Information Security and Data Protection Analyst

Sideways 6

Manchester

On-site

GBP 42,000 - 62,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

25 days annual leave
Cycle to work scheme
Learning & Development platform
Life Insurance
Auto Enrolment Pensions
Healthshield cashback
Mobile phone reimbursement
Free Gym membership

Job summary

Interact is seeking an Information Security and Data Protection Analyst in Manchester to strengthen our information security and GDPR compliance. You will balance security controls with business needs, working with stakeholders across Engineering and with external regulators if required.

The role covers policy development, risk assessments, incident response, and audit support, ensuring our ISO27001, SOC 2, and Cyber Essentials programs remain robust across North America, EMEA, and beyond.

Qualifications

  • 2-3 years minimum in an information security or data protection role.
  • Hands-on experience with at least two certification cycles (ISO 27001, SOC 2, etc.).
  • Demonstrable experience managing or influencing stakeholders at a senior level.
  • Involvement in penetration testing activities and remediations.
  • Experience handling real security incidents or data breaches.
  • Ability to pragmatically balance security risk against business need.
  • Maintenance and creation of the Risk Register, ROPA & DPIAs
  • Strong awareness of the GDPR, either through training or practical work.
  • Strong practical understanding of security and compliance frameworks (ISO27001, SOC 2 Type II, Cyber Essentials Plus).
  • Practical knowledge of Defender, Intune, Entra, Purview, AWS and Azure

Responsibilities

  • Create, review, and improve security policies.
  • Implement and maintain Information Security Management System (ISO27001 certification).
  • Support certification/compliance activities for security standards (ISO 27001, SOC 2, Cyber Essentials).
  • Experience in undergoing audits.
  • Support business continuity plans and policy.
  • Build and maintain relationships with technical and business stakeholders.
  • Lead regular risk assessments and internal process audits.
  • Collaborate with internal teams to manage risks and propose solutions.
  • Support evidence collation for audits.
  • Conduct vendor/supplier reviews per Internal Policy.
  • Complete client security questionnaires for prospects and customers.
  • Maintain and improve information security awareness within the business.
  • Monitor activities under UK GDPR and other data protection laws.
  • Coordinate with regulators during investigations as required.
  • Be point of contact for data processing inquiries.
  • Maintain security tickets with timely follow-up and cross-team collaboration.
  • Oversee penetration testing remediations.

Skills

Information Security
Data Protection
Stakeholder Management
Penetration Testing
Incident Response
Risk Management
GDPR Knowledge
ISO27001

Tools

Defender
Intune
Entra
Purview
AWS
Azure

Job description

Information Security and Data Protection Analyst

Department: Engineering

Employment Type: Full Time

Location: Manchester, UK

Reporting To: Zack King

Description

Interact provides enterprise-grade intranet software that connects over three million employees to leading global names like Levi's, Domino’s, Teva Pharmaceuticals, and Technicolor.

Our team of customer-focused problem solvers are passionate about helping organizations to communicate better. We do this together by constantly working to improve every service and product we offer. With offices in Manchester, New York, Dubai, Tulsa, and Warsaw, we operate across North America, EMEA, and Australia.

Click on any of our vacancies and you'll see one thing in common - they all begin with this message. Why? Because at Interact we treat everyone with the same respect and honesty. Whether you're a developer fresh out of college or a seasoned salesperson, we live the motto that we uphold for our customers: our people are our most valuable assets.

Your objective will be to support and strengthen the organisation's information security and data protection framework by maintaining compliance with recognised security standards and regulatory requirements, including ISO 27001, SOC 2, Cyber Essentials and UK GDPR.

The role is responsible for identifying, assessing and mitigating security and privacy risks, managing certification and audit activities, supporting incident response and remediation, and promoting a culture of security awareness across the business. Working closely with technical and business stakeholders, the Information Security & Data Protection Analyst will balance security and compliance requirements with commercial priorities, driving continuous improvement in governance, risk management and data protection practices while helping to safeguard the organisation's information assets and reputation

