GRC Analyst
Shirebrook - UK
Job Summary
The Role:
We are seeking a Technology GRC Analyst to support the continued development of Frasers Groups technology risk and assurance capability.
In this role you will identify assess and monitor technology and cyber risks while providing assurance that key IT and business controls are designed and operating effectively. Working closely with Technology Cyber Security Internal Audit Finance Supply Chain and business stakeholders you will help strengthen governance improve operational resilience and ensure risks are managed in line with industry standards and regulatory requirements.
You will play an important role in delivering technology risk assessments controls testing identity and access assurance third-party governance and supply chain assurance activities across the Group helping to embed a proactive risk culture that supports Frasers Groups continued growth.
Key Responsibilities:
- Deliver technology and cyber risk assessments across enterprise infrastructure cloud platforms retail systems digital applications and strategic technology initiatives.
- Perform controls testing across IT General Controls (ITGCs) automated application controls and key operational processes to provide assurance over the effectiveness of the Groups control environment.
- Conduct Identity and Access Management (IAM) assurance activities including user access reviews privileged access audits Joiner-Mover-Leaver (JML) controls and Segregation of Duties (SoD) assessments.
- Support identity audits to ensure access to business-critical systems remains appropriate compliant and aligned with security policies.
- Maintain the Technology Risk Register ensuring risks remediation actions and control improvements are accurately tracked and reported.
- Perform supplier and third-party technology risk assessments supporting ongoing assurance over strategic technology partners and service providers.
- Support Supply Chain Assurance by assessing technology and operational risks across logistics warehousing distribution centres and supplier ecosystems.
- Partner with Internal Audit Internal Controls and Cyber Security teams to coordinate audits evidence gathering and remediation activities.
- Produce meaningful risk dashboards management information Key Risk Indicators (KRIs) and governance reporting for senior leadership and risk forums.
- Collaborate with Technology Retail Operations Finance Procurement Legal and Supply Chain teams to embed effective risk management and assurance practices across the business.
- Support the ongoing development of the Technology Risk Management Framework aligned with recognised standards including NIST Cybersecurity Framework ISO 27001 and industry best practice.
- Drive continuous improvement of governance risk and compliance (GRC) processes reporting automation and assurance activities.
- Support regulatory internal and external audit requirements such as PCI -DSS ensuring documentation and evidence are maintained to a high standard.
Qualifications :
What we are looking for:
- 2 years experience within Technology Risk IT Audit Governance Risk & Compliance (GRC) Internal Controls or Cyber Risk.
- Experience delivering technology risk assessments and controls testing across enterprise technology environments.
- Strong understanding of IT General Controls (ITGCs) technology governance and operational risk management.
- Experience conducting Identity and Access Management (IAM) reviews user access certifications and privileged access assurance.
- Knowledge of third-party risk management supplier assurance and technology risk across complex supply chain environments.
- Experience supporting internal and external audits including evidence management and remediation tracking.
- Strong analytical and problem-solving skills with the ability to identify control weaknesses and recommend practical improvements.
- Excellent communication and stakeholder management skills with the ability to engage technical and non-technical audiences.
- Experience working with Governance Risk & Compliance (GRC) platforms such as OneTurst
- Passionate about strengthening governance improving controls and enabling secure business growth across a complex global retail organisation.
Desirable:
- Professional certifications such as CRISC CISA CISM CISSP or equivalent.
- Experience working within large retail e-commerce or multinational organisations.
- Knowledge of NIST Cybersecurity Framework ISO 27001 COBIT and ITIL.
- Experience with data analytics continuous controls monitoring or assurance automation.
- Familiarity with PCI DSS SOX or other regulatory and compliance frameworks.
Additional Information :
Along with your benefits package we also offer a wide range of perks for our colleagues:
Frasers Champion - Our employees are at the heart of our business and we ensure individuals are recognised every single month for their hard work. Frasers Champion is a peer nominated scheme where 8 winners will receive double their pay for a month where they have lived the Frasers Group values.
Retail Reconnect - In order to build the planets most admired and compelling brand ecosystem all employees must understand our business product and customers. Each financial year head office employees will gain insights by spending one to two days in one of our stores or the warehouse. The goal is to learn how the work you do impacts our teams on the frontline and to bring ideas back to the office which will improve how we work.
Fearless 1200 - Fearless 1200 is our way of recognising our growth. Its bold ambitious and designed to reward colleagues across the business for living our values and delivering impact. Fearless 1200 links how we perform to how were rewarded check out the video link to find out more - Welfare
Frasers Fit - Our Everlast Gyms Team are on a mission to make our workforce the best and fittest on the planet! We run free gym classes for employees as well as discounted memberships to our clubs. Frasers Fit is our wellbeing programme which aims to support and improve colleagues Physical Financial & Mental wellbeing. The app is accessible for every employee and includes training nutrition and lifestyle advice- all completely free.
Retail Trust - We know that its not just about physical health mental wellness is equally important which is why all of our employees get free access and support from the Retail Trust charity. This includes a 24 hour wellbeing helpline wellness hub counselling and financial/legal support.
Whats next
Our Recruitment Team will be reviewing applications and all candidates will receive a response whether you are successful or unsuccessful. Shortlisted applicants may be asked to confirm a few key details before being booked in for a first stage interview with the Recruiter - this will be behaviourally focussed and centred around how you align with our Culture and Values. If successful we anticipate one or two further interview stages with the Hiring Manager/wider team which will be more technically focussed and could include a presentation/task so we can see your skills in action.
Remote Work :
No
Employment Type :
Full-time
About Company
SportsDirect patriaci do Frasers Group sa z malého anglického obchodu so športovými potrebami rozrástol na celosvetový reťazec maloobchodných predajní s bohatou ponukou športového a luxusného módneho tovaru rôznych značiek. Riadime sa pravidlom Risk je zisk. Snažíme sa neustále napred ... View more