Cyber Security GRC Analyst
Powered by Water, Driven by Purpose
South West Water keeps the South West flowing with safe, reliable drinking water and wastewater services across some of the UK’s most stunning landscapes.
We’re proud to be part of Pennon Group, a leader in the UK water sector, working towards a greener future. Our goals? As well as lowering our carbon footprint, we’re working with partners to plant 300,000 trees, restore peatlands and supporting farmers and landowners to improve water quality and wildlife.
Whether you’re starting out or seeking a new challenge, our scale and ambition create opportunities for you to shape your own career.
Ready to make a splash? Join our team today.
Help protect critical services through effective cyber security governanceAre you passionate about cyber security, data governance and compliance? Do you enjoy translating complex security requirements into practical controls that make a real difference?
We're looking for a Cyber Security GRC Analyst to join our growing Cyber Security team. In this role, you'll play a key part in strengthening our cyber security posture through governance, risk management and compliance activities, while helping to ensure our information assets remain protected.
A significant focus of the role will be the administration and continual improvement of Microsoft Purview, ensuring effective data protection, information governance, data classification and compliance capabilities are embedded across the organisation.
Working closely with stakeholders across IT, Legal, Audit, Procurement and the wider business, you'll help shape security practices, drive compliance initiatives and support a positive security culture.
What you'll be doing:As our Cyber Security GRC Analyst, you will:
Administer, maintain and continuously improve Microsoft Purview capabilities, including:
Data Loss Prevention (DLP)
Information Protection
Data Lifecycle Management
Insider Risk Management
Communication Compliance
eDiscovery
Compliance Manager
Support the implementation and adoption of data classification and sensitivity labelling.
Monitor security and compliance alerts, investigate findings and coordinate remediation activities.
Develop and maintain security policies, controls and standards.
Produce management reporting, dashboards and compliance metrics.
Plan, conduct and document internal ISO 27001 audits.
Support third-party risk management and supplier security assurance activities.
Help maintain compliance with frameworks and regulations such as ISO 27001, NIS Regulations and Cyber Essentials.
Support information security awareness initiatives and promote a strong security culture.
Assist in security incident investigations and remediation activities.
Work with business stakeholders to improve information governance practices and data ownership accountability.
Experience administering or supporting Microsoft Purview and Microsoft 365 security and compliance solutions.
Knowledge of Microsoft Purview capabilities, including DLP, Information Protection, Sensitivity Labels, Insider Risk Management, eDiscovery and Compliance Manager.
Experience supporting data governance, information protection and compliance activities within a Microsoft 365 environment.
An understanding of cyber security risk management, governance and control frameworks.
Knowledge of information security standards such as ISO 27001, NIS Regulations and Cyber Essentials.
Experience producing reports, managing stakeholders and supporting audit activities.
Strong communication skills with the ability to influence and build relationships across diverse teams.
5 GCSEs (or equivalent), including Maths and English.
Educated to degree level or able to demonstrate equivalent professional experience.
Hands-on experience of Microsoft Purview administration and optimisation.
Experience within information security, governance, risk or compliance functions.
Knowledge of recognised security frameworks such as ISO 27001, NIST or Cyber Essentials.
Ability to successfully obtain UK Government Security Clearance (SC).
This is an excellent opportunity to develop your cyber security governance and compliance career within a supportive environment. You'll gain exposure to enterprise-scale Microsoft security technologies, contribute to critical compliance programmes and play a meaningful role in protecting services, systems and data that matter.
Generous holiday allowance plus bank holidays
A discretionary Bonus
Competitive Contributory Pension
Share-save Scheme
Various health benefits
Wellbeing support programmes
A range of Group Discounts
Cycle to Work Scheme
Closing Date: 1st September 2026
We may close this vacancy early if we receive a high volume of applications. We encourage you to apply as soon as possible.
Please note that the successful candidate will be subject to a mandatory DBS check as part of the onboarding process.
Be yourself, we like it that way. Together, we will build a culture of belonging, where inclusion is instinctive. Diversity is our strength and a reflection of our communities. We care, we value everyone, we celebrate uniqueness.
Our core values, which are essential to our success, are:
Be Rock Solid - Build trust and be trusted. Be the one we all look to and can depend on.
Be You - We want you to bring your best everyday. Be yourself and make your mark in your individual way.
Be the Future - Embrace change. Drive Progress. Own the challenge.