- Company Name
- prosource.it
- Job Title
- Risk & Compliance Senior Analyst
- Job Description
-
**Job title**: Risk & Compliance Senior Analyst
**Role Summary**:
Assesses, monitors, and improves organisational risk and compliance frameworks across governance, information security, and resilience domains. Supports senior leadership in executing audit, control, and vendor risk initiatives, ensuring accurate documentation, incident response readiness, and regulatory alignment.
**Expectations**:
- Deliver high‑quality assurance and compliance activities independently with minimal supervision.
- Drive continuous improvement of policies, procedures, and controls.
- Communicate findings and recommendations clearly to technical and non‑technical stakeholders.
**Key Responsibilities**:
- Execute security, audit, and compliance activities under the Global Risk & Compliance Senior Manager.
- Conduct organisational risk assessments, control gap analyses, and vendor risk reviews.
- Manage incident response support, including investigation, documentation, and reporting.
- Maintain the Information Security Management System (ISMS) with accurate risk, event, and issue records.
- Facilitate audit tests, self‑certifications, and reviews in line with professional standards.
- Align actions with regulations such as GDPR, Data Protection Act, ISO/IEC 27001, ITIL, COBIT, NIST 800‑53, and Cybersecurity Framework.
- Collaborate with IT and business teams to elicit requirements and integrate controls.
- Use performance metrics to track and improve assurance outcomes.
- Deliver project support for integration and risk‑resilience initiatives.
**Required Skills**:
- Extensive control management experience in governance, compliance, IT audit, IS assurance, and risk programmes.
- Ability to interpret and apply regulatory and industry standards.
- Strong stakeholder management and communication across technical and executive audiences.
- Proficiency in implementing compliance frameworks (ISO/IEC 27001, ITIL, COBIT, NIST).
- Skilled in audit methodology and documentation.
- High integrity, confidentiality handling, and sound judgment.
- Knowledge of OneTrust or comparable risk‑management tools.
**Required Education & Certifications**:
- BSc or equivalent IT‑based degree (preferred).
- CISA, CISM, or equivalent professional certification (preferred).