Back to jobs

Cyber Security Governance Analyst | Ireland

Ireland

  • Permanent position available with a considerable portfolio of works for the next 5+ years
  • To build your career by assisting in the delivery of ‘leading edge’ engineering projects.
  • To work with a vibrant, agile and multi-functional team in delivering projects on time, safely, to budget and to the required quality standards.
  • To benefit from Kirby’s Career Development Programmes that will enhance your leadership capability.
  • To work with the best.
  • Excellent package on offer with room for negotiations

  
About Kirby Group Engineering
Kirby Group Engineering is an international multi-disciplinary engineering services contractor and leading provider of high-value engineering services to a number of ‘blue chip’ companies. Operating across Ireland, the UK, Europe and South Africa, Kirby has become the engineering service provider of choice in growth segments such as pharmaceuticals, data centres and power transmission and distribution. Our culture is innovative, collaborative and performance focused. The successful candidate will have the opportunity to grow and develop in a company committed to developing talent and rewarding performance.

ROLE PURPOSE

 

Support and continually improve the organisation's cyber security governance, ISMS and AI governance arrangements, ensuring risks and controls are consistently managed, evidenced and audit ready.

 

KEY TASKS, ACTIVITIES, RESPONSIBILITIES & ACCOUNTABILITIES

 

  1. Cyber Security Governance (GRC)
  • Maintain the cyber security governance, risk and compliance framework. 
  • Own and maintain risk registers, control libraries, compliance records and corrective-action trackers. 
  • Monitor compliance with ISO 27001, GDPR and other applicable legal, regulatory and contractual requirements. 
  • Coordinate internal and external audits, evidence gathering, findings and remediation actions. 
  • Monitor control effectiveness, identify gaps and escalate overdue or ineffective actions. 
  • Provide clear risk, compliance and assurance reporting to management. 

 

  1. ISMS Management
  • Maintain and continually improve the Information Security Management System, ensuring policies, procedures, standards and controls remain current, approved, communicated and audit-ready. 
  • Coordinate ISMS management reviews, internal audits, corrective actions and continual-improvement activities. 
  • Ensure information security roles, responsibilities, control ownership and evidence requirements are clearly defined. 
  • Oversee information classification, sensitivity labelling, retention, protection and records-management requirements. 
  • Manage Microsoft Purview disposition reviews, ensuring records due for disposal are reviewed by authorised owners, decisions are documented, exceptions are controlled and actions are completed. 
  • Monitor Purview retention and labelling coverage, escalating risks relating to over-retention, uncontrolled information or inadequate audit traceability. 

 

 

 

  1. AI Governance
  • Own and continually improve the organisation's AI governance framework and supporting processes. 
  • Maintain the AI inventory, AI risk exposure register, governance decisions, approvals and supporting evidence. 
  • Assess proposed AI systems, agents, tools, integrations and use cases before implementation. 
  • Evaluate legal, security, privacy, ethical, supplier and operational risks associated with AI. 
  • Ensure compliance with the EU AI Act and alignment with ISO 27001, data protection and organisational governance requirements. 
  • Define requirements for human oversight, accountability, monitoring, documentation and ongoing review. 
  • Monitor emerging AI regulations, standards and risks, translating them into practical governance controls. 

 

 

Competencies to be Demonstrated

  • Strong knowledge of Information Security Governance, Risk and Compliance (GRC) principles and frameworks.
  • Experience managing and continually improving ISO 27001 Information Security Management Systems (ISMS).
  • Sound understanding of GDPR, data protection, records management and information governance requirements.
  • Proven ability to manage risk registers, control frameworks, corrective actions and compliance obligations.
  • Strong audit and assurance capability, including evidence management, internal audits and external audit coordination.
  • Excellent analytical and risk assessment skills with the ability to identify, evaluate and communicate business and cyber risks.
  • Strong written and verbal communication skills, capable of producing clear governance reports and engaging effectively with stakeholders at all levels.
  • Knowledge of AI governance, responsible AI principles and emerging regulatory requirements, including the EU AI Act.
  • Experience with Microsoft Purview, information protection, retention, records management and compliance technologies.
  • Strong organisational, planning and stakeholder management skills with the ability to drive accountability and continual improvement across the business.

 

The statements made in this role description are intended to describe the general nature and level of work being performed by an individual assigned to this role. These statements are not intended to be an exhaustive list of all tasks, responsibilities, accountabilities, duties, and skills.

For more information on this role, or other Construction / Engineering opportunities across Ireland, the UK, Europe, or South Africa please review our careers page (Vacancies - Kirby Group Careers) or contact the Talent Acquisition Team at Kirby Group in confidence on +353 (0)1 454 0411.

Kirby Group Engineering is an equal opportunities employer. We are committed to fostering an inclusive workplace and welcome applications from all suitably qualified candidates, regardless of race, gender, disability, religion, sexual orientation, or age.

 

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf