Back to jobs

GRC Analyst (Governance, Risk, Compliance & Security Standards)

Ireland

  • Permanent position available with a considerable portfolio of works for the next 5+ years
  • To build your career by assisting in the delivery of ‘leading edge’ engineering projects.
  • To work with a vibrant, agile and multi-functional team in delivering projects on time, safely, to budget and to the required quality standards.
  • To benefit from Kirby’s Career Development Programmes that will enhance your leadership capability.
  • To work with the best.
  • Excellent package on offer with room for negotiations

  
About Kirby Group Engineering
Kirby Group Engineering is an international multi-disciplinary engineering services contractor and leading provider of high-value engineering services to a number of ‘blue chip’ companies. Operating across Ireland, the UK, Europe and South Africa, Kirby has become the engineering service provider of choice in growth segments such as pharmaceuticals, data centres and power transmission and distribution. Our culture is innovative, collaborative and performance focused. The successful candidate will have the opportunity to grow and develop in a company committed to developing talent and rewarding performance.

Role Purpose

The GRC Analyst is responsible for establishing, operating, and continuously improving a structured Governance, Risk, and Compliance (GRC) capability across the business. Ensuring that risks, controls, policies, and compliance obligations are centrally managed visible, and consistently applied. Owning and managing data governance practices, ensuring that data classification, retention, and protection controls are consistently applied, maintained, and evidenced across the organisation with clear visibility for audit, compliance, and risk management purposes.

 

Key Responsibilities

  1. Governance & Policy Management
  • Maintain and continuously improve the organisation’s information security, governance, and compliance framework.
  • Ensure all policies, procedures, and standards are:
    • Up to date
    • Approved by the appropriate owners
    • Version controlled
    • Communicated and accessible
    • Aligned with ISO 27001 and relevant legal, regulatory, and contractual obligations
  • Support governance forums such as management reviews, steering groups, and risk/compliance meetings.
  • Ensure roles, responsibilities, and accountability for controls are clearly assigned across departments.
  • Support the development of governance mechanisms that provide leadership with visibility of compliance, control effectiveness, and key risks.

 

  1. Risk Management
  • Own and maintain the central risk register, including enterprise, operational, project, and technology-related risks.
  • Ensure risks are:
    • Identified consistently
    • Assessed using an agreed methodology
    • Assigned to named owners
    • Tracked through treatment, acceptance, or closure
  • Facilitate risk workshops and risk reviews with departments and key stakeholders.
  • Monitor risk treatment plans and escalate overdue or ineffective actions where required.
  • Ensure risks, incidents, audit findings, and control weaknesses are appropriately linked.
  • Support a structured and repeatable risk management approach across the organisation.

 

  1. Compliance & Regulatory Oversight
  • Monitor and support compliance with relevant obligations, including:
    • ISO 27001
    • GDPR
    • EU AI Act
    • Other applicable internal and external compliance requirements
  • Maintain evidence of compliance activities and ensure documentation is organised, current, and defensible.

 

 

 

  • Coordinate internal and external audit activities, including:
    • Evidence gathering
    • Stakeholder coordination
    • Tracking findings and corrective actions
    • Supporting closure and verification
  • Prepare compliance and assurance reporting for management.
  • Ensure compliance activities are embedded into day-to-day operations rather than treated as one-off exercises.

 

  1. Control Framework & Assurance
  • Maintain the organisation’s control framework, ensuring it is mapped to ISO 27001 Annex A and other applicable standards where required.
  • Ensure controls are:
    • Clearly defined
    • Allocated to accountable owners
    • Implemented in practice
    • Tested or reviewed periodically
    • Supported by evidence
  • Identify control gaps, inconsistencies, or weaknesses and drive remediation actions.
  • Support assurance reviews to determine whether controls are operating effectively.
  • Promote a continuous improvement approach to control maturity and evidence quality.

 

  1. Incident, Issue & Corrective Action Oversight
  • Ensure security, compliance, and operational incidents are:
    • Logged
    • Categorised
    • Investigated
    • Tracked to closure
  • Ensure issues and incidents are assessed for root cause, control impact, and recurring trends.
  • Link incidents and issues to risk treatment, control improvements, and lessons learned.
  • Monitor corrective actions arising from incidents, audits, or reviews to ensure completion and effectiveness.
  • Support reporting on incident trends, recurring weaknesses, and systemic issues.

