IT Security Governance, Risk & Controls Analyst

About RicohA global leader in digital services, recognised for innovation, sustainability and a people-first culture. We feature in the Gartner Magic Quadrant, are listed in the Global 100 Most Sustainable Companies, and have been named one of Forbes' World's Best Employers 2025. At Ricoh, we believe people do their best work when they feel valued and supported. We create inclusive workplaces where you can grow, contribute, and make a positive impact while helping to build a more sustainable future.

Find your place. Transform your futureOur purpose is centred on understanding and improving how people work. By focusing on real working experiences, we support individuals to develop their skills, realise their potential and do work that feels meaningful.

People transform when they Love What They DoThis belief sits at the heart of The Ricoh Promise. It guides how we recruit, how we support our people, and how we work together every day, creating an environment where you can grow, feel valued and make a difference.

When you join us, you are encouraged to share your ideas, challenge the way things are done, and work with others to build something better. If you are looking for a place where your voice is heard, your development is supported, and your work feels meaningful, you will feel at home at Ricoh.#RicohEuropeWhat you will be doingWe're looking for an IT Security Governance, Risk & Controls Analyst to help strengthen the security, governance and resilience of our European IT environment. This is an exciting opportunity for someone who enjoys working across security governance, technology risk and controls, helping organisations understand their security posture and make informed decisions about risk.

Working closely with infrastructure, cloud, identity and operational IT teams, you'll help develop and embed security policies, standards and controls, manage technology risks and support assurance activities across the European IT landscape.

You'll be someone who can take security frameworks and requirements and turn them into practical, effective controls — while building strong relationships with technical teams and senior stakeholders along the way.

If you enjoy improving security maturity, challenging the status quo and helping teams manage risk in a practical way, we'd love to hear from you.

Key Responsibilities Include:

Develop, maintain and embed IT security policies, standards, procedures and control requirements.

Support the development and continuous improvement of the IT security governance and control framework.

Own and maintain the IT Security Risk Register, ensuring risks are appropriately assessed, documented, monitored and managed.

Facilitate technology and security risk assessments, working with technical teams to identify risks and agree appropriate mitigation plans.

Assess the effectiveness of security controls and identify control gaps, weaknesses and opportunities for improvement.

Translate security frameworks and requirements, including ISO 27001 and NIST CSF, into practical operational controls.

Support audit, assurance and compliance activities, including ISO 27001, Cyber Essentials and internal control programmes.

Work with technology teams to ensure security controls are understood, implemented and operating effectively.

Provide clear reporting and insight on security risks, control effectiveness, compliance and remediation activity.

Track remediation actions and work with stakeholders to ensure identified risks and control gaps are addressed.

Support the continuous improvement of security governance, risk and control processes across the European IT function.

Build strong relationships with technical and business stakeholders, acting as a trusted partner on security risk and governance matters.

You will ideally haveYou'll have experience working in IT Security, Information Security Governance, IT Risk, Security Controls, GRC or a similar environment, with a strong understanding of how security governance operates within a complex organisation.

Ideally, you'll bring: Experience in IT Security, Security Governance, IT Risk, GRC or Security Controls.

Experience developing and maintaining security policies, standards, procedures and control frameworks.

Strong understanding of security governance and risk management principles.

Experience conducting or supporting technology/security risk assessments and maintaining risk registers.

Good knowledge of security control frameworks such as ISO 27001 and NIST CSF.Experience assessing control design and effectiveness, identifying gaps and supporting remediation.

Understanding of key IT security disciplines including vulnerability management, patching, identity and access management, privileged access management and backup governance.

Experience supporting internal or external audits, assurance reviews and compliance programmes.

Strong analytical and problem-solving skills, with the ability to understand complex risks and translate them into practical actions.

Excellent communication and stakeholder management skills, with confidence engaging with both technical teams and senior leadership. A proactive approach to improving security maturity, governance and control effectiveness.

Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer or similar would be advantageous.

In return for your commitment, you can expectAt Ricoh, work should feel meaningful, supportive and fulfilling. The Ricoh Promise shapes your experience through four pillars that bring our culture to life.

Love to ConnectYou become part of a global community built on openness, inclusion and genuine collaboration.

Across teams, countries and roles, you'll find people who listen, involve and encourage you - helping you feel valued and able to be yourself every day. Love to GrowYour development truly matters to us. With access to learning pathways, mentoring and career opportunities across functions and countries, you'll be supported to stretch your skills, explore new directions and stay future-ready in a changing world.

Love to Give BackPurpose is part of how we work. You'll have opportunities to make a difference through volunteering, sustainability initiatives and community programmes that reflect our shared values and commitment to positive impact. Love to SucceedSuccess at Ricoh is something we pursue together. You'll benefit from fair rewards, flexible working, wellbeing resources and real recognition - including programmes such as the Imagine. Change. Awards, where colleagues celebrate each other's achievements.

We are an equal opportunities employerWe believe that diverse perspectives make us stronger, and we welcome applications from people of all backgrounds, identities, and experiences. Our hiring decisions are based on skills, experience and potential, and we are committed to creating a fair and inclusive recruitment process. If you require any reasonable adjustments at any stage of the recruitment journey, please let us know and we will support you to bring your best self forward. Ready to love what you do? Apply now and help us shape what comes next.

Job SummaryJob number: RE02684Profession: Information TechnologyEmployment type: Full time

Job Details

Company
Ricoh
Location
London, UK
Employment Type
Full-time
Posted