Permanent position available with a considerable portfolio of works for the next 5+ years
To build your career by assisting in the delivery of ‘leading edge’ engineering projects.
To work with a vibrant, agile and multi-functional team in delivering projects on time, safely, to budget and to the required quality standards.
To benefit from Kirby’s Career Development Programmes that will enhance your leadership capability.
To work with the best.
Excellent package on offer with room for negotiations
About Kirby Group Engineering
Kirby Group Engineering is an international multi-disciplinary engineering services contractor and leading provider of high-value engineering services to a number of ‘blue chip’ companies. Operating across Ireland, the UK, Europe and South Africa, Kirby has become the engineering service provider of choice in growth segments such as pharmaceuticals, data centres and power transmission and distribution. Our culture is innovative, collaborative and performance focused. The successful candidate will have the opportunity to grow and develop in a company committed to developing talent and rewarding performance.
Role Purpose
The GRC Analyst is responsible for establishing, operating, and continuously improving a structured Governance, Risk, and Compliance (GRC) capability across the business. Ensuring that risks, controls, policies, and compliance obligations are centrally managed visible, and consistently applied. Owning and managing data governance practices, ensuring that data classification, retention, and protection controls are consistently applied, maintained, and evidenced across the organisation with clear visibility for audit, compliance, and risk management purposes.
Key Responsibilities
Governance & Policy Management
Maintain and continuously improve the organisation’s information security, governance, and compliance framework.
Ensure all policies, procedures, and standards are:
Up to date
Approved by the appropriate owners
Version controlled
Communicated and accessible
Aligned with ISO 27001 and relevant legal, regulatory, and contractual obligations
Support governance forums such as management reviews, steering groups, and risk/compliance meetings.
Ensure roles, responsibilities, and accountability for controls are clearly assigned across departments.
Support the development of governance mechanisms that provide leadership with visibility of compliance, control effectiveness, and key risks.
Risk Management
Own and maintain the central risk register, including enterprise, operational, project, and technology-related risks.
Ensure risks are:
Identified consistently
Assessed using an agreed methodology
Assigned to named owners
Tracked through treatment, acceptance, or closure
Facilitate risk workshops and risk reviews with departments and key stakeholders.
Monitor risk treatment plans and escalate overdue or ineffective actions where required.
Ensure risks, incidents, audit findings, and control weaknesses are appropriately linked.
Support a structured and repeatable risk management approach across the organisation.
Compliance & Regulatory Oversight
Monitor and support compliance with relevant obligations, including:
ISO 27001
GDPR
EU AI Act
Other applicable internal and external compliance requirements
Maintain evidence of compliance activities and ensure documentation is organised, current, and defensible.
Coordinate internal and external audit activities, including:
Evidence gathering
Stakeholder coordination
Tracking findings and corrective actions
Supporting closure and verification
Prepare compliance and assurance reporting for management.
Ensure compliance activities are embedded into day-to-day operations rather than treated as one-off exercises.
Control Framework & Assurance
Maintain the organisation’s control framework, ensuring it is mapped to ISO 27001 Annex A and other applicable standards where required.
Ensure controls are:
Clearly defined
Allocated to accountable owners
Implemented in practice
Tested or reviewed periodically
Supported by evidence
Identify control gaps, inconsistencies, or weaknesses and drive remediation actions.
Support assurance reviews to determine whether controls are operating effectively.
Promote a continuous improvement approach to control maturity and evidence quality.
Incident, Issue & Corrective Action Oversight
Ensure security, compliance, and operational incidents are:
Logged
Categorised
Investigated
Tracked to closure
Ensure issues and incidents are assessed for root cause, control impact, and recurring trends.
Link incidents and issues to risk treatment, control improvements, and lessons learned.
Monitor corrective actions arising from incidents, audits, or reviews to ensure completion and effectiveness.
Support reporting on incident trends, recurring weaknesses, and systemic issues.
GRC Tooling, Reporting & Records Management
Support the implementation, administration, and continuous improvement of GRC tooling where approved.
Maintain key GRC records and repositories, including:
Risk registers
Control libraries
Audit findings logs
Compliance evidence repositories
Exception and acceptance records
Produce dashboards, reports, and management information for:
Leadership teams
Audit purposes
Risk and compliance monitoring
Ensure GRC data is accurate, current, traceable, and usable for audit and management decision-making.
Data Governance, Retention & Protection
Ensure data classification, retention policies, and protection controls are:
Applied consistently across users, systems, and data types
Monitored for effectiveness and completeness
Maintained and updated in line with regulatory and business requirements
Maintain and oversee:
Data retention schedules
Data classification structures
Records management practices
Ensure data is:
Retained only as long as required
Protected appropriately based on classification
Disposed of in a controlled and auditable manner
Act as the governance owner for Purview outputs, including:
Compliance posture visibility
Retention and labelling coverage
Audit evidence for ISO 27001 and GDPR
Identify and escalate:
Gaps in data classification or retention coverage
Inconsistent application of policies
Risks relating to over-retention, uncontrolled data, or lack of audit traceability
Work with IT (where required) to:
Implement changes to existing policies
Improve coverage and consistency
Address findings from audits or risk reviews
Ensure all data governance activities are:
Documented
Traceable
Audit-ready
AI & Emerging Risk Governance
Maintain AI inventories, risk exposure logs, and related governance records.
Support AI risk assessments, treatment planning, and governance decisions.
Monitor emerging obligations relating to AI, automation, digital platforms, and regulatory developments.
Ensure AI use cases, tools, and integrations are captured and reviewed in line with organisational governance requirements.
Support the development of practical processes for managing emerging technology risks in a controlled and auditable manner.
Key Skills & Experience
Essential
Experience in Governance, Risk, and Compliance (GRC), Information Security, or a related control/governance role.
Strong understanding of:
ISO 27001
Risk management methodologies
Compliance and assurance processes
Control frameworks and audit readiness
Experience maintaining risk registers, audit evidence, action trackers, and compliance records.
Experience developing, implementing, or maintaining standards, procedures, or control frameworks.
Ability to interpret frameworks and translate them into practical business and IT controls.
Strong documentation, organisation, and stakeholder coordination skills.
Ability to work across business and technical teams to drive accountability and follow-through.
Desirable
Exposure to:
NIS2
GDPR compliance processes
EU AI Act / AI governance
MS Purview
Experience with GRC tools or structured compliance/risk platforms.
Relevant certifications would be beneficial but are not mandatory, for example:
ISO 27001
Security+ or similar security/governance-related certification
Key Behaviours
Structured thinker – able to bring order, consistency, and traceability to fragmented processes.
Risk-based mindset – understands impact, exposure, and prioritisation, not just compliance wording.
Implementation-focused – able to move from policy and standards into actual operational execution.
Audit-ready mentality – ensures everything is evidenced, traceable, defensible, and ready for review.
Cross-functional communicator – able to work effectively with IT, HR, Legal, Operations, and leadership.
Pragmatic and detail-oriented – balances best practice with operational reality and follows through on actions.
Ireland Remote (Country)