Technology Risk / Compliance Analyst
Job Description
Technology Risk / Compliance Analyst (GRC)
\nUp to £66,000 + benefits
\nEdinburgh or Glasgow | Hybrid - 2 days office / 3 days home
\nOur client is a fast-growing, well-established software business providing regulatory and compliance solutions to financial services organisations. They are looking for a Technology Risk / Compliance Analyst to join their Governance, Risk & Compliance function, reporting directly to the VP of GRC.
\nThis role can be based out of either the Edinburgh or Glasgow office, working a hybrid pattern of 2 days in the office and 3 days from home.
\nThis is a genuine opportunity to build specialist expertise in technology, cyber, data and third-party risk within a regulated financial services environment - with direct exposure to senior GRC oversight, governance forums, control assurance and client due diligence work.
\nWhat you'll be doing
\n- \n
- Supporting risk and control self-assessments across technology, cyber security, data, cloud services and third-party/supplier risk \n
- Analysing incidents, operational events and control data to identify trends, root causes and areas for improvement \n
- Tracking risk actions and remediation plans, escalating overdue items where required \n
- Maintaining key risk indicators and control information to support accurate governance and client assurance reporting \n
- Preparing draft packs, dashboards and summary updates for senior GRC review \n
- Supporting responses to client, audit and regulatory due diligence requests \n
- Contributing to continuous improvement of risk processes, including the use of automation and AI-enabled tools \n
What we're looking for
\n- \n
- Proven skills in a risk, audit, technology, cyber, data or controls role \n
- Financial services background essential - experience working in, or with, a regulated environment \n
- Experience with a GRC or compliance automation platform (e.g. Secureframe, Vanta, Drata or similar) is a strong plus \n
- Naturally curious and proactive - comfortable identifying risks unprompted and confident challenging control owners on findings \n
- Strong analytical skills and the ability to translate risk data into clear, actionable insight for technical, non-technical and client audiences \n
- Awareness of frameworks such as ISO 27001, NIST, SOC 2, GDPR, DORA or operational resilience is desirable \n
What's on offer
\n- \n
- Salary up to £66,000 depending on experience \n
- Hybrid working - 2 days in the office (Edinburgh or Glasgow), 3 days from home \n
- Benefits package (pension, healthcare and further details on application) \n
- Direct exposure to senior GRC leadership and governance forums \n
- Genuine scope to shape and improve risk processes, not just maintain them \n
If the above sounds like you please send a copy of your latest CV for a confidential discussion
\nGuidant, Carbon60, Lorien & SRG - The Impellam Group Portfolio are acting as an Employment Business in relation to this vacancy.
