IT Security Governance, Risk & Controls Analyst

Reference: ae9k59vkyc6hrfzqtxad

We are seeking an IT Security Governance, Risk & Controls Analyst to support the development, operation and continuous improvement of information security governance and risk management processes. In this role, you will help ensure that technology environments, business processes and third-party services are aligned with internal policies, regulatory expectations and recognised security frameworks. You will work closely with technology, risk, compliance, audit and business stakeholders to identify security risks, assess control effectiveness and support practical remediation plans.

Key responsibilities will include maintaining security policies, standards, procedures and control frameworks; coordinating periodic risk and control assessments; documenting risks, findings, action plans and exceptions; and monitoring progress through to resolution. You will support internal and external audits, provide evidence and responses, and help prepare management reporting on control performance, risk exposure and compliance activities. The role will also involve reviewing security requirements for projects, suppliers and technology changes, contributing to third-party risk assessments, and helping deliver awareness and governance initiatives. You may assist with control testing across areas such as access management, vulnerability management, incident response, data protection, business continuity and change management.

The successful candidate will have experience in information security governance, technology risk, IT controls, audit or compliance, with a sound understanding of frameworks such as ISO 27001, NIST, COBIT or CIS Controls. Relevant professional qualifications or certifications are desirable, as is experience working with GRC platforms, audit tools and reporting technologies. You will be analytical, organised and confident interpreting technical information, identifying gaps and communicating clearly with both technical and non-technical audiences. Strong stakeholder management, attention to detail and the ability to manage multiple priorities are essential. This is an opportunity to contribute to a mature and evolving security function while helping strengthen resilience, accountability and risk-aware decision-making across the organisation.

COMPETITIVE SALARY
Added 22/09/2026
Reference: ae9k59vkyc6hrfzqtxad

IT Security Governance, Risk & Controls Analyst

London, England, United Kingdom Permanent Governance and Compliance

Other similar jobs

IT Security Compliance & Reporting Analyst

Added 01/09/2026

We are seeking an IT Security Compliance & Reporting Analyst to support the ongoing development, monitoring and improvement of information security compliance across the organisation. In this role, you will help ensure that technology services, systems and processes meet relevant internal policies, regulatory requirements, contractual obligations and recognised security frameworks. You will work closely with IT, risk, audit and business stakeholders to gather evidence, assess control effectiveness and identify opportunities for improvement. Your responsibilities will include coordinating compliance reviews, maintaining control and risk registers, preparing audit evidence, tracking remediation actions and producing clear, accurate reports for management and governance forums....

Learn more

Application Security Consultant

Added 24/08/2026

Are you passionate about securing modern applications and guiding organizations in robust security practices? We are looking for an Application Security Consultant to join our dynamic team. In this role, you will be responsible for assessing, advising, and implementing security measures across a wide range of software development projects. You will work closely with development teams to identify vulnerabilities, perform code reviews, and provide recommendations for remediation. Your expertise will be crucial in building secure software solutions, conducting threat modeling exercises, and ensuring compliance with industry standards and best practices. Key responsibilities include conducting application security assessments for both web...

Learn more

IT Risk & Controls Analyst

Added 25/08/2026

We are seeking an IT Risk & Controls Analyst to support the effective identification, assessment and management of technology-related risks across the organisation. This role will help strengthen the control environment by assessing whether IT processes, systems and activities are designed and operating effectively, while providing practical recommendations to address weaknesses and improve resilience. Key responsibilities will include supporting risk and control assessments, maintaining risk and control documentation, and coordinating the review and testing of IT general controls, application controls and key technology processes. You will assist with internal and external audit activities, track remediation plans, validate evidence, and monitor...

Learn more

Business Analyst (Cyber Controls & Compliance) - Contract

Added 17/09/2026

We are seeking an experienced Business Analyst to support cyber controls and compliance activities on a contract basis. The successful candidate will work with cybersecurity, technology, risk, audit and business stakeholders to understand regulatory obligations, assess control effectiveness and help strengthen the organisation’s overall control environment. This role is suited to someone who can translate complex security and compliance requirements into practical, clearly documented processes and actionable improvements. Key responsibilities will include gathering and analysing business and control requirements; documenting current and future-state processes; mapping controls to relevant policies, standards and regulatory frameworks; and identifying gaps, risks, dependencies and opportunities...

Learn more

Cybersecurity Controls Analyst (SDLC/Deployment)

Added 11/08/2026

We are seeking a detail-oriented Cybersecurity Controls Analyst to join our dynamic team, focusing on the Software Development Life Cycle (SDLC) and deployment processes. In this role, you will be responsible for assessing and implementing cybersecurity controls throughout the development lifecycle, ensuring that security requirements are integrated into all phases from design to deployment. You will collaborate with cross-functional teams to identify potential vulnerabilities, assess risks, and develop strategies to mitigate them effectively. Your expertise will be crucial in conducting security assessments, audits, and compliance reviews to ensure adherence to organizational and regulatory standards. The ideal candidate will have a...

Learn more

Senior IT Cyber Governance, Risk & Compliance Analyst

Added 18/08/2026

We are seeking a highly skilled Senior IT Cyber Governance, Risk & Compliance Analyst to join our dynamic team. In this role, you will be responsible for developing, implementing, and maintaining an effective governance, risk management, and compliance framework to ensure the organization meets all regulatory requirements and industry standards. You will conduct thorough risk assessments, identify vulnerabilities, and recommend appropriate mitigation strategies. Additionally, you will collaborate with cross-functional teams to enhance cybersecurity policies and procedures, ensuring alignment with overall business objectives. The ideal candidate will have a strong background in IT security, risk management, and compliance, with a proven...

