Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security GRC Analyst (UK Remote) image - Rise Careers
Job details

Security GRC Analyst (UK Remote)

Company Description

When you join Turnitin, you'll be welcomed into a company that is a recognized innovator in the global education space. For over 25 years, Turnitin has partnered with educational institutions to promote honesty, consistency, and fairness across all subject areas and assessment types. Over 21,000 academic institutions, publishers, and corporations use our services: Feedback Studio, Originality, Gradescope, ExamSoft, Similarity, and iThenticate.

Experience a remote-centric culture that empowers you to work with purpose and accountability in a way that best suits you, supported by a comprehensive package that prioritizes your overall well-being. Our diverse community of colleagues are all unified by a shared desire to make a difference in education.

Turnitin is a global organization with team members in over 35 countries including the United States, Mexico, United Kingdom, Australia, Japan, India, and the Philippines.

Job Description

Turnitin is seeking an experienced Security GRC Analyst to join our Security & Compliance team. The Sr Security GRC Analyst will be responsible for ensuring that our information and cloud systems comply with relevant regulatory frameworks, industry standards, and internal policies. They will also collaborate with various departments, monitor compliance, conduct assessments, and support initiatives to identify and mitigate risks.

We are looking for someone who brings strong analytical ability, attention to detail, effective communication, compliance experience, and the willingness to continuously learn. This role requires hands-on work, critical thinking and the ability to find new solutions for compliance. 

This role reports to the GRC Information Security Manager.

Responsibilities: 

  • Maintain compliance tracking capabilities to help ensure adherence with Turnitin’s security program and industry standards such as NIST CSF, NIST 800-53, SOC 2, TX-RAMP and PCI DSS.
  • Conduct risk and compliance assessments, audits, and risk evaluations to identify potential risk and compliance gaps.
  • Lead preparation and audit activities required to maintain our SOC 2 Type 2.
  • Collaborate with internal teams and external auditors for audit and compliance reviews.
  • Collaborate with sales and customer support teams to respond to security questionnaires and security posture questions from customers.
  • Support TPRM Program and conduct third-party risk assessments.
  • Complete user access reviews.
  • Administration of GRC platform.
  • Participate in the development and documentation of security policy, standards and processes to align with company information security strategy.
  • Provide security awareness and phishing training for employees and promote a culture of security and compliance.
  • Coordinate phish testing.
  • Collaborate with DevOps, IT, Legal, Engineering, People Team, and other departments to ensure security control and policy requirements are integrated into systems and business processes.
  • Provide input on ways to improve and automate team processes.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent experience).
  • 3+ years of experience in a role related to Information Security or Cybersecurity Compliance.
  • Professional certification such as CCSK, AWS Cloud Practitioner, or other related industry certification.
  • Familiarity with cybersecurity frameworks and regulatory standards such as NIST, SOC 2, TX-RAMP, and PCI DSS.
  • Familiarity of risk management and security best practices.
  • Experience with assessing security controls, risk mitigation strategies, and audit procedures.
  • Understanding of concepts related to AWS Cloud Infrastructure and security.
  • Experience conducting security impact analysis for system changes.
  • Experience conducting periodic internal security reviews or risk assessments to ensure that compliance procedures and technical configurations are followed.
  • Experience conducting third-party risk assessments.
  • Contract review experience for security requirements.
  • Highly organized and proactive individual capable of managing multiple responsibilities and delivering results. 

Preferred Skills:

  • Experience running SOC 2 audits or NIST based authorizations.
  • Experience using Jira and Confluence for project and task management.
  • Hands-on experience with Wiz, KnowBe4, and Hyperproof.
  • Experience conducting third-party risk assessments.
  • Demonstrated knowledge of security assessment of cloud technology and services (AWS).
  • Entry level cybersecurity certification such as Security+, GIAC GSEC, or ISC2 Certified in Cybersecurity.

Additional Information

Total Rewards @ Turnitin
Turnitin maintains a Total Rewards package that is competitive within the local job market. People tend to think about their Total Rewards monetarily — solely as regular pay plus bonus or commission. This is what they earn in exchange for what they do. However, Turnitin delivers more than just these components. Beyond the intrinsic rewards of unleashing your potential to positively impact global education, and thriving in an organization that is free of politics and full of humble, inclusive and collaborative teammates, the extrinsic rewards at Turnitin include generous time off and health and wellness programs that offer choice and flexibility and provide a safety net for the challenges that life presents from time to time. Experience a remote-centric culture that empowers you to work with purpose and accountability in a way that best suits you, supported by a comprehensive package that prioritizes your overall well-being.

Our Mission is to ensure the integrity of global education and meaningfully improve learning outcomes.

Our Values underpin everything we do.

  • Customer Centric - We realize our mission to ensure integrity and improve learning outcomes by  putting educators and learners at the center of everything we do.
  • Passion for Learning - We seek out teammates that are constantly learning and growing and build a workplace which enables them to do so.
  • Integrity - We believe integrity is the heartbeat of Turnitin. It shapes our products, the way we treat each other, and how we work with our customers and vendors.
  • Action & Ownership - We have a bias toward action and empower teammates to make decisions.
  • One Team - We strive to break down silos, collaborate effectively, and celebrate each other’s successes.
  • Global Mindset - We respect local cultures and embrace diversity. We think globally and act locally to maximize our impact on education.

Global Benefits

  • Remote First Culture
  • Health Care Coverage*
  • Education Reimbursement*
  • Competitive Paid Time Off 
  • 4 Self-Care Days per year
  • National Holidays*
  • 2 Founder Days + Juneteenth Observed
  • Paid Volunteer Time*
  • Charitable contribution match*
  • Monthly Wellness or Home Office Reimbursement/*
  • Access to Modern Health (mental health platform)
  • Parental Leave*
  • Retirement Plan with match/contribution*

* varies by country

Seeing Beyond the Job Ad
At Turnitin, we recognize it’s unrealistic for candidates to fulfill 100% of the criteria in a job ad.  We encourage you to apply if you meet the majority of the requirements because we know that skills evolve over time. If you’re willing to learn and evolve alongside us, join our team!

Turnitin, LLC is committed to the policy that all persons have equal access to its programs, facilities and employment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Average salary estimate

$70000 / YEARLY (est.)
min
max
$60000K
$80000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security GRC Analyst (UK Remote), Turnitin, LLC

Join the innovative team at Turnitin as a Security GRC Analyst and become an integral part of our Security & Compliance department! Located in Leeds, UK, and fully remote, this position is perfect for those who are passionate about information security and compliance. In this exciting role, you will work closely with internal teams and external auditors, ensuring that our information and cloud systems comply with industry standards, including NIST and SOC 2. You'll conduct risk assessments, initiate compliance audits, and continuously monitor performance, helping identify potential risks or compliance gaps. Don’t worry—you won’t be working in isolation! Collaboration is key here; you’ll team up with Sales, IT, and Legal departments to address security questionnaires and bolster our security posture. If you have a hands-on approach, a keen eye for detail, and the desire to contribute meaningfully to education integrity on a global scale, this is the job for you! You’ll get to manage GRC platforms, develop security policies, and champion a culture of security awareness throughout the organization. Plus, at Turnitin, you’ll find a supportive environment with a robust rewards package that prioritizes your well-being and professional growth. If you’re ready to make a difference and grow in your career as a Security GRC Analyst, we’d love to hear from you!

Frequently Asked Questions (FAQs) for Security GRC Analyst (UK Remote) Role at Turnitin, LLC
What are the main responsibilities of a Security GRC Analyst at Turnitin?

As a Security GRC Analyst at Turnitin, your primary responsibilities include maintaining compliance tracking for the organization's security programs, conducting risk assessments and audits, collaborating with various departments for compliance reviews, and supporting the Third-Party Risk Management Program. You'll also lead preparations for SOC 2 Type 2 audits and conduct user access reviews, ensuring our standards meet industry regulations.

Join Rise to see the full answer
What qualifications are necessary for the Security GRC Analyst role at Turnitin?

To qualify for the Security GRC Analyst role at Turnitin, candidates should have a Bachelor's degree in Computer Science, Information Security, or a related field, along with a minimum of three years of experience in Information Security or Cybersecurity Compliance. Professional certifications such as CCSK or AWS Cloud Practitioner are beneficial, as well as familiarity with cybersecurity frameworks and regulatory standards like NIST and SOC 2.

Join Rise to see the full answer
How does Turnitin support its Security GRC Analysts in their career growth?

Turnitin is committed to fostering a culture of learning and development for Security GRC Analysts. The organization offers comprehensive professional development opportunities, including training programs and access to resources that enhance technical skills. Additionally, Turnitin supports a remote-centric work culture that values collaboration and personal growth.

Join Rise to see the full answer
What is the work environment like for a Security GRC Analyst at Turnitin?

The work environment for a Security GRC Analyst at Turnitin is integrated around a remote-first culture that promotes accountability and flexibility. This supportive atmosphere encourages security professionals to engage with teams globally while contributing to meaningful projects that enhance educational integrity. You'll find an inclusive and collaborative workforce, characterized by shared values of integrity, customer-centricity, and continuous learning.

Join Rise to see the full answer
What tools are utilized by Security GRC Analysts at Turnitin?

Security GRC Analysts at Turnitin leverage a variety of tools that aid in auditing, compliance tracking, and security assessments. Familiarity with platforms such as Wiz, KnowBe4, and Hyperproof is preferred, alongside experience using Jira and Confluence for project management tasks. Utilizing these tools effectively helps to ensure compliance and streamline audit processes, critical for maintaining Turnitin's high standards.

Join Rise to see the full answer
Common Interview Questions for Security GRC Analyst (UK Remote)
Can you explain your experience with compliance frameworks relevant to the Security GRC Analyst role?

In answering this question, provide specific instances where you've successfully implemented or monitored compliance frameworks like NIST or SOC 2. Highlight your understanding of the frameworks and their critical roles in assessing organizational security posture.

Join Rise to see the full answer
Describe a time you identified a security vulnerability. How did you handle it?

This is a chance to illustrate your analytical skills. Describe the process you took to identify the vulnerability, how you evaluated the risk, and the steps you took to mitigate it. Emphasize teamwork and communication with relevant stakeholders.

Join Rise to see the full answer
How do you prioritize tasks when handling multiple projects as a Security GRC Analyst?

Demonstrate your organizational skills by discussing your approach to prioritization. Mention tools or methods you use for managing tasks and deadlines, and explain how you ensure that compliance and security measures are not overlooked.

Join Rise to see the full answer
What is your approach when collaborating with teams outside of the security department?

Share your strategies for effective collaboration and communication, such as regular check-ins or sharing informative resources. Stress the importance of understanding the needs of other departments and how you can align security protocols with their goals.

Join Rise to see the full answer
Have you ever faced pushback when implementing security measures? How did you manage it?

Talk about your experience in advocating for security protocols even when met with resistance. Explain how you communicated the importance of compliance and security to gain buy-in, using data or case studies if applicable.

Join Rise to see the full answer
What tools or technologies do you consider essential for a Security GRC Analyst?

Mention specific tools that you have professional experience with or are familiar with, like GRC platforms or security assessment technologies. Discuss how these tools enhance the compliance and risk management processes.

Join Rise to see the full answer
How do you stay current on changes in regulatory requirements for the Security GRC Analyst role?

Share your commitment to continuous learning by mentioning industry resources, training programs, or professional networks you engage with. Discuss how you integrate new knowledge into your work to ensure compliance.

Join Rise to see the full answer
Describe your experience preparing for and conducting audits.

This is an opportunity to walk through your audit preparation process, including documentation, collaboration with other departments, and using findings to improve compliance. Illustrate your attention to detail and proactive mindset.

Join Rise to see the full answer
What security awareness training strategies would you propose for employees?

Discuss innovative ideas for security training programs, such as gamified learning experiences or regular phishing simulations. Highlight the importance of promoting a culture of security awareness in an organization.

Join Rise to see the full answer
Why do you want to work as a Security GRC Analyst at Turnitin?

Convey your admiration for Turnitin’s mission in education and how your values align with its goals. Share experiences that demonstrate your commitment to integrity and compliance, and how you envision contributing to the team.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User

Join Turnitin as a Senior Internal Comms Creative Production Partner to lead innovative internal communication strategies in a remote-centric environment.

Photo of the Rise User
Posted 7 days ago

Turnitin is looking for a dedicated Administrative Assistant to provide primary support to Senior Leadership in a remote environment.

Photo of the Rise User

Lead the development and implementation of high-quality technology solutions at NYC Health + Hospitals as a Full Stack Developer.

Shape the future of Salesforce as a Mid-Level Administrator/Developer in a fast-growing tech-driven company.

Posted 8 days ago

Join Brightspeed as an IT Solution Architect to shape the future of internet connectivity while ensuring exceptional service quality.

Banner Health Hybrid Banner Health Corp Mesa (525 W Brown Rd)
Posted 13 days ago

Join Banner Health as a Security Systems Technologist to ensure the safety and security of patients and staff through advanced technology.

Photo of the Rise User
ComTec Solutions Hybrid US, Monroe County, NY; New York State, Rochester, NY
Posted 10 days ago

We are seeking an IT Systems Specialist to provide top-notch technical support for our deployed technologies while ensuring customer satisfaction.

Posted 2 days ago

Join CommonSpirit Health as an IT Systems Engineer and play a vital role in advancing healthcare through technology innovations.

Photo of the Rise User
ManTech Remote US, Fairfax County, VA; Virginia, Herndon, VA
Posted 10 days ago

We are looking for an experienced Senior Solutions Architect to design innovative cloud solutions for national intelligence customers at ManTech.

Photo of the Rise User
Posted 9 days ago

A leading digital service provider in Düsseldorf seeks a skilled Application Owner for Salesforce Sales Cloud to lead platform development and compliance.

Turnitin solutions promote academic integrity, streamline grading and feedback, deter plagiarism, and improve student outcomes. The company is headquartered in Oakland, California.

42 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 19, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!