JOB DESCRIPTION
REPORTS TO: Compliance Lead
RESPONSIBLE FOR: The GRC Data Analyst will be responsible for managing compliance with EA ICT Assurance and other applicable cyber and information security policies and standards (e.g. those issued by the NCSC). The GRC Data Analyst will also be responsible for monitoring compliance for software licensing and for engaging with wider organisational and external compliance functions as necessary. The GRC Data Analyst will be responsible for engaging with the IT Security Officers to review the implementation of security policy and with the Network and Infrastructure teams in developing a means to monitor and measure compliance with policy for technical and procedural security controls. The GRC Data Analyst will be responsible for managing and leading the ICT Assurance compliance team. The GRC Data Analyst will be required to liaise with the Head of Services ICT Assurance on compliance issues to ensure consistency across EA service areas.
JOB PURPOSE
Leadership and management responsibilities
The GRC Data Analyst has the following leadership responsibilities for this portfolio of services:
Setting Vision and Strategy
Managing the Organisation to Deliver
Leadership
Building Relationships and Working with Others
Section-specific responsibilities
The following list provides an outline of the key responsibilities. It does not, however, represent a comprehensive list of tasks.
Control
Plan
Implement
Evaluate
Maintain
This job description is intended to provide a broad outline of the responsibilities and is not intended to be exhaustive. Other reasonable duties may be assigned by the ICT Assurance Compliance Lead and Head of ICT Assurance in consultation with the post-holder.
This job description will be subject to review in light of changing circumstances and is not intended to be rigid and inflexible but should be regarded as providing guidelines within which the individual works. Other duties of a similar nature and appropriate to the grade may be assigned from time to time.
In accordance with Section 75 of the Northern Ireland Act (1998), the post-holder is expected to promote good relations, equality of opportunity and pay due regard for equality legislation at all times.
PERSON SPECIFICATION
NOTES TO JOB APPLICANTS1. You must clearly demonstrate on your application form under each question, how, and to what extent you meet the required criteria as failure to do so may result in you not being shortlisted. You should clearly demonstrate this for both the essential and desirable criteria, where relevant.
2. You must demonstrate how you meet the criteria by the closing date for applications, unless the criteria state otherwise.
3. The stage in the process when the criteria will be measured is outlined in the table below.
4. Shortlisting will be carried out on the basis of the essential criteria set out in Section 1 below, using the information provided by you on your application form.
5. Please note that the Selection Panel reserves the right to shortlist only those applicants that it believes most strongly meet the criteria for the role.
6. In the event of an excessive number of applications, the Selection Panel also reserves the right to apply any desirable criteria as outlined in Section 3 at shortlisting, in which case these will be applied in the order listed. It is important therefore that you also clearly demonstrate on your application form on how you meet any desirable criteria.
Section 1 - Essential Criteria
The following are essential criteria which will initially be measured at the shortlisting stage and whichmay also be further explored during the interview/selection stage. You should therefore make it clear on your application form how, and to what extent you meet these criteria. Failure to do so may result in you not being shortlisted.
Factor Essential Criteria Method of Assessment Qualifications/Hold a Bachelor’s degree relating IT related field – Computer Science, Data science, Data Analytic, IT or Cyber-Security and have two years experience of performing a role involving IT data analytics or data engineering ideally with security context;
OR
five years’ experience of performing a role involving IT data analytics or data engineering ideally with security context.
Demonstrable experience of the successful operation of a compliance framework and governance model including policies, procedures and systems.
Shortlisting by Application Form
Skills/A good level of IT literacy using a range of ETL tools, such as Power BI.
Ability to analyse security compliance data and reporting findings to a variety of stakeholders, from Executive Summaries to SRO Reports.
Shortlisting by Application Form
KnowledgeDemonstrable knowledge of the current and anticipated cyber security challenges.
Knowledge of a range of information security governance, risk and compliance.
Shortlisting by Application Form
OtherWillingness to work outside of normal working hours as and when required.
The successful candidate will be required:
to have access to a suitable vehicle (appropriately maintained and insured for Education Authority business) that will enable them to carry out the mobility requirements of the post in an efficient and effective manner and thus meet this essential criterion;
OR
be able to provide sufficient information on the application form that will satisfy the employer that he/she has access to an appropriate alternative form of transport that will enable them to carry out the mobility requirements of the post in an efficient and effective manner and thus meet this essential criterion.
Shortlisting by Application Form
Section 2 - Essential Criteria
The following are additional essential criteria which will be measured during the interview/selection stage in line with EA’s Game Changing People Model.
Factor Essential Criteria Method of Assessment alifications/Demonstrable knowledge of management of IT security and compliance in a large organisation. This includes supporting development and implementation of strategic vision for the ICT Assurance Service.
Demonstrable Knowledge/experience of information Security frameworks, governance and operation models including but not limited to:
Knowledge of Compliance reporting.
Interview/Presentation
Skills/In line with EA’s Game Changing People Model we will look for evidence of:
A proven ability to analyse and solve problems using their broad knowledge of information security.
Good collaborative skills to build genuine and productive relationships with internal & external stakeholders.
Coach, Support, motivate and develop employees effectively, promoting inclusion and engagement.
Ability to respond to cyber security incidents in a calm and effective manner.
Proven ability to achieve targets/objectives and to meet challenging deadlines through the engagement of teams or working groups.
Interview
Values OrientationEvidence of how your experience and approach to work reflect EA’s ethos and values. You will find information about our Values here
Interview
Section 3 - Desirable Criteria
Some or all of the desirable criteria may be applied by the Selection Panel in order to determine a manageable pool of candidates. Desirable criteria will be applied in the order listed. You should make it clear on your application form how, and to what extent you meet the desirable criteria, as failure to do so may result in you not being shortlisted.
FactorDesirable CriteriaMethod of AssessmentKnowledgeKnowledge of Risk Management standards, such as ISO 27005.
Shortlisting by Application Form
Our Values
Through the selection process we will also seek evidence that the personal values of candidates align with those of the EA. This will include evidence of commitment to equality and excellence in service delivery. These reflect our aim which is to meet the needs of all our children and young people equally, removing barriers to learning and ensuring equality of access to excellent education services so that every child can develop to his or her full potential.
DISCLOSURE OF CRIMINAL BACKGROUND
The Safeguarding Vulnerable Groups (Northern Ireland) Order 2007 defines working directly with children or young people or in specified places as ‘regulated activity’.
In the event that you are recommended for appointed to a post that involves ‘regulated activity’, the Education Authority will be required to undertake an Enhanced Disclosure of Criminal Background.Please note that youWILLbe expected to meet the cost of an Enhanced Disclosure Certificate. Details of how to make payment will be sent to you at the pre-employment stage.
Further information can be accessed atNI Director theDepartment of Justice.
APPLICANT GUIDANCE NOTES
To view the applicant guidance notes, please click here .
To learn about the many great benefits of joining the Education Authority, click here
The Education Authority is an Equal Opportunities Employer.