Job Description
The Cyber GRC Analyst supports the delivery of cyber security governance, risk, and compliance across CRH International, operating within a hybrid technology model spanning centrally delivered platforms (UnITy) and independent Operating Companies (OpCos).
Reporting to the Senior GRC Manager, the role is responsible for translating security requirements into practical, risk-based controls and driving their consistent adoption across both central services and decentralised environments. The position acts as a key link between Group Information Security, central platform teams and OpCos, ensuring that security standards, risk management practices, and compliance requirements are effectively implemented and embedded across the organisation.
This role plays a critical part in reducing cyber risk at scale, enabling a consistent security posture while respecting the operational realities of a federated, multi-country business.
About CRH
CRH is committed to contributing to a more resilient and sustainable built environment.
Key Tasks and Responsibilities
- Develop and maintain cyber security policies, standards, and control frameworks, ensuring alignment with CRH Group requirements and applicability across both central platforms (UnITy) and OpCo-managed environments.
- Drive consistent adoption of security standards across central technology services and OpCos, balancing global governance with local implementation models.
- Provide risk-based guidance across both centrally delivered services and decentralised OpCo environments (e.g. IAM, network, endpoint, vulnerability management).
- Perform and support cyber risk assessments across UnITy platforms and OpCos, maintaining risk registers and tracking remediation to reduce enterprise risk exposure.
- Coordinate and support compliance and assurance activities, acting as a central interface between UnITy service teams, OpCos, and auditors.
- Support the delivery of the CRH International cyber programme, ensuring alignment between central technology initiatives and OpCo execution.
- Interpret and translate regulatory, legal, and contractual requirements into scalable and consistent controls applicable across both central and local operating models.
- Support third-party and supply chain risk management across both centrally managed services and OpCo suppliers, ensuring consistent security expectations and remediation tracking.
Key Functional Competencies
- Strong understanding of cyber security frameworks (NIST CSF, ISO 27001, CIS)
- Experience in risk management, control design, and audit support
- Ability to translate technical risks into business impact
- Strong stakeholder management across technical and non-technical audiences
- Structured, pragmatic, and delivery-focused mindset
- Experience operating in a federated or multi-entity organization
- Exposure to third-party risk and regulatory environments
- Familiarity with ServiceNow or similar GRC tooling
- Security certifications (e.g. CISM, CRISC, ISO 27001)
Key Characteristics
- Pragmatic approach to GRC and willing to learn and adopt
- Problem solver and resolves conflicts
- Looks for ways to innovate to improve the focus on the customer
- Motivated and can deal with resistance
- Coaches others to build on strengths and improve on weakness; listens to and encourages regular honest feedback
- An inclination to drill into detail and to take corrective action early and decisively
Individual Competencies
- Drive Results - Consistently achieving objectives, even under tough circumstances, pushing self and others to accomplish goals
- Have Courage - Stepping up to address difficult issues, saying what needs to be said
- Cultivate Innovation - Creating new and better ways for the organisation to be successful
- Collaborate - Building partnerships and working collaboratively with others to meet shared objectives
Experience / Education
- 3-5 years’ experience in Information/IT security
- Good to have certifications like CISM/CISSP/CRISC/GRCP/ISO27001 lead implementor
- Fluency in both speaking and writing English
Additional Information
- Number of Managed Users: 33k+
- Geographies Supported: 20+ Countries
- Headcount within the IT Operations team: 60+
- Headcount across European IT teams: 450+
What CRH Offers You
- A culture that values opportunity for growth, development, and internal promotion
- Comprehensive secondary benefits
- Significant contribution to your pension plan
- Health and wellness programs, including an on-site gym and fitness classes
- Excellent opportunities to develop and progress with a global organization
Benefits/perks listed above may vary depending on the nature of the employment with CRH and the country where you work.