Information Security (GRC) Analyst

Company: Softcat
Apply for the Information Security (GRC) Analyst
Location: Manchester
Job Description:

Overview

In this role you will support governance, risk and compliance activities within Softcat’s Information Security team. You will help keep controls, records and evidence audit-ready, while learning practical GRC skills across ISO 27001 and CE+ programs. You collaborate with cross-functional teams and contribute to a culture that values development and security maturity. This position offers hands-on exposure to supplier assurance, audits and reporting in a growing technology environment.

Pay / Benefits

  • Hybrid working – 2 days in office, 3 days from home
  • Flexible hours
  • Support for diverse backgrounds and neurodiversity
  • Inclusive, collaborative team culture
  • Potential for career development
  • Permanent, full-time role

Responsibilities

  • Support information security governance, risk and compliance activities across the business
  • Complete due diligence assessments on suppliers and maintain associated records
  • Respond to customer assurance questionnaires with approved evidence
  • Maintain security policies, procedures, evidence libraries and compliance records
  • Support internal audits, control testing and tracking of corrective actions
  • Update the Information Security Risk Register and follow up actions
  • Collect and validate information used in security metrics and reporting
  • Support ISO 27001 and CE+ compliance activities, including audit prep, evidence gathering and maintaining audit readiness

Key requirements

  • Some relevant experience in information security, compliance, risk, audit, governance, supplier assurance or related area
  • Strong organisational skills with accuracy and attention to detail
  • Good written and verbal communication skills
  • Proficient using documents and spreadsheets to maintain records and support reporting
  • Ability to manage several tasks, follow processes and meet deadlines
  • Willingness to learn and develop a career in information security GRC
  • strong organisational skills
  • clear written and verbal communication
  • attention to detail
  • information security governance
  • risk and compliance
  • supplier assurance

…

Posted: October 10th, 2026