Information Security GRC Analyst
Information Security GRC Analyst
Location: London
Salary: £38,000-£48,000
Working Pattern: Hybrid
About the Role
A London-based law firm is looking for a Information Security GRC Analyst to join its Risk and Information Security team. This is a strong opportunity for someone at the early stages of their GRC career to build practical experience within a professional services environment, with exposure to ISO 27001, information security risk, compliance and assurance.
Key Responsibilities
- Support the administration and continual improvement of the Information Security Management System (ISMS).
- Assist with ISO 27001 certification, surveillance and internal audit activities.
- Coordinate audit evidence collection and track remediation actions.
- Maintain information security policies, procedures, standards and governance documentation.
- Support information security risk assessments, treatment plans and exception tracking.
- Coordinate client security due diligence questionnaires and assurance requests.
- Support supplier assurance and third-party risk assessments.
- Produce information security metrics, dashboards and management reporting.
- Support security awareness, communications and training activities.
Key Requirements
- Understanding of information security governance, risk and compliance principles.
- Knowledge of ISO 27001 or other recognised information security frameworks.
- Some experience within Information Security, GRC, Risk, Compliance or a related area.
- Exposure to audits, compliance reviews or governance processes would be beneficial.
- Understanding of supplier assurance or third-party risk management would be advantageous.
- Experience producing reports, dashboards or management information.
- Proficiency in Microsoft Office, particularly Excel, Word and PowerPoint.
- Relevant information security or GRC qualifications, such as ISO 27001 Foundation or CISM, would be advantageous.
Inventum Group is acting as an Employment Agency in relation to this vacancy.