Job Description
Established in 1981 with a single store in the Northwest of England, the JD Group is a leading omni-channel retailer of Sports Fashion, Outdoors and Gyms with our colleagues working in stores across several retail fascias in many markets around the world.
JD Sports Fashion Plc was listed on the London Stock Exchange in 1996 and has been a FTSE100 publicly quoted company since 2019 and continues to grow in the UK and internationally.
We want to be the leading global omnichannel retailer in the sports and outdoor industry. To be a part of this successful company and help us to achieve this you will have the desire to ingrain our strategic goals of being a people-led, innovative and customer-focused organisation which provides operational excellence whilst identifying new areas of growth as part of our day to day objectives.
Role Purpose
The GRC Analyst (Technology and Cyber Risk) will sit within the second line of defence and is responsible for assisting the Cyber Risk Lead in identifying, assessing, and monitoring cyber and technology-related risks across key JD systems, applications, cloud environments, and third-party services. This role requires collaboration with IT, information security, internal audit, and business stakeholders to ensure technology and cyber risks are effectively managed and aligned with regulatory requirements and industry best practices across JD Sports.
Key Responsibilities
Technology and Cyber Risk Management
• Identify, assess, and document technology and cyber risks across IT infrastructure, applications, and cloud environments.
• Perform technology and cyber risk assessments for key JD systems, applications or initiatives.
• Maintain and update the technology risk register, including risk treatment plans and tracking remediation activities.
• Support the development and enhancement of JD Technology Risk Management Framework aligned to standards such as NIST.
• Assess technology risk associated with vendors, suppliers, and third parties.
• Monitor ongoing third-party risk and ensure appropriate mitigation actions are being followed.
Risk Reporting & Stakeholder Engagement
• Prepare clear and concise technology risk reports, dashboards, and metrics for management and governance forums.
• Communicate complex technical risks in business-friendly language.
• Collaborate with IT, Information Security, and business teams to embed a strong risk-aware culture
• Maintain GRC tooling, dashboards and metrics relating to technology and cyber risks.
• Present findings and recommendations with clarity and confidence, supporting informed risk-based decision making.
Audit Support & Stakeholder Management
• Support the Cyber Risk Lead with internal and external auditors during IT audit cycles, coordinating evidence requests, facilitating walkthrough and managing the audit relationship professionally around technology and cyber risk management.
• Support preparation for inspections and audits, ensuring documentation and evidence packs are accurate, complete and audit-ready where required.
• Build effective working relationships and support cross-functional collaboration with other teams and functions such as Technology, Internal Controls, Internal Audit, Enterprise Risk, Legal and Procurement.
Continuous Improvement
• Identify opportunities to improve the efficiency and effectiveness for technology and cyber risk assessments and risk management including automation, tooling and methodology enhancements.
• Support enhancements of GRC policies, standards and procedures relating to technology risk and control.
• Stay current with changes to relevant regulatory requirements, audit standards and industry best practice.
Skills & Experience
Essential
• 3 to 5 years of demonstrable experience in end to end technology and risk management or GRC function within a fast-paced and complex organisation.
• Strong understanding of technology risk concepts, including cloud security, network security, application risk and third-party risk.
• Strong written and verbal communication skills, with the ability to produce clear and concise technology and cyber risk assessment reports.
• Strong stakeholder management and communication skills.
• Familiarity with frameworks such as NIST CSF.
• Ability to identify control weaknesses, articulate risk impact and develop actionable remediation recommendations.
• Organised and methodical approach to workload management, with the ability to manage multiple priorities and deadlines.
Desirable
• Relevant professional certifications such as CISM, CRISC, CISSP or equivalent.
• Familiarity with audit frameworks and standards including NIST and ISO27001
• Experience in a retail, e-commerce or large global enterprise environments, supporting GRC management or support activities.
• Familiarity with GRC tooling platforms such as AuditBoard or similar.
Behaviours & Competencies
• Independence and objectivity: Operates with integrity and professional scepticism, providing impartial assurance regardless of organisational pressure.
• Analytical thinking: Applies a structured, evidence-based approach testing.
• Stakeholder engagement: Builds credible and effective working relationships with first line teams, auditors and senior stakeholders.
• Attention to detail: Maintains a high standard of accuracy in technology and cyber risk management and assessments.
• Continuous improvement: Seeks opportunities to improve processes and outcomes.
We know our colleagues work tirelessly to make JD Sports the success it is today and in turn, we offer them some amazing benefits including staff Discount On JD Group and other brands within the organisation and personal development opportunities to learn and develop at work.
Thank you for your time
#JD