Analyst, Information Security GRC
Manchester, GB
Analyst, Information Security GRC
Location: Manchester, UK | Work Arrangement: Hybrid | Department: Information Security
About the Role
Fitch is seeking an Information Security GRC Analyst to support the delivery and ongoing development of its Cyber Security Awareness and Education program. This role helps employees understand cyber risks and build secure working habits through engaging communications, training, phishing simulation activities, campaigns, reporting, and program administration.
This is an excellent opportunity for someone early in their cyber security, communications, learning and development, risk management, or employee engagement career who is interested in the human side of cyber security. The successful candidate will work closely with Information Security, Employee Communications, Learning and Development, Technology, HR, and business stakeholders to make security guidance clear, practical, and relevant for employees across a global organization.
Responsibilities:
-
Support the planning, coordination, and delivery of cyber security awareness campaigns, including Cyber Security Awareness Month and targeted awareness initiatives throughout the year.
-
Support awareness communications such as newsletters, articles, email campaigns, intranet posts, manager updates, event invitations, and reminder messages.
-
Translate technical cyber security topics into clear, accessible, and employee-friendly messaging.
-
Support the security awareness training lifecycle, including content updates, testing, launch coordination, completion tracking, reminders, and evidence retention.
-
Assist with targeted, role-based, regional, and regulatory training activities, including stakeholder reviews, approvals, and supporting documentation.
-
Support phishing simulation campaigns, including preparation, testing, audience coordination, communications, reporting, and post-campaign follow-up.
-
Compile and maintain program metrics, including training completion, campaign engagement, phishing simulation outcomes, reporting rates, and communication performance.
-
Support the preparation of dashboards, leadership updates, meeting materials, and program reports.
-
Maintain organized records of approvals, communications, process documentation, evidence, and supporting materials.
-
Coordinate with stakeholders across Information Security, Technology, Communications, HR, Learning and Development, Facilities, and business teams.
-
Assist with virtual and in-person awareness events, including speaker coordination, event briefs, calendar invites, promotional materials, volunteer coordination, and post-event follow-up.
Qualifications:
-
Experience in cyber security awareness, human risk, training, communications, and employee education.
-
Strong written communication skills, with the ability to make complex topics clear, simple, and engaging.
-
Good attention to detail and the ability to manage multiple tasks, deadlines, and stakeholders.
-
Strong organizational skills and confidence maintaining trackers, documentation, and structured records.
-
Ability to work collaboratively with technical and non-technical colleagues across different teams and regions.
-
Comfortable using Microsoft Office tools, including Word, PowerPoint, Excel, Outlook, Teams, and SharePoint.
-
Willingness to learn about phishing, social engineering, data protection, identity and access management, secure working practices, AI-related risks, and emerging cyber threats.
-
Ability to handle sensitive information responsibly and maintain confidentiality.
-
A proactive, curious, and improvement-focused mindset.
Preferred Experience:
-
Experience with cyber security awareness programs, phishing simulations, security training platforms, employee engagement campaigns.
-
Experience drafting internal communications, newsletters, articles, presentations, training materials.
-
Experience coordinating campaigns, events, workshops, stakeholder reviews, approval processes.
-
Familiarity with reporting metrics and dashboards.
-
Basic understanding of cyber security topics such as password security, multi-factor authentication, data handling, AI-related risks, and incident management.
-
Experience working in a regulated, financial services, professional services, or global corporate environment.
What We Offer:
You will have the opportunity to contribute to a global cyber security awareness program, work with stakeholders across the business, and develop practical experience in cyber security, communications, training, reporting, and human risk management.
Why Choose Fitch:
- Hybrid Work Environment: On-site presence required two days per week.
- A Culture of Learning & Mobility: Access to dedicated training, leadership development, and mentorship programs to support continuous learning.
- Investing in Your Future: Retirement planning and tuition reimbursement programs to help you meet your short- and long-term goals.
- Promoting Health & Wellbeing: Comprehensive healthcare offerings that support physical, mental, financial, social, and occupational wellbeing.
- Supportive Parenting Policies: Family-friendly policies, including a generous global parental leave plan, designed to help you balance work and family life.
- Inclusive Work Environment: A collaborative workplace where all voices are valued, supported by Employee Resource Groups that unite and empower colleagues worldwide.
- Dedication to Giving Back: Paid volunteer days, matched donation programs, and ample opportunities to volunteer in your community.
Fitch is committed to providing global securities markets with objective, timely, independent and forward-looking credit opinions. To protect Fitch’s credibility and reputation, our employees must take every precaution to avoid conflicts of interest or any appearance of a conflict of interest. Should you be successful in the recruitment process at Fitch Ratings you will be asked to declare any securities holdings and other potential conflicts prior to commencing employment. If you, or your immediate family, have any holdings that may conflict with your work responsibilities, you may be asked to divest yourself of them before beginning work.
Fitch is proud to be an Equal Opportunity and Affirmative Action Employer. We evaluate qualified applicants without regard to race, color, national origin, religion, sex, sexual orientation, gender identity, disability, protected veteran status, and other statuses protected by law.