Enable job alerts via email!

Information Security Analyst

Lancashire Insurance Group

Greater London

On-site

GBP 40,000 - 60,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a dedicated Information Security Analyst to enhance its cyber security posture during a pivotal digital transformation. This role involves evaluating security controls, conducting risk assessments, and collaborating with cross-functional teams to ensure compliance with regulatory frameworks. The ideal candidate will possess hands-on experience with recognized security frameworks such as NIST CSF and ISO27001, and will be instrumental in developing risk mitigation strategies. Join a forward-thinking organization that values integrity and fosters a positive work culture, where your contributions will directly impact the security landscape of the business.

Qualifications

  • Experience in Information Security, especially in financial services.
  • Hands-on knowledge of cyber risk assessments and compliance.

Responsibilities

  • Support the Information Security Manager in delivering security management systems.
  • Evaluate cyber security controls and conduct risk assessments.

Skills

Information Security
Cyber Risk Assessment
NIST Cyber Security Framework (CSF)
ISO27001
Regulatory Compliance (FCA, PRA, NYDFS)
Analytical Skills
Interpersonal Skills
Problem-Solving Skills
Communication Skills
Microsoft Systems (on-premise and Azure)

Job description

Direct message the job poster from Lancashire Insurance Group

Information security is an essential function at Lancashire and is committed to its continuous improvement; the addition of this role is an important element in achieving its security objectives during Lancashire’s time of digital transformation and growth.

Reporting to the Information Security Manager, the post holder will be responsible for evaluating cyber security controls, conducting risk assessments and collaborating with cross-functional teams. The post holder will support the Information Security Manager in maintaining all aspects of information security risk management including responding to security inquiries and incidents, maintaining cyber security governance, and ensuring compliance with relevant regulatory requirements.

Responsibilities
  • Support the Information Security Manager in delivering the Information Security Management System and to drive continuous improvement for information security.
  • Evaluate and assess cyber security controls across the business and its third party vendors to ensure compliance with the NIST Cyber Security Framework (CSF).
  • Conduct comprehensive risk assessments using the NIST CSF.
  • Use risk management techniques to identify cyber threats, risks and issues in a timely manner.
  • Support, develop and conduct third-party vendor security assurance activities.
  • Collaborate with cross-functional teams to develop and implement risk management activities.
  • Respond to security support tickets and other enquiries; providing information security support and escalation.
  • Support the creation and collection of metrics, validation of security control performance and the identification of emerging cyber risks.
  • Collaborate with the Enterprise Risk Management (ERM) team to maintain, develop and deliver cyber risk reporting and appetite statements.
  • Maintain Information Security policy and procedure ensuring content is relevant to the current cyber threat landscape.
  • Maintain, develop and test the Cyber Incident Response Plan, ensuring content is relevant to the current cyber threat landscape.
  • Monitor, maintain and manage Lancashire compliance with its relevant cyber security regulation obligations.
  • Manage actions and output generated by stakeholder engagements; for example customers, regulators, internal and external auditors.
  • Maintain currency with emerging security trends, threat intelligence, industry standards and good practice, and security enhancing technologies.
Minimum Requirements
  • Sound knowledge of and experience in an Information Security role.
  • Experience working in a professional or financial services environment.
  • Hands-on experience conducting cyber risk assessments and developing cyber risk mitigation strategies.
  • Hands-on experience conducting cyber security control assessments, and developing and maintaining cyber risk reporting and risk appetite statements.
  • Hands-on knowledge and experience working with recognised security frameworks such as NIST CSF, ISO27001 etc.
  • Hands-on experience managing and maintaining cybersecurity compliance with regulatory frameworks such as FCA, PRA, NYDFS etc.
  • Experience developing a governance framework by maintaining policy and procedure.
  • Ability to achieve against agreed deadlines.
  • Ability to work both independently and collaboratively.
  • Strong interpersonal and communication skills (written and verbal), with the ability to interact with technical and non-technical stakeholders at all levels.
  • Strong analytical, problem-solving, organisation and planning skills.
  • A pro-active and enthusiastic approach.
  • Knowledge of Microsoft systems (on-premise and Azure cloud), technologies, infrastructure, awareness of systems management and operational support tools.
  • Acknowledges and responds positively to exceptional events in information security to meet the objectives of the business.
The Lancashire Way

At Lancashire, we believe our culture sets us apart. The way we behave and approach our work day-to-day is what makes us unique and creates a positive experience for our people, business partners and other stakeholders. Honesty and integrity in all we do is a given and The Lancashire Way reflects our true character and spirit.

Seniority level

Associate

Employment type

Full-time

Job function

Analyst, Information Technology, and Other

Industries

Insurance

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

IT Security Analyst

Newmedica

London

Remote

GBP 40,000 - 48,000

12 days ago

Information Security Analyst - Third Party Assurance

Starling Bank

London

Hybrid

GBP 40,000 - 60,000

Yesterday
Be an early applicant

Information Security Analyst

Cloud Decisions

Remote

GBP 45,000 - 58,000

4 days ago
Be an early applicant

Senior Information Security Analyst

Pearson Whiffin Recruitment Ltd

England

Remote

GBP 40,000 - 60,000

4 days ago
Be an early applicant

Senior Information Security Analyst

IOVENDO

East Malling

Remote

GBP 40,000 - 60,000

4 days ago
Be an early applicant

Junior Information Security Analyst - Home based

RecruitMe

Remote

GBP 36,000 - 42,000

5 days ago
Be an early applicant

Information Security Analyst

Intec Select

Greater London

Hybrid

GBP 45,000 - 55,000

4 days ago
Be an early applicant

Information Security Analyst

NorthMark Strategies

Greater London

On-site

GBP 50,000 - 75,000

6 days ago
Be an early applicant

IT Security Analyst

Witherslack Group

Remote

GBP 35,000 - 45,000

2 days ago
Be an early applicant