Senior IT Security GRC Delivery Analyst
Core
Lead governance, risk, and compliance initiatives for the cyber security function, acting as a trusted advisor on security policies, risk management, and SOCI obligations.
Role type
Senior IT Security GRC Delivery Analyst
Builds
IT Security Governance, Risk and Compliance framework; risk registers; security policies and standards; executive-level reporting on risk and compliance.
Domain
Cyber Security / Governance, Risk, and Compliance (GRC) / Critical Infrastructure
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Information security governance, risk and compliance; security policy and standards development; risk register management; control remediation; SOCI obligations knowledge; executive reporting; stakeholder influence; Operational Technology (OT) environment exposure
Preferred skills
Critical infrastructure experience; highly regulated enterprise environment experience
Technologies
GRC platforms; risk management tools
Responsibilities
Maintain and enhance the IT Security Governance, Risk and Compliance framework; manage the IT Risk Register and treatment plans; develop and maintain security policies and governance documentation; deliver executive-level reporting on risk, compliance, and audit activities; coordinate with risk owners to assess risks and drive mitigation to closure; support audit, assurance, and control testing activities; drive accountability and remediation across technology and operational teams
Seniority
Senior, hands-on IC
