Information Security Analyst - GRC & Operations
WHSmith North America
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
About the role
Information Security Analyst — GRC & Operations
Overview
Hybrid role combining security operations (Tier 1) with Governance, Risk, and Compliance (GRC) responsibilities. You will help secure systems and information assets while supporting continuous control assessment, compliance alignment, security training, and audit readiness.
What you’ll do
- Protect organizational systems and information assets using cybersecurity best practices.
- Partner with end users and department leaders to identify security needs and embed controls.
- Deploy/integrate/configure security solutions per standard operating procedures.
- Act as a Tier 1 responder for alerts: triage, contain, escalate, document, and investigate anomalous activity.
- Support vulnerability assessments and penetration testing, coordinating remediation.
- Administer periodic access reviews to enforce least privilege.
- Support global cybersecurity compliance aligned to NIST CSF, CIS Controls, ISO 27001, and PCI DSS.
- Perform continuous control assessments: document evidence, identify gaps, and report findings.
- Maintain GRC artifacts: risk register, control catalog, and supporting policies/standards/procedures.
- Assist with internal/external audits and third-party risk reviews and ongoing monitoring.
- Deliver cybersecurity training (new-hire onboarding, annual refreshers, role-based training) and run phishing simulations.
- Track security awareness metrics (completion rates, click/report rates, repeat offenders, behavioral trends) and coordinate remedial training with HR/IT/managers.
- Promote a culture of security awareness across the organization.
What you bring
- Education: BS in Cybersecurity or related field, or equivalent hands-on experience.
- Experience: 1–2 years in cybersecurity/IT/GRC, or strong academic background with relevant projects/lab work and/or certifications.
- Frameworks: foundational understanding of NIST CSF, CIS Controls, ISO 27001, and/or PCI DSS.
- Security operations: exposure to endpoint security/EDR and basic alert triage/escalation/incident documentation; willingness to learn Tier 1 workflows.
- Vulnerability & access: familiarity with vulnerability scanning concepts, remediation tracking, user access reviews, and least-privilege.
- Risk/policy/audit: awareness of risk management and policy concepts; interest in evidence collection and audit support.
- Security awareness training: interest in creating/delivering awareness content and tracking training/phishing metrics.
About WHSmith North America
WHSmith North America is part of WHSmith, a retail and distribution company known for selling products such as books, magazines, stationery, and travel-related items. The role focuses on protecting and operating their cyber infrastructure while driving Governance, Risk, and Compliance (GRC) activities across the organization.
Scraped 8/2/2026