GRC Analyst – Digital & IT
// Role Summary
Join Rolls-Royce as a GRC Analyst in Derby, contributing to the protection of critical assets by managing cyber security governance, risk, and compliance activities.
// Key Responsibilities
- Manage cyber security governance, risk, and compliance across Rolls-Royce.
- Conduct risk assessments and identify threats, vulnerabilities, and control gaps.
- Embed regulatory and industry standards (e.g., NIST, ISO 27001, ITAR/EAR) into processes.
- Perform control testing and support audits for accreditation.
- Hybrid working model: 3 days in office, 2 days remote.
// Role Specification
GRC Analyst – Digital & IT
Rolls-Royce is seeking a Governance, Risk and Compliance (GRC) Analyst to join their central Cyber Security team in Derby. This role is crucial for managing cyber security governance, risk, and compliance activities, thereby supporting the protection of people, information, technology, and operations. You will have broad exposure across the organisation and the opportunity to enhance our cyber security control environment.
The Cyber Security team plays a vital role in helping the organisation understand and manage cyber security risks while ensuring compliance with relevant policies, standards, and regulatory requirements. Rolls-Royce values individuality, diverse perspectives, and experiences to drive innovation and high performance.
What You Will Be Doing:
- Review and triage newly logged risks, ensuring clear descriptions, accurate assessments, defined ownership, and actionable remediation plans.
- Conduct risk assessments across IT systems, engineering programmes, and operations to identify threats, vulnerabilities, and control gaps, recommending appropriate mitigations.
- Support structured reporting on risk posture, compliance status, audit outcomes, and remediation progress to facilitate informed decision-making.
- Maintain and update risk registers, ensuring alignment with enterprise frameworks and accurate tracking of ownership, impact, likelihood, and treatments.
- Embed regulatory and industry standards such as NIST, ISO 27001, ITAR/EAR, DFARS, Cyber Essentials Plus, and NIS2 into processes and controls in collaboration with Group teams.
- Perform control testing to assess design and effectiveness, identifying opportunities for improvement.
- Support audits and accreditation processes (e.g., RMF, ATO) through evidence coordination, control validation, and remediation tracking.
What We Offer:
- Excellent development opportunities.
- A competitive salary and exceptional benefits, including bonus, employee support assistance, and employee discounts.
- Hybrid working: A flexible arrangement balancing office and remote work (average of three days per week in the office).
Who We're Looking For:
- An IT, cyber security, or related degree, or equivalent professional experience.
- Experience in governance, risk, compliance, information security, cyber security assurance, or a related field.
- Understanding of cyber security risk management, security controls, and recognised frameworks/standards like ISO 27001 or NIST.
- Strong analytical, communication, and stakeholder management skills.
- Ideally, hold or be working towards a relevant professional qualification (e.g., CISSP, CISA, CRISC, ISO 27001 Lead Implementer/Auditor).
Rolls-Royce is committed to fostering a respectful, inclusive, and non-discriminatory workplace where individuality is valued and diverse perspectives drive innovation.