholders to help ensure that IT and cyber activities are aligned with regulatory expectations, internal policies and good practice.
KEY RESPONSIBILITIES
Compliance and Risk Management:
· Support compliance with applicable regulatory, IT, cyber and control frameworks, which may include DORA, ISO 27001, NIST CSF, SOX and Cyber Essentials.
· Support the evaluation and management of IT, cyber, compliance and security risks across systems, processes and operations.
· Monitor emerging technology, cyber and operational resilience risks to support proactive risk management and timely escalation.
· Assist in preparing for and supporting regulatory inspections and internal, external and third-party audits.
· Support the tracking of cyber risk remediation actions, including actions arising from risk assessments, assurance reviews, incidents, audits, control reviews and control improvement initiatives.
· Support the maintenance of the cyber risk register, including the capture of risks, issues and remediation actions, and the preparation of updates for governance forums.
· Support third-party and supplier security assurance activities, including security due diligence, assessment of supplier responses and tracking of supplier remediation actions.
· Coordinate and evidence user access reviews and privileged access reviews with system owners and the business, supporting the move to tool-based access certification.
· Perform first-line compliance monitoring and control checks against information security policies and standards, including the tracking of policy exceptions.
Policy & Procedure Development:
· Support the development, implementation and updating of IT risk, cyber security and compliance policies, standards and procedures to ensure alignment with legal, regulatory, control and sound practice requirements.
· Maintain an up-to-date understanding of applicable regulatory requirements and help implement changes to comply with new or evolving regulations.
· Assist in developing and delivering internal training and awareness on IT governance, cyber risk and compliance topics.
Reporting & Communication:
· Support the preparation of cyber risk, control and remediation reporting for management and governance forums.
· Support the development and tracking of key performance indicators (KPIs) related to IT risk and compliance.
· Support internal breach notification and escalation processes where required, in coordination with Legal, Data Protection and relevant stakeholders, including supporting regulatory reporting where appropriate.
SKILLS, QUALIFICATIONS AND EXPERIENCE
· Bachelor's degree in Cybersecurity, Information Technology, Risk Management, or a related field, or equivalent experience.
· Relevant certifications such as CRISC, CISA, CISM, ISO 27001 or CISSP, or a willingness to undertake similar, are desirable.
· Minimum of 5 years' experience in IT governance, risk management, cyber or information security, or a related role, with a strong knowledge of related control and compliance requirements.
· Working knowledge of key technology areas, including infrastructure, applications, networking, cloud services, vulnerability management, incident management and access controls.
· Experience supporting audit, regulatory or compliance activities, including evidence coordination, issue tracking and remediation follow-up. Experience with SOX compliance and ITGCs is desirable.
· Experience in insurance or wider financial services, or another regulated environment, is desirable.
· Excellent communication skills, with the ability to convey technical information to non-technical stakeholders.