Role Responsibilities
  • Creating, reviewing and improving the security policies.
  • Implement and maintain Information Security Management System (ISO27001 certification)
  • Contribute to activities towards certification/compliance to security. standards and regulations (ISO 27001, SOC 2, Cyber Essentials, etc.)
  • Experience of undergoing audits
  • Support progress on business continuity plans and policy
  • Build and maintain relationships with technical and business stakeholders.
  • Leading regular risk assessments and internal process audits.
  • Working with internal teams and stakeholders to manage risks, suggest solutions, and resolving issues.
  • Support and lead with evidence collation for audits.
  • Conduct vendor/supplier reviews in line with Internal Policy.
  • Experience in completing client security questionnaires for prospects and customers
  • Maintain and improve information security awareness within the business.
  • Conduct monitoring activities as required with the UK GDPR and other data protection laws, again our data protection policies
  • Work with regulator investigations as required in Article 36
  • Point of contact to our employees and individuals about data processing activities.
  • Supporting the business maintaining the Security tickets through prompt follow-up and resolution, in collaboration with teams and other stakeholders.
  • Management of penetration testing remediations.
Skills, knowledge & expertise
  • 2-3 years minimum in an information security or data protection role
  • Hands-on experience with at least two certification cycles (ISO 27001, SOC 2, etc.) from start to finish.
  • Demonstrable experience managing or influencing stakeholders at a senior level.
  • Involvement in penetration testing activities and remediations.
  • Experience handling real security incidents or data breaches.
  • Ability to pragmatically balance security risk against business need
  • Maintenance and creation of the Risk Register, ROPA & DPIAs
  • Strong awareness of the GDPR, either through training from working within a business that processes personal data or independent learning.
  • Strong practical understanding of security and compliance frameworks, such as ISO27001, SOC 2 type II and Cyber Essentials Plus.
  • Practical working knowledge of Defender, Intune, Entra, Purview, AWS and Azure
Desirable but not essential
  • Knowledge of GRC tools such as Drata and Safebase.
  • Knowledge of Security and Awareness training tools, campaign creation etc.
  • SaaS background
  • Good understanding of Risk Management and continuous improvement practices.
Benefits
  • 25 days annual leave (with the option to buy and sell additional days)
  • Cycle to work scheme
  • Access to Learning & Development platform
  • Life Insurance
  • Auto Enrolment Pensions
  • Healthshield (Cashback on dental check-ups and fillings, eye tests, physiotherapy, prescriptions and much more
  • Reimburse for usage of personal mobile phone
  • Free Gym membership and Free Friday lunch for office based staff
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security and Data Protection Analyst
Information Security and Data Protection Analyst

Interact Software • Manchester

On-site
GBP 45,000 - 65,000
Cyber Security Engineer
Cyber Security Engineer

Sideways 6 • Manchester

On-site
GBP 30,000 - 40,000
Annual leave
Cycle to work
Learning platform
+5
Senior Information Security & Compliance Analyst
Senior Information Security & Compliance Analyst

InfoSec People Ltd • Hattersley

Hybrid
GBP 60,000 - 90,000
25 days annual leave
Life assurance
Health insurance
+3
Information Security Analyst
Information Security Analyst

Sellick Partnership • Manchester

Hybrid
GBP 48,000
Hybrid work
Professional development
Influence security processes
Principal Information Security Engineer
Principal Information Security Engineer

Manchester Digital • Manchester

On-site
GBP 70,000 - 95,000
26 days holiday
Pension 7% matched
Discretionary bonus
+6
Senior Security Analyst
Senior Security Analyst

Experis UK • Manchester

Hybrid
GBP 49,000 - 59,000
Group Pension
Life Assurance
Private Medical Insurance
+4
Senior Security Engineer
Senior Security Engineer

NCC Group • Greater Manchester

On-site
GBP 80,000 - 105,000
Flexible working
25 days holiday + bank holidays
Medicash & Critical Illness Scheme
+4
Cyber Security Engineer
Cyber Security Engineer

Interact Software • Manchester

On-site
GBP 65,000 - 90,000
Principal Information Security Engineer
Principal Information Security Engineer

AJ Bell Business Solutions Limited • Salford

Hybrid
GBP 90,000 - 120,000
Competitive salary
Holidays 26–31 days
Pension matched 7%
+5
Cyber Security Analyst
Cyber Security Analyst

Jobtailor • Birmingham

On-site
GBP 70,000 - 80,000
Annual bonus up to 10%
25 days annual leave + bank holidays
Pension contribution up to 8%
+2