Cirrus Logic

Cirrus Logic

Midlothian, Scotland

Lead Information Security Analyst, GRC

Full-Time£49,000 - 80,000 per yearavant-hierUnited Kingdom
IT

Job Description

Salary: £49,000 - 80,000 per year

Requirements:
  • Proven experience in information security, with a strong focus on GRC, risk management, and/or security compliance in a global environment.
  • Bachelors degree in cybersecurity, information systems, or a related field, or demonstrated equivalent experience as a security professional in a globally dispersed enterprise.
  • Hands-on experience with ISO/IEC 27001, including the ISMS lifecycle, Annex A controls, risk assessment, and treatment, and related security control frameworks such as NIST CSF, ISO 27000, or TISAX.
  • Demonstrated experience with Integrated Risk Management, including project or solution risk assessments, and Third-Party Risk Management, including vendor due diligence, ongoing monitoring, and remediation.
  • Technical fluency across core IT and security domains, such as networks, endpoints, identity, cloud/SaaS, and logging/monitoring, and experience working with Security Engineering, Security Operations, and IT teams.
  • Experience configuring and maintaining an enterprise-grade GRC platform, preferably ServiceNow GRC, for risk, control, assessment, and exception workflows.
  • Strong analytical and problem-solving skills, with the ability to balance security, compliance, and business objectives practically.
  • Effective communication and interpersonal skills, including the ability to convey risk and technical issues clearly to technical and non-technical stakeholders, including senior leaders.
  • Ability to drive work independently, manage multiple concurrent initiatives, and follow through to completion in a fast-paced environment.
  • Experience in high-tech, engineering, or semiconductor environments is beneficial.
  • Relevant certifications, such as ISO 27001 Lead Implementer/Lead Auditor, CISSP, CISM, CISA, or CRISC, are preferred but not required.
  • You must live within a commutable distance of our Edinburgh office or be willing to relocate; the role requires at least two days onsite per week, with work-from-home flexibility depending on business needs.
  • Candidates must be able to access technical data without requiring an export license. We are unable to sponsor or obtain export licenses for this role.
Responsibilities:
  • Lead the day-to-day operation and continuous improvement of our ISO 27001-aligned Information Security Management System, including organization-wide policies, standards, and control procedures.
  • Develop, maintain, and communicate information security policies, standards, and guidelines; manage exceptions through risk-based, documented decisions and periodic reviews.
  • Lead security risk and control assessments for new systems, services, and business initiatives. Work with Security, IT, and business owners to identify threats, evaluate control design and effectiveness, and document and track risk treatment plans.
  • Assess AI/ML use cases, including internal builds and third-party services, for security, data protection, and misuse risks.
  • Plan and conduct third-party risk assessments for suppliers and service providers, reviewing security questionnaires, trust documents, and remediation plans.
  • Analyze risks across technologies and business processes, prioritize remediation based on business impact and likelihood, and prepare risk and control status reports for security leadership and stakeholders.
  • Configure, administer, and optimize GRC tools such as ServiceNow GRC or OneTrust GRC to support risk registers, control libraries, assessments, exceptions, and third-party workflows, including appropriate integrations with IT and security platforms.
  • Coordinate audits and assessments and provide evidence for internal and external audits, customer security assessments, and certifications, including ISO 27001 and SOC-related reviews.
  • Partner with Legal, HR, and other stakeholders to identify and manage security-related privacy and regulatory obligations, support privacy risk assessments and data protection controls, and assess the privacy and data protection implications of AI/ML solutions.
  • Define and maintain security and risk guardrails for AI/ML technologies, including acceptable-use guidelines, control requirements, and review processes for new AI use cases and vendors.
  • Advise team members and IT and business teams, translating security and risk requirements into practical solutions aligned with engineering and operational realities.
  • Partner with IT, engineering, and business teams to embed security, risk, and governance requirements into AI solution design and operations, collaborating with our globally dispersed team across time zones.
  • Communicate complex risk, control, compliance, and program matters clearly to technical teams, business stakeholders, and executive leadership; develop executive-ready presentations, briefings, and status updates that support informed decision-making.
  • Support GRC awareness, communications, and training initiatives, including targeted awareness on the secure and responsible use of authorized AI tools.
Technologies:
  • AI
  • Cloud
  • Support
  • Security
  • ServiceNow
  • Agentic AI
  • Network

More:

We are Cirrus Logic, a company with more than four decades of experience in mixed-signal processing, working with leading consumer brands. Our engineering team tackles complex challenges, and our culture emphasizes inclusion, fairness, community engagement, and positive employee experiences. We are seeking a Lead Information Security Analyst – Governance, Risk Management, & Compliance to join our Information Security team and support our business strategy in a dynamic, engineering-driven environment. The role is based in our Edinburgh office and is hybrid, with a minimum of two days onsite per week and flexibility to work from home depending on business needs. We value diversity and aim to foster an open, collaborative workplace where different perspectives are respected and valued.

last updated 39 week of 2026

Interested in this role?

Submit your application now

How to Apply

Ready to apply for this position? Here's what you need:

  • An updated resume highlighting relevant experience
  • A compelling cover letter (if required)
  • Portfolio or work samples (for relevant positions)

About Cirrus Logic

Cirrus Logic

Cirrus Logic

Midlothian

IT

Skills & Technologies

GoRustRailsAIUI

Inferred from job description

Salary Insight

£64,500

This role

£85,000

UK median

This salary is 24% below the UK median for Lead roles (£85,000/yr).

Based on 2024–2025 UK technology sector benchmarks

Explore More UK Opportunities

Thousands of tech jobs across the United Kingdom