Job Search and Career Advice Platform

Enable job alerts via email!

Cyber GRC / Configuration Management Analyst

Sword group

City of Edinburgh

On-site

GBP 30,000 - 40,000

Full time

30+ days ago

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading IT consulting firm in the United Kingdom is seeking an entry-level Cyber GRC / Configuration Management Analyst. The role involves developing and documenting a Configuration Management Plan aligned with NIST standards, analyzing compliance reports, and collaborating with teams for effective rollout. Ideal candidates will have experience in cyber security standards and strong writing skills. This full-time position offers a competitive salary and various benefits aimed at professional growth and work-life balance.

Benefits

Personalised Career Development
Flexible working
Generous annual leave allowance
Enhanced family-friendly benefits
Access to private health and well-being schemes

Qualifications

  • Experience writing cyber security policies and procedures.
  • Ideally experience with a Configuration Management Plan.
  • Ability to understand process flows and RACIs.

Responsibilities

  • Develop and document a Configuration Management Plan.
  • Rollout the Configuration Management Plan and assign responsibilities.
  • Gather and analyse Configuration Compliance reports.

Skills

Experience with Cyber Security standards such as ISO27001
Knowledge of Secure Configuration and Cyber Security Policy
Strong documentation writing skills
Ability to distil complex security concepts into simple language
Collaborate with Comms teams for rollout
Job description
Cyber GRC / Configuration Management Analyst

Join to apply for the Cyber GRC / Configuration Management Analyst role at Sword Group

About the role:

Develop and document a comprehensive Configuration Management Plan that aligns with the guidelines and recommendations set in NIST SP 800-128. This plan will serve as a critical framework to ensure that all configuration items are effectively managed and monitored, thus supporting the overall integrity and security of the information systems.

In addition to the core elements of the plan, it is essential to clearly define and document the roles and responsibilities associated with the 2nd Line of Defense within the Configuration Management Plan. This will facilitate accountability and streamline processes, ensuring that all stakeholders understand their specific duties and contributions to the success of the configuration management efforts.

Once the Configuration Management Plan is developed, a thorough rollout process will be initiated. This will involve communicating the details of the plan to all relevant personnel and stakeholders, as well as assigning specific responsibilities to ensure its effective implementation.

Here\'s what the role looks like:

  • Develop and document a Configuration Management Plan in alignment with NIST SP 800-128
  • Document the 2nd Line of Defence roles and responsibilities in the Configuration Management Plan
  • Rollout of the Configuration Management Plan, including communicating and assigning responsibilities
  • Document Secure Configuration Policy Level Statements to define overarching secure configuration principles, including review then communicate it
  • Document all the Configuration Compliance tooling which currently exists
  • Gather Configuration Compliance reports from monitoring tools
  • Analyse the reported deviations and escalate where necessary to drive the deviation resolution
  • Define an Approved Software List for RedHat Linux
  • Update the change management process and include input into the Change Advisory Board (CAB)
  • Communicate the updates to change management teams
  • Update the project assurance process

Requirements

  • Experience with Cyber Security standards such as ISO27001, or NIST 800-53
  • Knowledge of Secure Configuration and Cyber Security Policy
  • Experience writing cyber security policies and procedures
  • Ideally experience with a Configuration Management Plan
  • Strong documentation writing skills
  • Ability to understand process flows and RACIs
  • Ability to distil complex security concepts in to simple language that can be understood by business users
  • Ability to summarise secure configuration requirements into a few principles
  • Collaborate with Comms teams and Business Change teams to rollout new processes and procedures

Benefits

At Sword, our core values and culture are based on caring about our people, investing in training and career development and building inclusive teams where we are all encouraged to contribute to achieve success. We offer comprehensive benefits designed to support your professional development and enhance your overall quality of life. In addition to a Competitive Salary, here\'s what you can expect as part of our benefits package:

Personalised Career Development: We create a development plan customised to your goals and aspirations, with a range of learning and development opportunities within a culture that encourages growth.

Flexible working: Flexible work arrangements to support your work-life balance. We can\'t promise to always be able to meet every request, however are keen to discuss your individual preferences to make it work where we can.

A Fantastic Benefits Package: This includes generous annual leave allowance, enhanced family friendly benefits, pension scheme, access to private health, well-being, and insurance schemes, an employee assistance programme, discounted cash plan and more.....

At Sword we are dedicated to fostering a diverse and inclusive workplace and are proud to be an equal opportunities employer, ensuring that all applicants receive fair and equal consideration for employment, regardless of whether they meet every requirement. If you don\'t tick all the boxes but feel you have some of the relevant skills and experience we\'re looking for, please do consider applying and highlight your transferable skills and experience. We embrace diversity in all its forms, valuing individuals regardless of age, disability, gender identity or reassignment, marital or civil partner status, pregnancy or maternity status, race, colour, nationality, ethnic or national origin, religion or belief, sex or sexual orientation. Your perspective and potential are important to us.

If we can do anything to help make the hiring process more accessible, please let our talent acquisition team know when you apply so we can support any adjustments.

Seniority level
  • Entry level
Employment type
  • Full-time
Job function
  • Other
  • Industries
  • IT Services and IT Consulting

Referrals increase your chances of interviewing at Sword Group by 2x

Sign in to set job alerts for “Configuration Management Analyst” roles.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.