Clue
Security GRC Analyst
Bristol, GB · Posted 3h ago
Job Description
Role specifics
Salary range: £60,000 – 70,000
Reporting to: Chief Information Officer
Key stakeholders: Platform and Development, Product, Sales and Onboarding, IT Operations, Legal Counsel and DPO, People team, our managed security operations provider, customer security and assurance teams
Organisational Framework Level: Level 3 – Professional Specialist
Eligible to obtain UK security clearance (SC). UK-based.
Minimum requirement of 2 days per week in our Bristol office
About you/ Job Summary
As a Security Governance, Risk and Compliance Analyst, you keep our information security management system current, evidenced and moving. Clue supplies software to UK public sector, Sports and law enforcement, and those customers expect us to show, not just say, that our controls work. You will administer our ISO 27001 ISMS day to day, maintain the risk register, lead customer security assurance, run the supplier assessment cycle and coordinate the record-keeping and communications when an incident occurs. The CISO leads the security function, sets direction, and holds accountability; the Security Engineering team and IT own the technical controls. Your job is to do the work between them intelligently: know where every piece of evidence lives, what we have promised each customer, what is due next, and who needs chasing.
At Clue we are actively adopting AI to improve our products and workflows. You will bring curiosity and a willingness to use AI tools to work faster and more accurately, while knowing where they should not be trusted.
Key Accountabilities
ISMS and certification
• Administer the information security policy, set: review schedule, publication and acknowledgement records, with the CISO approving changes.
• Maintain ISO 27001:2022 certification: statement of applicability, evidence library, internal audit scheduling and external audit coordination.
• Work with IT to maintain security accreditations such as Cyber Essentials Plus and our ISO accreditations, plus the evidence set for the NCSC Cyber Assessment Framework where customers require it.
• Maintain the security exceptions register, tracking time-limited approvals and named risk sponsors.
• Pen-test and crisis simulation exercise management and coordination, alongside the CISO.
Risk management
• Maintain the risk register and apply the scoring model set by the CISO. Keep entries current, sponsored and treated.
• Prepare and coordinate the monthly risk register review with executive risk sponsors, and track treatment plans to closure.
• Draft register entries from audit findings, incident lessons, threat assessments and customer requirements, for CISO review, each with a proposed owner.
• Maintain the list of security-related product roadmap requests and coordinate prioritisation between the CISO and Product.
Customer assurance and contractual compliance
• Lead customer security assurance: draft questionnaire responses, assemble evidence packs and handle due diligence requests, drawing technical input from the DevSecOps Engineer and IT Operations.
• Maintain the single record of every security commitment made to a customer.
• Carry out compliance checks of customer environments before go-live and report the results to the CISO for sign-off.
• Track our obligations under CCS framework security schedules and G-Cloud 15 Call-Off Schedule 9A, and maintain the evidence for each.
• Produce customer-facing assurance reporting, including the monthly vulnerability report within five working days of month end.
Security operations governance
• Coordinate the day-to-day relationship with our managed security operations provider: track service levels, prepare monthly service reviews and maintain the detection improvement backlog.
• Track vulnerability remediation against contractual windows, record exceptions and report performance.
• Maintain the protective monitoring standard and the logging and monitoring evidence an assurance review will test.
• Keep a record of threat intelligence intake from NCSC and other sources, and of the actions taken.
Incident management
• Act as incident coordinator: convene the response channel, keep the record, apply the severity matrix and escalation path without discretion, and track actions to closure. The CISO chairs incidents and coordinates Clue response.
• Prepare and track customer and regulatory notifications, including any contractual out of hours customer notification and the UK GDPR 72-hour ICO window, with Legal and the DPO.
• Maintain the incident register, organise post-incident reviews and track corrective actions.
• Maintain the annualcrisis exercise plan and organise the exercises.
Third-party risk management
• Operate the supplier assurance process and platform: onboard, tier and reassess suppliers on a risk-based cycle.
• Keep a named executive sponsor recorded for each material supplier and chase their review obligations.
People, access and awareness
• Draft security awareness and training requirements and assure delivery with the People team.
• Support the People Director with the vetting policy and collect the evidence that personnel security controls operate.
• Collect and check access governance evidence: review schedules, privileged access records and joiner, mover and leaver records.
• Support the Security Champions network with process guidance.
Governance and reporting
• Organise the governance cadence: weekly security governance, fortnightly Security Steering Group, monthly risk review and quarterly Information Security Management Forum. Agendas, papers, minutes and actions.
• Draft sponsor and board-level reporting for the CISO, sourced and consistent across documents.
• Track every security action to a named owner and a date, and report status without spin.
Key role measures
ISO 27001 certification maintained with no major nonconformities; audit findings closed within agreed date
Risk register currency: every entry reviewed within its cycle, sponsored, and with a live treatment plan
Customer assurance turnaround: questionnaires and evidence requests answered within agreed SLAs with no unsupported commitments
Vulnerability remediation reported accurately against contractual windows, with exceptions recorded
Incident notifications made within contractual and regulatory windows; post-incident actions closed
Supplier coverage: all material suppliers tiered, assessed and sponsored
Experience and skills
Our ideal candidate would have experience in the following areas:
Information security management
Working within an ISO 27001 ISMS through certification or surveillance audits, ideally in a SaaS organisation.
Maintaining a risk register and working with senior risk owners to keep entries current and treated.
Keeping exceptions, policies and evidence to an audit-ready standard.
Customer and public sector assurance
Responding to customer security questionnaires and due diligence, ideally for UK public sector customers.
Working knowledge of CCS framework security schedules, G-Cloud Schedule 9A, Cyber Essentials Plus and the NCSC Cyber Assessment Framework.
Good understanding of data protection and UK GDPR, including Articles 28 and 33.
Supplier and service governance
Tracking a managed service or supplier against contract and service levels and preparing service reviews.
Third-party risk management, including experience of a TPRM platform (desirable).
• Incident management
Coordinating security incidents, keeping records and preparing customer or regulatory notifications.
Technical literacy
Enough understanding of cloud, SIEM and vulnerability management to read a service report or scan output and ask the right questions. You will not be writing detection rules.
Communication and ways of working
Clear, precise written English. Your reports and evidence will be read by customers, auditors and executives.
Organised and self-directed, able to keep several governance cycles moving in parallel and chase others to dates politely and persistently.
Qualifications
ISO 27001 Lead Implementer or Lead Auditor, CISM, CRISC, CISMP or equivalent (desirable).
Diversity, Equity and InclusionIf you’re excited about this role but your experience doesn’t align perfectly, we encourage you to apply anyway and tell us more about yourself. You may be just the right candidate for this or other roles.
We believe that seeing the world from all sorts of angles makes life better for all. We want you to know that the things that make you an individual, like your identity, age, ethnicity, religion, ability and background, are things that we choose to celebrate and support.
We are a scale-up company, and as we continue to grow, we are passionate that having a diverse, inclusive and authentic workplace will remain at our core. We are creating an inclusive environment where our people can thrive.
Our values are aligned and at the heart of everything we do. We are respectful, united, rigorous, relentless and ethical.