Are you an experienced Information Security Analyst looking for your next opportunity?
We’re supporting our client with a new vacancy for an experienced Information Security Analyst at an exciting stage of growth. You will join a collaborative team and play a key role in strengthening its security capabilities. This is a great opportunity for someone looking to develop their experience across Governance, Risk & Compliance (GRC)while also gaining exposure to technical security. You'll have knowledge and experience working with recognised security frameworks such as ISO 27001 or NIST.
The Role
You’ll be involved across a broad range of information security activities, including:
- Conducting information security risk assessments across technology, applications, projects and business processes
- Monitoring security risks, actions and remediation activity
- Escalating significant or overdue risks where appropriate
- Supporting third-party risk management, supplier due diligence and security assessments
- Performing security assurance activities and identifying opportunities to strengthen controls
- Producing security reports, dashboards and management information
- Working closely with Security Operations and IT teams on vulnerability assessments and remediation
- Supporting the implementation of security tools and technologies
- Assisting with the management of security events and incidents
- Supporting security awareness and training initiatives
- Maintaining and improving information security policies, standards and procedures
- Acting as the Information Security representative for allocated projects and business areas
- Keeping up to date with emerging threats, vulnerabilities and industry developments
Skills & Experience
- Proven experience in information security, cyber security, security assurance or technology risk
- Practical experience conducting security risk assessments and reviewing security controls
- Experience identifying control weaknesses and supporting assurance activitiesA good understanding of information security governance and risk management
- The ability to translate technical findings into clear business risks
- Experience working with both technical and non-technical stakeholders
- Strong analytical, problem-solving and communication skills
- Excellent organisation and attention to detail
- The ability to manage competing priorities and work independently
- Knowledge of recognised security frameworks such as ISO 27001 or NIST