Analyst, Information Security GRC

Company: Fitch Ratings
Apply for the Analyst, Information Security GRC
Location: Manchester
Job Description:

Overview

In this role you support Fitchs global cyber security awareness program, helping employees understand cyber risks and adopt secure habits. You will collaborate with Information Security, Communications, HR, and business teams to translate complex topics into practical guidance. You’ll manage campaigns, training, phishing simulations, and program metrics to drive a security-aware culture. This is an opportunity to blend awareness, learning, and risk management in a global financial services context.

Pay / Benefits

  • Hybrid work arrangement
  • Dedicated training and mentorship programs
  • Retirement planning and tuition reimbursement
  • Comprehensive healthcare offerings
  • Parental leave policies
  • Volunteer days and charitable giving programs

Responsibilities

  • Plan and deliver cyber security awareness campaigns (e.g., Cyber Security Awareness Month)
  • Create and disseminate awareness communications (newsletters, articles, emails, intranet posts, manager updates)
  • Translate technical topics into clear, employee-friendly messaging
  • Manage security awareness training lifecycle (content updates, testing, launch, reminders, evidence)
  • Coordinate targeted, role-based, regional, and regulatory training activities
  • Support phishing simulation campaigns (prep, testing, audience coordination, reporting, follow-up)
  • Compile and maintain program metrics (training completion, engagement, phishing outcomes, dashboards)
  • Prepare leadership updates, meeting materials, and program reports
  • Maintain organized records of approvals, communications, and process documentation
  • Coordinate with cross-functional stakeholders across Information Security, Technology, Communications, HR, L&D, Facilities
  • Assist with virtual and in-person awareness events (speaker coordination, materials, follow-up)

Key requirements

  • Experience in cyber security awareness, human risk, training, communications, or employee education
  • Strong written communication to simplify complex topics
  • Good attention to detail and ability to manage multiple tasks and stakeholders
  • Strong organizational skills and record-keeping
  • Collaborative work style across technical and non-technical teams
  • Proficiency with Microsoft Office (Word, PowerPoint, Excel, Outlook, Teams, SharePoint)
  • Willingness to learn about phishing, data protection, IAM, secure practices, AI risks, and emerging threats
  • Ability to handle sensitive information with confidentiality
  • Proactive, curious, improvement-focused mindset
  • Excellent written communication
  • Attention to detail
  • Organizational skills
  • Microsoft Office tools (Word, PowerPoint, Excel, Outlook, Teams, SharePoint)
  • Phishing simulations understanding
  • Security training platforms (preferred)

Posted: September 15th, 2026