Job Description
About us
The Cyber Risk and Compliance Analyst is responsible for identifying, assessing, and mitigating cyber security risks across the organization, ensuring compliance with relevant standards, frameworks, and regulations. This role will work closely with IT, security, legal, audit, and business teams to safeguard our digital assets and ensure ongoing regulatory compliance.
About the role
Risk Assessment & Analysis:
Conduct risk assessments of information systems, processes, and third-party vendors.
Analyze security threats, vulnerabilities, and internal/external risks.
Maintain and update risk registers and dashboards.
Compliance Management:
Monitor and ensure adherence to regulatory requirements (e.g., GDPR, ISO 27001, NIST, SOX).
Maintain documentation and evidence to support compliance audits.
Coordinate and support internal/external compliance assessments and audits.
Policy Development & Review:
Assist in developing, implementing, and updating security policies, standards, and procedures.
Ensure policies and processes reflect current regulations and best practices.
Incident Response:
Support incident management and investigation activities.
Document lessons learned and help implement corrective actions.
Awareness & Training:
Deliver security awareness training and communications to employees and stakeholders.
Reporting:
Produce regular and ad hoc risk and compliance reports for leadership.
Track remediation activities for identified risks and audit findings.
About you
Bachelor’s degree in Information Security, Computer Science, Information Systems, or related field (or equivalent experience).
Experience:
2+ years in cyber security, IT audit, risk management, or compliance roles.
Knowledge:
Familiarity with common security frameworks and regulations (such as ISO 27001, NIST, GDPR).
Understanding of risk assessment methodologies and compliance processes.
Skills:
Excellent analytical, problem-solving, and communication skills.
Strong attention to detail and organization.
Ability to work independently and as part of a team.
Certifications (desirable):
CompTIA Security+, CISA, CISM, or other relevant certifications.
Key Competencies
Strong ethics and integrity
High degree of initiative and accountability
Collaboration and stakeholder management
Adaptability in a fast-changing regulatory environment
Dyson is an equal opportunity employer. We know that great minds don’t think alike, and it takes all kinds of minds to make our technology so unique. We welcome applications from all backgrounds and employment decisions are made without regard to race, colour, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other any other dimension of diversity.