Lead Information Security Analyst, GRC

Company: Cirrus Logic
Apply for the Lead Information Security Analyst, GRC
Location: Edinburgh
Job Description:

Overview

In this role, you will lead and continually enhance Cirrus Logic’s ISO 27001-aligned ISMS and GRC program, focusing on integrated and third-party risk, AI governance, and security controls. You’ll partner across Legal, IT, and engineering to embed security into AI solutions and business initiatives. Expect collaboration with a global team to drive risk-informed decisions and enable secure, compliant product and services. This is a hands‑on, governance‑driven role with significant impact on enterprise security posture and AI risk management.

Responsibilities

  • Lead day-to-day operation and continuous improvement of ISO 27001–aligned ISMS, including policies, standards, and control procedures
  • Develop, maintain, and socialize information security policies, standards, and guidelines; manage risk-based exceptions
  • Lead Integrated Risk Management for new systems and initiatives, including AI/ML use case risk assessments
  • Plan and execute Third-Party Risk Management activities, including security questionnaires and remediation
  • Analyze risk across technologies and processes; produce risk and control status reports for leadership
  • Configure and optimize GRC tooling (ServiceNow GRC or OneTrust GRC) for risk, control, assessments, exceptions, and third-party workflows
  • Coordinate internal and external audits, and support customer security assessments and certifications
  • Partner with Legal and HR to manage privacy and regulatory obligations; assess AI privacy implications
  • Define AI risk governance guardrails, acceptable-use guidelines, and review processes for AI use cases and vendors
  • Act as trusted advisor to IT and business teams to embed security and governance into AI solution design and operations
  • Communicate risk, control, and program status clearly to technical and non-technical stakeholders; contribute to awareness and training

Key requirements

  • Proven experience in Information Security with a strong focus on GRC, risk management, and/or security compliance in a global environment
  • Bachelor’s degree in cybersecurity, information systems, or related field, or demonstrated equivalent experience
  • Hands-on experience with ISO/IEC 27001 and related frameworks (NIST CSF, ISO 27000, TISAX)
  • Experience with Integrated Risk Management and Third-Party Risk Management
  • Technical fluency across core IT and security domains; able to collaborate with Security Engineering and IT teams
  • Experience configuring enterprise GRC platforms (preferably ServiceNow GRC; OneTrust a plus)
  • Strong analytical and problem-solving skills; ability to balance security, compliance, and business needs
  • Excellent written and verbal communication; able to present to technical teams and executives
  • Proven ability to work independently and manage multiple initiatives in a fast-paced environment
  • Experience in high-tech/engineering or semiconductor environments is beneficial
  • Relevant certifications (ISO 27001 Lead/Implementer, CISSP, CISM, CISA, CRISC) preferred but not required
  • Strong communication and executive-level presentation skills
  • Collaborative and advisory mindset
  • Ability to translate complex risk into practical solutions
  • ISO/IEC 27001 ISMS lifecycle
  • NIST CSF
  • GRC platforms (ServiceNow GRC, OneTrust)

…

Posted: October 1st, 2026