Information Security Analyst

Oyster Ims

Greater London

Hybrid

GBP 45,000 - 65,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Oyster IMS is seeking an Information Security Analyst to join our Information Security team in Greater London. The role blends information security and GRC consultancy with hands-on configuration of the OneTrust platform.

You will help clients understand and manage information security risks, implement controls and derive real value from GRC technology. The position involves working across client engagements and maintaining our own security practices.

Qualifications

  • Experience delivering information security and GRC engagements.
  • Ability to translate client requirements into practical, proportionate solutions.
  • Experience with ISO 27001 and information security controls.
  • Familiarity with OneTrust configurations and implementations.

Responsibilities

  • Support delivery of client information security, GRC, IT risk management and third party risk engagements.
  • Assist with implementing and operating ISO 27001 ISMS for clients.
  • Translate client issues into practical, proportionate solutions.
  • Develop and maintain information security policies, controls and procedures.
  • Provide clear information security, risk and GRC advice to technical and non-technical stakeholders.
  • Deliver training and education on information security topics.
  • Configure and implement OneTrust GRC solutions to meet client requirements.
  • Support IT risk management and third party risk management through OneTrust.
  • Conduct supplier security reviews and third-party risk assessments.
  • Carry out ISMS reviews, audits and spot checks.

Skills

Information Security
GRC
ISO 27001
OneTrust
Risk Management

Tools

OneTrust

Job description

We are looking for an Information Security Analyst to join our Information Security team.

Working closely with our Head of Information Security , consultants, and clients, this is a varied role combining information security and GRC consultancy with hands-on configuration and implementation of the OneTrust platform.

You will work across a range of client engagements, helping organisations understand and manage their information security risks, implement effective controls and get real value from their GRC technology.

This isn’t a role where you’ll simply produce reports and recommendations. We are looking for someone who can understand a client’s problem, work out what needs to happen and help make it happen.

Key Responsibilities

Information Security and GRC Consulting

  • Support the delivery of client information security, GRC, IT Risk Management and Third Party Risk Management engagements.
  • Support clients with the implementation and ongoing operation of ISO 27001 Information Security Management Systems.
  • Understand client issues and requirements and translate them into practical, proportionate solutions.
  • Help clients develop, implement and maintain appropriate information security policies, controls and procedures.
  • Provide clear, practical information security, risk and GRC advice to both technical and non-technical stakeholders.
  • Deliver training, presentations and education on information security topics.

OneTrust

  • Configure and implement OneTrust GRC solutions to meet client requirements.
  • Build and configure assessments, attributes, workflows and related platform functionality.
  • Support the delivery of IT Risk Management and Third Party Risk Management solutions through OneTrust .
  • Work with clients to translate their processes and requirements into effective OneTrust configurations.
  • Maintain relevant OneTrust learning and certifications and keep your platform knowledge current.

Risk, Assurance and Compliance

  • Support clients in identifying, assessing, documenting and treating information security and cyber risks.
  • Undertake supplier security reviews and third-party risk assessments as part of client managed services.
  • Evaluate supplier security posture and support decisions around remediation, risk acceptance or supplier rejection.
  • Carry out and document ISMS reviews, audits and spot checks to determine whether controls are operating effectively.
  • Help clients understand and respond to relevant information security regulatory and compliance requirements, including DORA where applicable.
  • Maintain appropriate records and evidence to demonstrate compliance with relevant standards, regulatory requirements and good practice.

Client and Stakeholder Relationships

  • Build effective relationships with client stakeholders, internal teams and third-party suppliers.
  • Explain complex security, risk and regulatory requirements clearly to technical and non-technical audiences.
  • Work confidently with senior stakeholders and constructively challenge assumptions or decisions where needed.
  • Manage multiple projects and pieces of work simultaneously while maintaining quality and meeting priorities.

Supporting Information Security at Oyster IMS

Alongside client work, you will also help us maintain and continuously improve our own information security environment.

This will include:

  • Maintaining Oyster IMS Policy Management processes through OneTrust , including policy publication and attestation.
  • Supporting administration of our Phished platform, including phishing simulations and security awareness activities.
  • Helping test and improve our internal information security processes and controls.
  • Keeping your technical knowledge, OneTrust learning and relevant certifications current.

Your email address is used only to send you the requested brochure. Please see our privacy policy to find out more.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security & GRC Consultant—OneTrust
Information Security & GRC Consultant—OneTrust

Oyster Ims • Greater London

Hybrid
GBP 45,000 - 65,000
Information Security Analyst
Information Security Analyst

Broster Buchanan • Liverpool

On-site
GBP 40,000 - 60,000
Information Security GRC Manager
Information Security GRC Manager

AJ Bell • Manchester

Hybrid
GBP 65,000 - 85,000
27 days’ holiday
Pension with matched contributions up to 8%
Discretionary bonus and share awards
+3
Graduate Consultant
Graduate Consultant

Oyster Ims • Greater London

On-site
GBP 25,000 - 35,000
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 60,000 - 80,000
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 40,000 - 60,000
IT GRC Senior Analyst
IT GRC Senior Analyst

Nigel Wright Recruitment • Newcastle upon Tyne

Hybrid
GBP 70,000 - 90,000
Hybrid work policy
Information Security Analyst - Tech b/g - Know GRC - Local to Hull - £55k
Information Security Analyst - Tech b/g - Know GRC - Local to Hull - £55k

LT Harper - Cyber Security Recruitment • Kingston upon Hull

Hybrid
GBP 50,000 - 55,000
Information Security Officer
Information Security Officer

Maxwell Bond • Reading

Hybrid
GBP 55,000 - 57,000
Senior Information Security Consultant (GRC)
Senior Information Security Consultant (GRC)

Waterstons • Greater London

On-site
GBP 70,000 - 110,000
Flexible benefits
EV car scheme
Sponsored training
+4