Make Your Resume Now

Risk Analyst (Security Governance)

Posted March 02, 2026
Employee

Job Overview

Keyloop bridges the gap between dealers, manufacturers, technology suppliers and car buyers.
We empower car dealers and manufacturers to fully embrace digital transformation. How? By creating innovative technology that makes selling cars better for our customers, and buying and owning cars better for theirs.
 
We use cutting-edge technology to link our clients’ systems, departments and sites. We provide an open technology platform that’s shaping the industry for the future. We use data to help clients become more efficient, increase profitability and give more customers an amazing experience. Want to be part of it?
 

Role Summary

The Risk Analyst will support Keyloop’s Security Governance function by identifying, assessing, and monitoring information security risks across the organisation. This role ensures that risk management practices are embedded in business processes, technology deployments, and operational procedures, enabling informed decision-making and compliance with regulatory and industry standards.
The Risk Analyst works closely with Information Security, IT, and business teams to provide risk insights, track remediation, and support continuous improvement of the organisation’s security posture.
Keyloop bridges the gap between dealers, manufacturers, technology suppliers and car buyers.
We empower car dealers and manufacturers to fully embrace digital transformation. How? By creating innovative technology that makes selling cars better for our customers, and buying and owning cars better for theirs.
 
We use cutting-edge technology to link our clients’ systems, departments and sites. We provide an open technology platform that’s shaping the industry for the future. We use data to help clients become more efficient, increase profitability and give more customers an amazing experience. Want to be part of it?
 


Role Summary

The Risk Analyst will support Keyloop’s Security Governance function by identifying, assessing, and monitoring information security risks across the organisation. This role ensures that risk management practices are embedded in business processes, technology deployments, and operational procedures, enabling informed decision-making and compliance with regulatory and industry standards.
The Risk Analyst works closely with Information Security, IT, and business teams to provide risk insights, track remediation, and support continuous improvement of the organisation’s security posture.

Key Responsibilities:

  • Risk Identification & Assessment
  • Conduct risk assessments for systems, applications, projects, and business processes.
  • Identify and evaluate information security risks, threats, and vulnerabilities.
  • Maintain an up-to-date risk register with clear risk categorisation, ownership, and mitigation strategies.
  • Support security control design and risk treatment plans.
  • Policy & Framework Compliance
  • Monitor adherence to internal security policies, standards, and procedures.
  • Support implementation and enforcement of security governance frameworks (e.g., NIST, ISO 27001, SOC 2).
  • Assist in gap analysis and remediation planning for audits, assessments, and compliance reviews.
  • Third-Party Risk Management
  • Assess risks associated with vendors, partners, and third-party service providers.
  • Participate in vendor risk assessments, questionnaires, and ongoing monitoring.
  • Track remediation of identified third-party risks and ensure alignment with contractual requirements.
  • Risk Reporting & Metrics
  • Produce regular risk reports for Information Security leadership and key stakeholders.
  • Define, collect, and report on key risk metrics and indicators.
  • Support management in understanding residual risk, trends, and emerging threats.
  • Audit & Assurance Support
  • Assist in internal and external audits related to information security risk management.
  • Prepare documentation, evidence, and responses for audit inquiries.
  • Ensure risk mitigation and control implementation progress is tracked and reported.
  • Security Awareness & Stakeholder Engagement
  • Work with business and IT teams to raise awareness of security risks and best practices.
  • Provide guidance and support to risk owners in managing and mitigating identified risks.
  • Build effective relationships with stakeholders to embed a risk-aware culture.
  • Continuous Improvement
  • Keep abreast of emerging threats, vulnerabilities, and regulatory changes affecting risk posture.
  • Recommend improvements to risk assessment methodologies, governance processes, and reporting tools.
  • Contribute to the maturity of Keyloop’s Security Governance and Risk Management capability.

Required Experience & skillsets

  • 3–5 years of experience in information security risk management, security governance, or related roles.
  • Practical experience conducting risk assessments, maintaining risk registers, and supporting remediation efforts.
  • Familiarity with security frameworks such as NIST CSF, ISO 27001, SOC 2, or similar.
  • Experience with third-party risk management processes and vendor assessments.
  • Exposure to IT, cloud, and business process risk identification.

  • Skills & Competencies
  • Technical Skills
  • Information security risk assessment and management
  • Security governance frameworks and compliance standards
  • Risk reporting and metric definition
  • Audit support and evidence collection
  • Soft Skills
  • Strong analytical and problem-solving abilities
  • Effective written and verbal communication
  • Ability to influence stakeholders and collaborate across teams
  • Detail-oriented with strong organizational and documentation skills
  • Proactive and adaptable mindset

Why join us?
We’re on a journey to become market leaders in our space – and with that comes some incredible opportunities. Collaborate and learn from industry experts from all over the globe. Work with game-changing products and services. Get the training and support you need to try new things, adapt to quick changes and explore different paths. Join Keyloop and progress your career, your way.
 
An inclusive environment to thrive
We’re committed to fostering an inclusive work environment. One that respects all dimensions of diversity.  We promote an inclusive culture within our business, and we celebrate different employees and lifestyles – not just on key days, but every day.
 
Be rewarded for your efforts
We believe people should be paid based on their performance so our pay and benefits reflect this and are designed to attract the very best talent. We encourage everyone in our organisation to explore opportunities which enable them to grow their career through investment in their development but equally by working in a culture which fosters support and unbridled collaboration.

Keyloop doesn’t require academic qualifications for this position. We select based on experience and potential, not credentials.
We are also an equal opportunity employer committed to building a diverse and inclusive workforce.  We value diversity and encourage candidates of all backgrounds to apply.

Ready to Apply?

Take the next step in your career journey

Stand out with a professional resume tailored for this role

Build Your Resume – It’s Free!