Application Deadline: 5 May 2026
Department: Corporate Services
Location: Priory IT Offices
Description
We’re looking for a skilled IT Technical Risk Analyst to join our team, based in or around Bristol, with a flexible hybrid model (4 days from home, 1 day in the office). In this role, you’ll play a key part in strengthening our IT risk and compliance framework—overseeing system acquisition processes, driving risk mitigation strategies, and supporting the ongoing development of the Priory ISMS.
You’ll also coordinate third-party risk management and lead compliance monitoring activities, ensuring the organisation consistently meets its internal standards, regulatory requirements, and broader governance objectives. This is a great opportunity to make a tangible impact in a role that combines technical insight with strategic oversight.
What you'll be doing
You’ll play a key role in strengthening our IT governance, risk, and compliance framework. This includes evolving the ISMS, leading internal compliance activities, analysing audit data, and supporting security incident response with clear risk assessments and reporting.
You’ll oversee IT risk management processes—maintaining the risk register, tracking mitigation actions, and supporting reporting across cybersecurity, resilience, and third-party risk. Working closely with IT, Legal, Procurement, and business teams, you’ll also support system acquisitions, bids, and due diligence from a security perspective.
In addition, you’ll manage software governance and application risk, ensuring effective controls, clear ownership, and timely remediation. Reporting to the Group CISO, you’ll contribute to the development of the IT GRC function while promoting strong information security practices across the organisation.
What you'll bring to the role
You’ll bring a strong understanding of information security, risk, and compliance in a regulated environment, with hands-on experience of frameworks such as ISO 27001, NIST, Cyber Essentials, and GDPR.
You’ll have proven experience in IT risk or compliance roles, including risk assessments, audits, gap analysis, and maintaining risk registers. You’re comfortable working in project-based environments and managing multiple priorities to deliver accurate, high-quality outputs.
Strong communication skills are essential, with the ability to engage confidently with senior stakeholders and collaborate across technical and non-technical teams. You’ll be organised, detail-focused, and proficient in MS Office tools, with the ability to quickly pick up new systems.
You’ll also bring a proactive mindset and a genuine interest in cybersecurity and IT governance, with a relevant degree or professional qualification preferred.
What we will give you in return