Cyber Governance Analyst
About this role
As a CPaaS leader with 25 years of groundbreaking experience, we're the force behind over 7 billion customer interactions each year, enabling businesses worldwide to connect via advanced channels like SMS, RCS, and complex mobile journeys.Our culture is our core strength. Operating across the UK, EMEA, the USA, and Australia, we've fostered a truly diverse and connected environment, earning a consistent 4 out of 5 culture score in our employee engagement surveys. You'll join a vibrant team where your diverse experience makes a daily global impact.We need talented people to grow a global company where everyone feels proud to belong, have a purpose and do their best to directly shape the digital future.We are looking for a Security Governance Analyst with around 1 year of hands-on experience in information security, risk, or compliance to join our Cyber Security team. Working directly alongside our Cyber Security Manager, you will act as the operational driver of our Information Security Management System (ISMS) across more than 20 active global frameworks. If you already have the fundamentals down and are looking for a role that offers serious breadth, high visibility, and clear career progression, this is your opportunity. What You’ll Be DoingEvidence & Audit Management: Sourcing, evaluating, and maintaining audit-ready technical evidence for frameworks like ISO 27001, PCI DSS, SOC 2, HIPAA, and Cyber Essentials. Risk Ownership: Driving our technology risk action plans (~140+ items), proactively chasing technical teams, and escalating stalled risks to management. Control Testing: Planning and executing routine testing across assigned frameworks to ensure internal teams comply with security standards. Common Controls Framework (SCF): Mapping control evidence to the SCF to standardise responses and streamline audit workloads across multiple frameworks. Security Culture & Awareness: Coordinating global security awareness training, managing phishing campaigns, and tracking completion rates across all territories. Policy Rollout: Overseeing the distribution, communication, and acknowledgement tracking of updated IS policies. What We’re Looking ForExperience: Circa 1 year of experience working in an information security, compliance, GRC, or IT auditing environment. Framework Exposure: Familiarity with at least one major compliance standard (such as ISO 27001, Cyber Essentials, PCI DSS, or SOC 2). Strong Organisational & Stakeholder Skills: Proven ability to manage multiple priorities, track action plans, and confidently challenge technical colleagues for updates. Methodical Mindset: Sharp attention to detail with strong written skills for maintaining audit-proof documentation.
What this role is, and what else it is called
Employers in Nottingham advertise this kind of work as IT Cyber Security Engineer 304336, Senior Cyber Security Engineer and Graduate Cyber Governance Analyst too, so it is worth searching more than one wording. It is a mid-level Cybersecurity role in Nottingham, advertised as hybrid, splitting time between home and the office.
About hiring at Commify
Commify has 3 other live technology roles on its careers page, across Software Engineering and Cybersecurity. Of those, 0% are advertised as fully remote and 75% as hybrid. Where Commify states a salary, the median advertised ceiling is £30,011 across 4 roles. Elsewhere in its adverts Commify asks for C#, Angular, Azure, SQL and JavaScript. See all Commify roles, salaries and stack.
How this role compares to the market
Nottingham has 48 live IT vacancies across 24 employers, with a median advertised salary of £35,000. Browse Nottingham roles.
Market figures are today's snapshot of live UK roles on employer careers pages; see hiring trends.
Detected on Commify's careers page. ProdReady Recruitment lists this vacancy as an aggregator and is not the employer; applications go to the employer's own site. More IT jobs in East Midlands.