Source description
About the role
Description Job Purpose The GRC Analyst is responsible for managing and responding to client-initiated information security due diligence requests, including vendor security questionnaires (VSQs), request for proposal (RFP) security schedules, and ESG-related assessments. Operating as part of the Information Security function and reporting directly to the Information Security Manager, the post-holder serves as a point of coordination between Greshams security, legal, and commercial teams and its clients procurement and risk functions. As a financial services technology provider operating in highly regulated environments, Greshams clients subject the business to rigorous third-party risk assessments covering data security, operational resilience, access controls, and increasingly, ESG and sustainability criteria. The GRC Analyst ensures these assessments are completed accurately, consistently, and within agreed timescales, thereby directly supporting client acquisition, retention, and the organisations broader information security governance framework. Key Responsibilities - Manage and respond to client information security due diligence questionnaires (DDQs), vendor security questionnaires (VSQs), and RFP security schedules in an accurate, timely, and consistent manner, maintaining a central response library to improve efficiency and quality over time. - Maintain and continuously improve Greshams GRC evidence repository, ensuring that supporting documentation including policies, certifications, audit reports, and control evidence is current, accessible, and appropriately version-controlled to support both reactive client requests and proactive assurance activities. - Coordinate responses to client and prospect ESG assessments, working cross-functionally with People & Culture, Facilities, Legal, and Finance to collate accurate data across environmental, social, and governance dimensions, and ensuring outputs are consistent with Greshams broader sustainab .
More at Gresham