Enable job alerts via email!

Itgrc Analyst

Buscojobs

Greater London

On-site

GBP 40,000 - 80,000

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking an IT Governance, Risk and Compliance Analyst to enhance policies and standards while ensuring compliance across various IT controls. This role involves supporting audits, evaluating risks, and collaborating with stakeholders to implement effective governance practices. The ideal candidate will have a strong background in risk management and compliance, with the ability to analyze complex information and communicate effectively. Join a dynamic team that values innovation and offers numerous opportunities for professional growth and development.

Benefits

Additional personal leave

Company discounts

Wellness programs

Paid days off for moving or volunteering

Qualifications

  • 2-4 years of experience in governance, risk management, compliance, or audit roles.
  • Strong understanding of risk assessment methodologies and frameworks.

Responsibilities

  • Support ITGRC program and global ISMS for compliance practices.
  • Evaluate compliance to IT controls, policies, and standards.

Skills

Governance

Risk Management

Compliance

Audit

Analytical Skills

Communication Skills

Problem-solving

Attention to Detail

Time Management

Education

Tertiary education in business administration

Information Security

Risk Management

Tools

Governance, risk management, and compliance software

Microsoft Office (Word, Excel, PowerPoint)

Job description

ITGRC Analyst

Department : IT

Employment Type : Permanent - Full Time

Location : Melbourne

Description

As the IT Governance, Risk and Compliance Analyst, you will apply your subject matter expertise in IT risk management and compliance to enhance and implement policies and standards, maintain control assurance activities, support IT audits, evaluate and improve IT controls, execute security and risk assessments, provide insights and guidance to IT and business stakeholders, and assess and document compliance with laws, regulations, directives, and contracts. You will also support the governance, risk and compliance tooling, and the vendor risk management program.

Key Responsibilities

  1. Support the ITGRC program and the global Information Security Management System (ISMS) for a large portfolio of applications, ensuring sustainable compliance practices across the company.
  2. Evaluate and monitor compliance to D&D’s IT controls, policies and standards and perform gap assessments. Map and maintain common controls framework and control scope / applicability for a portfolio of compliance initiatives.
  3. Facilitate and coordinate numerous ad hoc and periodic internal / external assessments, audits, and certifications, such as vendor assessments by key customers, ITGC and SOC 2 audits, and ISO 27001 certification, including evidence gathering, walkthrough coordination and management response to identified findings.
  4. Assist in driving the vendor / partner security risk assessment program using D&D’s 3rd-party risk assessment tool and support the vendor due diligence process.
  5. Support the implementation and ongoing management of an enterprise IT Governance, Risk and Compliance solution to enhance the company’s risk management and risk reporting / tracking capabilities.
  6. Assist in creating and maintaining policies, guidelines, and documentation that support the organization's IT GRC strategy. Work closely with other departments to ensure policies are communicated, understood, and followed.
  7. Support the development and maintenance of D&D’s global risk register and support risk treatment planning, monitoring, and reporting processes.
  8. Deploy a repeatable playbook for onboarding each acquired company onto the ISMS.
  9. Collaborate with D&D’s Legal department to incorporate new requirements from applicable legal / regulatory changes.
  10. Interface with global IT and business partners to provide guidance and support.
  11. Document and report control failures and gaps to stakeholders / control owners. Provide remediation guidance and prepare stakeholders' reports to track remediation activities.
  12. Evaluate and report any security / compliance risks to track as part of the company risk register. Consult on developing security standards, procedures, and controls to manage risks.

Skills, Knowledge and Expertise

  1. Tertiary education in business administration, Information Security, Risk Management, or a related field.
  2. At least 2-4 years of experience in governance, risk management, compliance, or audit roles. Familiarity with governance, risk management, and compliance software tools.
  3. Knowledge of applicable regulatory frameworks (e.g., ISO 27001, SOC 2, PCI DSS).
  4. Strong understanding of risk assessment methodologies and frameworks.
  5. Proficiency with Microsoft Office tools (Word, Excel, PowerPoint) and reporting tools.
  6. Strong analytical and problem-solving skills.
  7. Excellent attention to detail and organizational skills.
  8. Effective communication skills, with the ability to present complex information to various stakeholders. Ability to collaborate across teams and drive compliance initiatives.
  9. Strong time management skills, with the ability to prioritize tasks effectively.

Benefits

At Dye & Durham we strive to be visionaries! As a leader in our field, we ensure our employees are ready for the next challenge in their journey with us by offering a range of learning and career opportunities through mobility and learning. We offer a host of benefits including additional personal leave, company discounts, wellness programs, and paid days off to move house or volunteer for your favourite charity.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.