Hiring.Camp

InfoSec Governance, Risk and Compliance Analyst

Leonardocompany

·

Today

Location
GB - Basildon, United Kingdom · GB - Edinburgh · GB - Yeovil - Lysander Rd · GB - Southampton · GB - Bristol - Coldharbour Lane · GB - Luton - Cap. Green 300 · GB - London · GB - Lincoln · GB - Newcastle
Workplace
Hybrid
Type
Full-time
Department
Legal
Clearance
Required
Source
Workday

Description

Job Description:

Your impact 

Leonardo UK operates in a complex security, regulatory and defence environment. As a Governance, Risk and Compliance Analyst, you will support the Information Security team in maintaining clear standards, assessing risk and providing assurance that security controls are understood, evidenced and reviewed across the business. The role will work across multiple business areas and may require travel between Leonardo UK sites, with hybrid working supported where appropriate. 

What you will do as Governance, Risk and Compliance Analyst: 

  • Support the Head of Governance, Risk and Compliance with the day-to-day information security governance, risk and compliance workload. 

  • Assist with maintaining security standards, control mappings and assurance processes. 

  • Support reviews of security management and assurance plans to help ensure controls are properly described, evidenced and aligned to the agreed standard. 

  • Conduct or support risk assessments where security controls are not implemented, including documenting the risk position and supporting appropriate review. 

  • Conduct audit and assurance activity across Leonardo UK systems and services. 

  • Help track non-compliances, remediation activity and risk acceptance decisions. 

  • Work with delivery teams, system owners and security specialists to gather evidence and support proportionate security governance. 

  • Contribute to compliance, risk and assurance reporting for the Information Security function. 

  • Support continual improvement of the Information Security Operating Model, including better use of data, tooling and automation. 

What you’ll bring 

You will bring experience or strong working knowledge of information security governance, risk and compliance. You should be comfortable working with security standards, control frameworks, risk records and assurance evidence in a regulated environment. 

Essential experience and skills: 

  • Experience in information security, cyber risk, compliance, assurance or audit. 

  • Knowledge of security control frameworks and risk management practices. 

  • Understanding of cyber and information risk frameworks and methodologies. 

  • Understanding of MoD and other UK government security policy and frameworks. 

  • Familiarity with security standards, policies, control frameworks or risk management artefacts. 

  • Practical understanding of risk assessment, residual risk, risk acceptance and non-compliance management. 

  • Experience supporting audits, assurance reviews, control testing or compliance reporting. 

  • Ability to review evidence and assess whether security controls are clearly described and appropriately supported. 

  • Experience working with technical and non-technical stakeholders to gather information and support risk or assurance activity. 

  • Professional security qualification such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or willingness to work towards one. 

  • Knowledge of governance tooling, dashboards, data analysis or automation would be beneficial. 

This is not an exhaustive list, and we are keen to hear from you even if you might not have experience in all the above. The most important skill is a good attitude and willingness to learn. 

 

Security Clearance 

This role is subject to pre-employment screening in line with the UK Government’s Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). For more information and guidance please visit: https://careers.uk.leonardo.com/gb/en/security-and-vetting 

Why join us 

At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work–life balance. Whether you're looking to grow professionally, care for your health, or plan for the future, we’re here to help you thrive. 

  • Time to Recharge: Enjoy generous leave with the opportunity to accrue up to 12 additional flexi-days each year. 

  • Secure your Future: Benefit from our award-winning pension scheme with up to 15% employer contribution. 

  • Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks championing inclusion and diversity (Enable, Pride, Equalise, Armed Forces, Carers, Wellbeing and Ethnicity).  

  • Rewarding Performance: All employees at management level and below are eligible for our bonus scheme. 

  • Never Stop Learning: Free access to 4,000+ online courses via Coursera and LinkedIn Learning. 

  • Refer a friend: Receive a financial reward through our referral programme. 

  • Tailored Perks: Spend up to £500 annually on flexible benefits including private healthcare, dental, family cover, tech & lifestyle discounts, gym memberships and more. 

  • Flexible working: Flexible hours with hybrid working options. For part time opportunities, please talk to us about what might be possible for this role. 

For a full list of our company benefits please visit our website. 

Leonardo UK operates a grade-based salary framework with broad bands. The salary range shown reflects the approved grade band for this role, or a narrower hiring range published within that band, and is benchmarked against the external market. Exceptions above the standard range are managed through governance controls to protect internal equity. 

Leonardo is a global leader in Aerospace, Defence, and Security. Headquartered in Italy, we employ over 53,000 people worldwide including 8,500 across 9 sites in the UK. Our employees are not just part of a team—they are key contributors to shaping innovation, advancing technology, and enhancing global safety.  

At Leonardo we are committed to building an inclusive, accessible, and welcoming workplace. We believe that a diverse workforce sparks creativity, drives innovation, and leads to better outcomes for our people and our customers. If you have any accessibility requirements to support you during the recruitment process, just let us know. 

Be part of something bigger - apply now! 

 

Primary Location:

GB - Basildon

Additional Locations:

GB - Bristol - Coldharbour Lane, GB - Edinburgh, GB - Lincoln, GB - London, GB - Luton - Cap. Green 300, GB - Newcastle, GB - Southampton, GB - Yeovil - Lysander Rd

Contract Type:

Permanent

Hybrid Working:

Hybrid

Skills

Risk ManagementComplianceISO 27001CISSP