 

  1. GRC Tooling, Reporting & Records Management
  • Support the implementation, administration, and continuous improvement of GRC tooling where approved.
  • Maintain key GRC records and repositories, including:
    • Risk registers
    • Control libraries
    • Audit findings logs
    • Compliance evidence repositories
    • Exception and acceptance records
  • Produce dashboards, reports, and management information for:
    • Leadership teams
    • Audit purposes
    • Risk and compliance monitoring
  • Ensure GRC data is accurate, current, traceable, and usable for audit and management decision-making.

 

  1. Data Governance, Retention & Protection
  • Ensure data classification, retention policies, and protection controls are:
    • Applied consistently across users, systems, and data types
    • Monitored for effectiveness and completeness
    • Maintained and updated in line with regulatory and business requirements

 

 

 

  • Maintain and oversee:
    • Data retention schedules
    • Data classification structures
    • Records management practices
  • Ensure data is:
    • Retained only as long as required
    • Protected appropriately based on classification
    • Disposed of in a controlled and auditable manner
  • Act as the governance owner for Purview outputs, including:
    • Compliance posture visibility
    • Retention and labelling coverage
    • Audit evidence for ISO 27001 and GDPR
  • Identify and escalate:
    • Gaps in data classification or retention coverage
    • Inconsistent application of policies
    • Risks relating to over-retention, uncontrolled data, or lack of audit traceability
  • Work with IT (where required) to:
    • Implement changes to existing policies
    • Improve coverage and consistency
    • Address findings from audits or risk reviews
  • Ensure all data governance activities are:
    • Documented
    • Traceable
    • Audit-ready

 

 

 

 

 

  1. AI & Emerging Risk Governance
  • Maintain AI inventories, risk exposure logs, and related governance records.
  • Support AI risk assessments, treatment planning, and governance decisions.
  • Monitor emerging obligations relating to AI, automation, digital platforms, and regulatory developments.
  • Ensure AI use cases, tools, and integrations are captured and reviewed in line with organisational governance requirements.
  • Support the development of practical processes for managing emerging technology risks in a controlled and auditable manner.

 

Key Skills & Experience

Essential

  • Experience in Governance, Risk, and Compliance (GRC), Information Security, or a related control/governance role.
  • Strong understanding of:
    • ISO 27001
    • Risk management methodologies
    • Compliance and assurance processes
    • Control frameworks and audit readiness
  • Experience maintaining risk registers, audit evidence, action trackers, and compliance records.
  • Experience developing, implementing, or maintaining standards, procedures, or control frameworks.
  • Ability to interpret frameworks and translate them into practical business and IT controls.
  • Strong documentation, organisation, and stakeholder coordination skills.
  • Ability to work across business and technical teams to drive accountability and follow-through.

 

 

  •  

Desirable

  • Exposure to:
    • NIS2
    • GDPR compliance processes
    • EU AI Act / AI governance
    • MS Purview
  • Experience with GRC tools or structured compliance/risk platforms.
  • Relevant certifications would be beneficial but are not mandatory, for example:
    • ISO 27001
    • Security+ or similar security/governance-related certification

 

Key Behaviours

  • Structured thinker – able to bring order, consistency, and traceability to fragmented processes.
  • Risk-based mindset – understands impact, exposure, and prioritisation, not just compliance wording.
  • Implementation-focused – able to move from policy and standards into actual operational execution.
  • Audit-ready mentality – ensures everything is evidenced, traceable, defensible, and ready for review.
  • Cross-functional communicator – able to work effectively with IT, HR, Legal, Operations, and leadership.
  • Pragmatic and detail-oriented – balances best practice with operational reality and follows through on actions.

For more information on this role, or other Construction / Engineering opportunities across Ireland, the UK, Europe, or South Africa please review our careers page (Vacancies - Kirby Group Careers) or contact the Talent Acquisition Team at Kirby Group in confidence on +353 (0)1 454 0411.

Kirby Group Engineering is an equal opportunities employer. We are committed to fostering an inclusive workplace and welcome applications from all suitably qualified candidates, regardless of race, gender, disability, religion, sexual orientation, or age.

 

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf