Graduate Cyber Governance Analyst
Summary
Graduate Cyber Governance Analyst collects and maintains audit-ready technical evidence for global compliance frameworks (ISO 27001, PCI DSS, SOC 2, Cyber Essentials), tracks risk actions, executes security tests, and supports security training/policy rollout across international teams.
At Commify, we're not just a company, we're a globally connected team of innovators who love what we do. As a CPaaS leader with 25 years of groundbreaking experience, we're the force behind over 7 billion customer interactions each year, enabling businesses worldwide to connect via advanced channels like SMS, RCS, and complex mobile journeys.
Our culture is our core strength. Operating across the UK, EMEA, the USA, and Australia, we've fostered a truly diverse and connected environment, earning a consistent 4 out of 5 culture score in our employee engagement surveys. You'll join a vibrant team where your diverse experience makes a daily global impact.
We need talented people to grow a global company where everyone feels proud to belong, have a purpose and do their best to directly shape the digital future.
We are looking for a Graduate Cyber Governance Analyst. Working directly alongside our Cyber Security Manager, you will form the operational backbone of our Cyber Security team. This hands-on role gives you unprecedented, multi-territory exposure across more than 20 global compliance frameworks.
If you are eager to learn, detail-oriented, and keen to build a long-term career in cyber security, risk, and compliance, this is your launchpad.
What You’ll Be Doing
- Evidence Management: Source, collect, and maintain the audit-ready technical evidence behind major standards like ISO 27001, PCI DSS, SOC 2, and Cyber Essentials.
- Risk Action Tracking: Help manage our technology risk register, chasing updates and keeping around 140+ action items moving forward.
- Control Testing: Execute routine security tests across assigned frameworks to ensure technical teams adhere to our security policies.
- Framework Standardisation: Work with the Common Controls Framework (SCF) to streamline control answers and map evidence, making audits smoother for technical teams.
- Security Awareness & Training: Help run company-wide security training, manage phishing simulations, and keep our global team cyber-smart.
- Policy Communication: Support the rollout of information security policies across international teams and track compliance.
Requirements
What We’re Looking For
- Degree: A degree related to cyber security.
- Communication Skills: Clear written and spoken English, with the confidence to collaborate with technical and non-technical colleagues alike.
- Passion for Cyber Security: A genuine enthusiasm for cyber governance, cyber security, risk, or compliance, alongside a strong desire to learn.
- Right to Work: Eligible to work in the UK.
- Bonus Points (Desirable): Any prior exposure to cyber governance frameworks or standards such as ISO 27001, PCI DSS, SOC 2, Cyber Essentials, or common controls frameworks through study or projects, familiarity with GRC tools, evidence or policy tracking systems, or phishing simulation platforms, or working towards a cyber security certification such as CompTIA Security+.
Benefits
Benefits:
- Competitive Salary (£30,000-35,000)
- Company Bonus Scheme
- Comprehensive healthcare cash plan
- A generous 27 days of annual leave in addition to Bank Holidays
- 2 Wellbeing leave days and 2 days dedicated to giving back to your community
- Enjoy your birthday off!
- Employer pension contribution at 5%
- Death in service benefit (4 times your salary)
- Annual award recognition
- Fun monthly and quarterly social events
- Opportunities for training and professional development
As published by workable
First name, Last name, Email, Phone, Address, Salary Expectations?, Education, Experience, Resume, Cover letter
- Do you have unrestricted right to work in the UK? (This requires either a British citizenship, ILR or equivalent, should your VISA have an end date, such as a spousal VISA the answer would be no to this question) yes / no
- Are you legally authorized to work in the UK? yes / no
- Are you a recent graduate from a cyber security related course, or a course with cyber modules?
- What are your annual salary expectations in GBP?
- Are you happy to commute to our Nottingham City center office twice per week?