Learn more

InfoSec Governance, Risk and Compliance Analyst

Added 10/08/2026

We are seeking a qualified InfoSec Governance, Risk and Compliance Analyst to join our dynamic team. In this role, you will be responsible for developing, implementing, and maintaining the organization's information security governance framework. You will work closely with various departments to ensure compliance with relevant regulations and standards, while promoting a culture of security awareness throughout the organization. Your expertise will be crucial in identifying and assessing risks, as well as implementing effective strategies to mitigate them. Key responsibilities include conducting regular audits and assessments of information security policies and procedures, ensuring adherence to industry standards such as ISO...

Learn more

Cyber Security Controls Tester (Contractor)

Added 11/09/2026

We are seeking an experienced Cyber Security Controls Tester to support the assessment, validation and continuous improvement of security controls across a complex technology environment. Working on a contract basis, you will help determine whether controls are appropriately designed, consistently implemented and operating effectively in line with internal policies, recognised security frameworks and applicable regulatory requirements. You will work closely with control owners, technology teams, risk specialists and internal stakeholders to gather evidence, clarify processes and communicate findings. Your responsibilities will include planning and executing control testing activities across areas such as access management, vulnerability management, change management, incident response,...

Learn more

Lead Software Engineer, Cyber Security Controls Automation

Added 02/09/2026

We are seeking a Lead Software Engineer, Cyber Security Controls Automation to design, build and lead the delivery of scalable solutions that strengthen security control compliance across a complex technology environment. You will work at the intersection of software engineering, cyber security, cloud platforms and governance, translating control requirements into reliable, automated capabilities that improve visibility, reduce operational risk and support continuous assurance. In this role, you will provide technical leadership across the full software development lifecycle, from discovery and architecture through development, testing, deployment and ongoing optimisation. You will develop automation for security control monitoring, evidence collection, exception management,...

Learn more

1st Line Security Controls Testing Manager

Added 26/08/2026

We are seeking a 1st Line Security Controls Testing Manager to lead the effective delivery of first-line security control testing across a complex and evolving environment. You will be responsible for establishing and maintaining a robust testing approach that provides clear assurance over the design, implementation and operating effectiveness of key information and cyber security controls. Working closely with control owners, risk teams, internal audit and technology stakeholders, you will help identify weaknesses, assess risk exposure and drive timely remediation. Your responsibilities will include developing risk-based testing plans; prioritising activities in line with regulatory, business and threat requirements; overseeing control...

Learn more

Senior Data Scientist - (Privacy & Security Controls)

Added 20/08/2026

We are seeking a highly skilled Senior Data Scientist specializing in Privacy & Security Controls to join our dynamic team. In this role, you will lead the development and implementation of advanced analytical models to ensure data privacy and security across various platforms. You will be responsible for analyzing complex datasets, identifying vulnerabilities, and creating solutions that adhere to compliance regulations. Collaborating with cross-functional teams, you will help to design and enhance privacy and security features within our products while ensuring that data handling practices meet industry standards. The ideal candidate will possess a strong background in data science, machine...

Learn more

Senior Data Scientist - (Privacy & Security Controls)

Added 19/08/2026

We are seeking a highly skilled Senior Data Scientist specializing in Privacy & Security Controls to join our dynamic team. In this role, you will be responsible for developing and implementing advanced data analytics solutions that ensure the privacy and security of sensitive information. You will work closely with cross-functional teams to design data-driven strategies that mitigate risks, enhance compliance, and promote best practices in data governance. Your expertise will be pivotal in analyzing large datasets to identify vulnerabilities and recommend actionable insights that support organizational objectives. The ideal candidate will possess a deep understanding of data privacy regulations, security...

Learn more

Cyber Controls Manager

Added 22/09/2026

We are seeking a Cyber Controls Manager to lead the development, implementation and continuous improvement of cybersecurity controls across a complex technology and business environment. This role will help strengthen cyber resilience by ensuring that security controls are appropriately designed, consistently operated, regularly assessed and aligned with relevant regulatory, industry and internal requirements. You will work closely with technology, risk, compliance, audit and business stakeholders to identify control gaps, agree remediation plans and support a strong culture of security and accountability. Key responsibilities will include maintaining the cybersecurity control framework; mapping controls to recognised standards and regulatory obligations; coordinating control...

Learn more

Cyber Controls Specialist

Added 22/09/2026

We are seeking a Cyber Controls Specialist to support the design, implementation and ongoing improvement of cybersecurity controls across a complex technology and business environment. The role will help ensure that security practices align with internal policies, recognised industry frameworks and applicable regulatory requirements. You will work closely with technology, risk, audit and business stakeholders to assess control effectiveness, identify weaknesses and coordinate practical remediation plans. Key responsibilities include maintaining and reviewing the cybersecurity control framework; mapping controls to relevant standards and regulatory obligations; supporting risk and control self-assessments; and gathering evidence for internal and external assurance activities. You will...

Learn more

Cybersecurity Controls Testing Assistant Manager

Added 01/09/2026

We are seeking a Cybersecurity Controls Testing Assistant Manager to support the evaluation of information security controls across technology, business, and third-party environments. In this role, you will help assess whether controls are appropriately designed, implemented, and operating effectively against internal policies, recognised security frameworks, and applicable regulatory requirements. You will contribute to risk-focused testing plans, coordinate review activities, and provide clear, evidence-based conclusions to stakeholders. Key responsibilities include performing and reviewing control testing, documenting procedures and results, identifying control gaps, and assessing the impact of exceptions. You will work with control owners to obtain supporting evidence, challenge responses where...

Learn more
Required for two factor authentication
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.