← Takaisin työpaikkoihin

Cyber GRC Analyst

  • Etätyö
  • Ruotsi
  • Englanti
  • Julkaistu 14.09.26 13:54

Cyber GRC Analyst | 12 Month Contract | Remote (EU) We are hiring a Cyber GRC Analyst for a large organisation that is building out its own in-house Cyber Security function. This is an urgent backfill with an immediate start, on an initial 12 month contract, and the role is fully remote for candidates based in the EU. ABOUT THE ROLEOur client is taking ownership of cyber security in-house from its wider parent group, which means this role sits right at the centre of how the new function is shaped. You will own cyber risk, controls assurance, compliance and governance activity, and work directly with business and technology owners across the organisation. Day to day you will be running cyber security risk assessments, assessing and testing security controls, managing third party and supplier risk, tracking remediation through to closure, supporting audits, and building out policy and governance. Please note: this is not a SOC, Security Engineering or pure IT Audit position. It sits squarely in Cyber GRC, Cyber Risk and Security Assurance, with a genuine balance across risk, controls, compliance and governance. WHAT YOU WILL BE DOINGDelivering cyber security risk assessments across the business and technology estateAssessing, testing and providing assurance over security controlsOwning third party and supplier risk management end to endProviding compliance oversight against applicable frameworks and regulatory obligationsTracking remediation actions with business and technology owners and driving them to closureSupporting internal and external audit activityDeveloping, maintaining and embedding cyber policies, standards and governance processesEngaging stakeholders at all levels and translating technical risk into business languageWHAT WE ARE LOOKING FORA background in Cyber GRC, Cyber Risk or Security ComplianceExperience running cyber security risk assessmentsSecurity controls assessment, testing and assurance experienceThird party and supplier risk managementCompliance oversight and remediation trackingAudit support experiencePolicy and governance workStrong stakeholder management skillsWorking knowledge of NIS2, GDPR, NIST CSF or equivalent frameworksNICE TO HAVEExperience in a regulated industry such as aviation, financial services or critical national infrastructureSecure by DesignCloud security controls and modern IT architectureCyber resilience, including BCM, DR and cyber recoveryStructured control testing methodologiesPolicy and standards lifecycle managementPower BIGRC platforms such as ServiceNow GRC, Archer or SureCloudCertifications such as CISSP, CISA, CRISC or ISO 27001 Lead Implementer / Lead Auditor IS THIS ROLE FOR YOU?This role will suit someone who owns risk and controls rather than operates them. If your background is primarily SOC operations, incident response or security engineering, or if your experience is compliance checkbox work without hands-on risk assessment and controls assurance, this one is unlikely to be the right fit.