Security Compliance Analyst-UK

Company: Certinia
Apply for the Security Compliance Analyst-UK
Location: Harrogate
Job Description:

Overview

In this Security Compliance Analyst role, you support customer trust and security governance across Certinia’s enterprise. You will help respond to customer inquiries, manage audits, and monitor controls with cross-functional partners in IT, Legal, and Privacy. The position contributes to the ongoing security program, aligning with multiple frameworks to sustain risk posture and customer confidence. You’ll engage with sales, customers, and vendors to drive secure, compliant solutions at scale. This is a chance to shape security posture in a fast-growing, SaaS environment.

Responsibilities

  • Assist Customer Trust Program responses and support RFx activity
  • Maintain standard responses in the contract and proposal process
  • Support customer calls to highlight security within products
  • Support compliance audits and readiness initiatives (SOC 1, SOC 2, ISO 27001, ISO 42001, FedRAMP)
  • Monitor remediation efforts across functions and geographies
  • Document gap analyses and track remediation progress
  • Contribute to policies, standards, procedures, and guidelines
  • Maintain security controls library and map controls to frameworks
  • Coordinate with Legal on security language aligned to commitments
  • Perform third-party risk assessments for annual reviews and new vendors
  • Maintain vendor inventory in Whistic with up-to-date information and audit-ready documentation
  • Track remediation for any non-compliance issues

Key requirements

  • 2+ years in information security, GRC or IT audit
  • Experience with ISO 27001, SOC 1, SOC 2, FedRAMP or similar
  • Bachelor’s Degree or equivalent in related field
  • Strong customer-facing communication skills
  • Strong written communication with attention to audience tailoring
  • Customer-focused mindset and sales enablement awareness
  • Experience working across global teams and time zones
  • customer-facing communication
  • attention to detail
  • collaboration across functions
  • GRC practices
  • information security frameworks (ISO 27001, SOC 1, SOC 2, FedRAMP)
  • third-party risk assessments

Posted: September 16th, 2026