Shape the Future of AIJoin one of the UK's fastest-growing companies and become a Professional Development Expert in Artificial Intelligence.

View Roles

IT Risk & Policy Analyst

Leatherhead
4 days ago
Create job alert

IT Risk, Policy & Training Analyst - Leatherhead (2-3 days per week) - £35,000 per annum base + benefits**

The IT Risk, Policy & Training Analyst is responsible for managing IT risks, monitoring audit actions, maintaining IT policies and procedures, and supporting GDPR compliance. The role ensures effective governance and compliance across IT processes, providing a framework for the identification, mitigation, and management of risks.

This position bridges technical and governance aspects, ensuring alignment with company standards and regulatory requirements, while fostering collaboration across teams to embed robust IT practices:

Ensuring that all IT risk and IT audit actions are highlighted, monitored, and escalated where appropriate.
Maintaining the suite of IT policies and procedures.
Providing support to the Privacy Team in ensuring GDPR compliance.Main accountabilities:

Assisting in managing IT Risk Register inputs and outcomes, liaising with IT SLT & Group Assurance and external auditors as appropriate.
Liaising with other teams to ensure SLAs in scope are met.
Identifying policy/procedure gaps and working with SMEs to create the material.
Managing review process for existing IT policies and procedures, updating, or archiving as required
Building strong relationships in IT & across the business to facilitate the adoption of agreed IT policies and procedures.
Assisting with tracking the annual DR testing programme.
Assisting the Privacy Team in ensuring DPIAs are completed where required.Required skills and experience:

Some experience of working in an IT function or in an audit/governance role
Knowledge of IT risk management and IT governance, risk, and compliance (GRC) would be an advantage but not essential.
Understanding of cybersecurity risks and controls would be an advantage but not essential.
Understanding of GDPR requirements would be an advantage but not essential.
Experienced Microsoft Office user (Word, Excel and PowerPoint)Qualifications

ITIL trained would be an advantage but not essential.
IT risk management or cybersecurity certification would be an advantage, otherwise a desire to work towards achieving formal qualification.Skills

Excellent oral and written communication skills, with high attention to detail
Ability to produce high quality, detailed outputs.
Good analytical skills
Highly organised and able to implement and manage robust governance processes.
Strong relationship building and interpersonal skills across a wide range of stakeholders.

Damia Group Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept our Data Protection Policy which can be found on our website.

Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and ability to perform the duties of the job.

Damia Group is acting as an Employment Business in relation to this vacancy and in accordance to Conduct Regulations 2003

Related Jobs

View all jobs

Cyber Policy & Compliance Analyst

Cyber Risk Assessment Analyst

Senior Cyber Security Analyst

Senior Cyber Security Analyst

Information Security Analyst

Information Security Analyst

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Automate Your Cyber Security Jobs Search: Using ChatGPT, RSS & Alerts to Save Hours Each Week

Cyber roles drop across consultancies, MSSPs, hyperscalers, banks, gov & start-ups every day—often buried in ATS portals or duplicated across boards. The fix is simple: put discovery on autopilot with keyword-rich alerts, RSS feeds & a reusable ChatGPT workflow that triages listings, ranks fit, & tailors your CV in minutes. This copy-paste playbook is built for www.cybersecurityjobs.tech readers. It’s UK-centric, practical, & designed to save you hours each week. What You’ll Have Working In 30 Minutes A role & keyword map spanning SecOps/Detection, DFIR, AppSec, Cloud Security, GRC, Red Team, Threat Intel, IAM/PAM, OT/ICS & Vulnerability Management. Shareable Boolean search strings for Google & job boards to cut noise fast. Always-on alerts & RSS feeds delivering fresh roles to your inbox/reader. A ChatGPT “Cyber Job Scout” prompt that deduplicates, scores fit & outputs tailored actions. A simple pipeline tracker so deadlines & follow-ups never slip.

10 Cyber Security Recruitment Agencies in the UK You Should Know (2025 Job‑Seeker Guide)

UK cyber security hiring remains resilient in 2025, driven by nation-state threats, cloud security investments, and NCSC regulatory pressures. Lightcast reports +42 % YoY growth in UK roles mentioning “SOC”, “cyber risk”, “offensive security” or “GRC”. Yet despite 30,000 active cyber professionals, monthly live vacancies remain in the 2,500–2,900 range. The result: strong demand across public and private sector. We reviewed 50 + consultancies and included only those that: Are registered in the UK (Companies House) Operate a dedicated Cyber Security / InfoSec / Risk & Compliance desk Posted at least 5 UK cyber security roles between March and June 2025 This guide includes 2025 salary ranges, key skills, interview prep tips, and a verified recruiter directory.

Cyber Security Jobs Skills Radar 2026: Emerging Frameworks, Tools & Certifications to Learn Now

Cyber threats are evolving—and so must the people defending against them. As ransomware, AI-enhanced phishing, and supply chain attacks grow more advanced, UK employers are urgently hiring cyber security professionals with the right mix of strategic and hands-on skills. Welcome to the Cyber Security Jobs Skills Radar 2026, your go-to guide for the most in-demand tools, frameworks, certifications, and technologies shaping the UK's cyber workforce. Whether you're a SOC analyst, penetration tester, or cloud security architect, this annual radar is designed to help you stay ahead of the market.