Full-Time Security GRC Analyst (UK Remote)
Jobs For Humanity is hiring a remote Full-Time Security GRC Analyst (UK Remote). The career level for this job opening is Experienced and is accepting Newcastle upon Tyne, United Kingdom based applicants remotely. Read complete job description before applying.
Jobs For Humanity
Job Title
Posted
Career Level
Career Level
Locations Accepted
Share
Job Details
Turnitin is seeking an experienced Security GRC Analyst to join our Security & Compliance team.
The Sr Security GRC Analyst will be responsible for ensuring that our information and cloud systems comply with relevant regulatory frameworks, industry standards, and internal policies.
Responsibilities:
- Maintain compliance tracking capabilities to ensure adherence with Turnitin’s security program and industry standards (NIST CSF, NIST 800-53, SOC 2, TX-RAMP, PCI DSS).
- Conduct risk and compliance assessments, audits, and risk evaluations to identify potential risk and compliance gaps.
- Lead preparation and audit activities for SOC 2 Type 2.
- Collaborate with internal teams and external auditors for audit and compliance reviews.
- Collaborate with sales and customer support teams for security questionnaires.
- Support TPRM Program and conduct third-party risk assessments.
- Complete user access reviews and administer GRC platform.
- Participate in developing and documenting security policy, standards, and processes.
- Provide security awareness and phishing training.
- Coordinate phish testing.
- Collaborate with DevOps, IT, Legal, Engineering, People Team, to integrate security controls.
- Provide input for process improvement and automation.
Qualifications:
- Bachelor’s degree in Computer Science, Information Security, or related field.
- 3+ years of experience in Information Security or Cybersecurity Compliance.
- Relevant professional certifications (e.g., CCSK, AWS Cloud Practitioner).
- Familiarity with cybersecurity frameworks and regulatory standards (NIST, SOC 2, TX-RAMP, PCI DSS).
- Familiarity with risk management and security best practices.
- Experience assessing security controls, risk mitigation, and audit procedures.
- Understanding of AWS Cloud Infrastructure and security.
- Experience conducting security impact analysis for system changes.
- Experience conducting internal security reviews or risk assessments.
- Experience conducting third-party risk assessments.
- Contract review experience.
- Highly organized and proactive individual.
Preferred Skills:
- Experience running SOC 2 audits or NIST authorizations.
- Experience using Jira and Confluence.
- Hands-on experience with Wiz, KnowBe4, and Hyperproof.