the City
Nub News Logo
Nub News

Security Risk Analyst

Where

City

Type

Contract

Salary

550 Daily

Security Risk Analyst 6-month contract London/Remote Inside IR35

My Customer is looking for a Security Risk Analyst to join their Governance, Risk & Compliance (GRC) team. You will play a key role in strengthening their risk management processes, working primarily with Archer and other GRC tools to support risk assessment, compliance, and governance activities.

In this role, you will be responsible for identifying, assessing, and tracking security risks across assets, systems, and third parties, ensuring compliance with internal standards, policies, and regulatory frameworks.

Key Skills from the Security Risk Analyst:

  • Strong background in Security Risk and Governance with hands-on experience in Archer (experience with other GRC tools is also valuable).
  • Solid understanding of risk assessment methodologies, security frameworks (NIST, ISO (phone number removed , and compliance requirements (GDPR, PCI DSS, SOX).
  • Strong written communication skills, able to produce clear technical reports and risk documentation.
  • Excellent stakeholder management, able to collaborate across technical and non-technical teams.
  • Beneficial certifications: CISSP, CISA, CISM (or equivalent).
  • ISO27001 / ISMS Accredited qualifications would be beneficial
  • Experience working in financial sector would be beneficial
  • Experience in ensuring internal IT system compliance against agreed standards

Key Responsibilities of the Security Risk Analyst:

  • Maintain and improve the security risk assessment framework, procedures, and workflows.
  • Manage and update security questionnaires to align with compliance requirements, industry standards, and regulations.
  • Conduct asset-level and third-party/vendor risk assessments.
  • Analyse and document inherent and residual risks, providing clear recommendations.
  • Produce detailed technical reports highlighting findings, control gaps, and proposed remediation plans.
  • Drive remediation
  • Perform periodic and ad-hoc risk assessments in line with organisational policies.

The Security Risk Analyst is required onsite in London, once a week.

Apply now to speak with VIQU IT in confidence about the Security Risk Analyst role. Or reach out to Connor Smal via the VIQU IT website.

Do you know someone great? We ll thank you with up to £1,000 if your referral is successful (terms apply).

For more exciting roles and opportunities like this, please follow us on IT Recruitment.

Related Jobs

RF Recruitment Consultancy

Annual

City (EC1A2)

Permanent

Are you a qualified plumbing and heating engineer? Are you looking for a new mobile role where you will be working for a well organised service provider with a range of clients in the UK. Within this mobile engineer role you will be working both in London and on the outskirts and will enjoy a varied role.

1st Step

Annual

City (EC1A2)

Permanent

1st Step Solutions are supporting an M&E Contractor who have an opportunity for a on a Infrastructure Engineer on a Permanent basis based in London Barbican. Hybrid model of work - 3 days in the office and 2 days at home.Role overview:The Infrastructure Engineer plays a key role in supporting the organisation's IT strategy and digital transformation objectives. This position is central to driving the adoption of modern technologies while ensuring infrastructure remains secure, resilient, and aligned with business goals. The role requires a proactive approach to technology trends and continuous improvement across the IT estate. Key Duties: Configure, monitor, and maintain network infrastructure and ensure network security. Support, administer, and assist in the development of server and user infrastructure, including virtualisation technologies. Oversee software across servers and user devices. Maintain compliance with the internal Approved Software List. Administer ERP systems. Monitor and maintain the Microsoft cloud environment. Manage Helpdesk tickets, escalate where needed, and ensure SLA compliance. Conduct root cause analysis and implement solutions. Deliver planned and ad-hoc IT projects within established frameworks. Create and maintain all IT documentation. Administer security tools and maintain governance, risk, and compliance standards. Improve security posture, using tools such as Microsoft Secure Score. Support implementation of business process improvements. Review and suggest enhancements to current procedures. Make independent decisions aligned with departmental and strategic IT objectives. Act as Deputy for other roles when competent to do so and appoint a suitable Deputy during periods of absence.Qualifications & Experience Minimum 5 years in IT roles, including at least 2 years in a service delivery capacity. Experience with internal and external stakeholders, regulated environments, and ITIL-aligned processes. A combination of the following is preferred: CompTIA (Networking, Security, A+, Server), Microsoft Certifications (e.g. Azure Administrator, Security, Server Hybrid Admin, Power Platform Fundamentals). Membership in relevant bodies such as BCS, IEEE, ISACA, (ISC) , CompTIA, or ITIL/AXELOS. Skilled in LAN/WAN management, VLANs, routers/switches, VPNs (Azure or Always On), firewall configuration, and protocols (DNS, DHCP, TCP/IP). Proficient in PowerShell for automation and reporting. Knowledge of Power Automate and CI/CD pipelines. Knowledge of disaster recovery and business continuity planning. Experience with storage solutions and playbook maintenance. Experience with Microsoft Defender, Sentinel or equivalent SIEM tools, RBAC, PIM, and awareness of ISO 27001 / Cyber Essentials. Familiarity with IAM, PAM, XDR, and GRC tools. Proficient in Microsoft 365, Azure, Entra, SharePoint, Exchange, Purview, Intune, Teams, Power Platform, and other Microsoft services. Experience in Windows Server admin, OS hardening, patching, Hyper-V, VM provisioning, backup, HA, and clustering. Knowledge of AD/AAD, GPOs, Entra ID, SSO, MFA, and Conditional Access. Open to adopting new tools, technologies, and methodologies. Clear in both verbal and written communication; confirms understanding when conveying information.Package: Competitive salary Private Medical Healthcare Cash Back Plan Life Assurance Excellent annual leave Employee Assistance Programme Pension Maternity and Paternity pay Other discounts and company benefits

Sign-up for our FREE newsletter...

We want to provide thecity with more and more clickbait-free news.