Enable job alerts via email!

IT Security Analyst

83zero Ltd

England

Hybrid

GBP 50,000 - 60,000

Full time

11 days ago

Job summary

A leading software firm is seeking an IT Security Analyst to manage security questionnaires, conduct vendor risk assessments, and improve security initiatives. The ideal candidate has over 3 years of experience in Information Security, excellent communication skills, and knowledge of standards like ISO 27001. This hybrid position offers a salary between £50,000 - £60,000, along with numerous benefits including annual leave and professional development opportunities.

Benefits

25 days annual leave + public holidays
Matched pension scheme
Private medical insurance
Fitness allowance
Paid study leave
Flexible hybrid working

Qualifications

  • 3+ years' experience in Information Security or Vendor Risk Management.
  • Strong experience issuing or responding to security questionnaires.
  • Eligible to work in the UK and able to pass background checks.

Responsibilities

  • Manage responses to customer security questionnaires.
  • Conduct vendor risk assessments against multiple frameworks.
  • Track and publish key security metrics.

Skills

Information Security
Vendor Risk Management
Communication skills
Security questionnaires

Tools

ISO 27001
SOC 2
GDPR/CCPA
Job description

IT Security Analyst

Location: Hybrid - Middlesbrough

Salary: 50,000 - 60,000 + Benefits

83zero are partnered with a market-leading software company who are on a mission to transform the construction and related industries through their end-to-end digital solutions. With teams across the UK, Europe, USA and India, they are delivering large-scale transformation projects on a global scale and are continuing to expand.

The Role
  • Own and manage responses to customer security questionnaires (SIG, CAIQ, bespoke).
  • Work cross-functionally with Legal, Compliance, Procurement, Product and Security teams.
  • Maintain the security assurance matrix in line with ISO 27001, Cyber Essentials, and SOC 2.
  • Act as the key point of contact for security assurance queries.
  • Conduct vendor risk assessments against ISO 27001, NIST, and CIS Controls.
  • Manage the third-party due diligence programme, including onboarding and periodic reviews.
  • Track and publish key security metrics such as risk severity, SLA adherence, and turnaround times.
  • Provide audit artefacts and support internal/external audits.
  • Contribute to broader security initiatives and continuous improvement within the organisation.
About You
  • 3+ years\' experience in Information Security, GRC, or Vendor Risk Management.
  • Strong experience issuing or responding to security questionnaires.
  • Knowledge of ISO 27001 Annex A, SOC 2, and GDPR/CCPA.
  • Excellent communication skills, able to translate technical risk to non-technical stakeholders.
  • Eligible to work in the UK and able to pass background checks.
Desirable
  • Certifications such as CRISC, CISSP, CISA, or ISO 27001 Lead Auditor.
  • Familiarity with SaaS/cloud platforms (AWS, Azure, GCP).
  • Understanding of secure software supply chains (SBOM, SLSA).
What\'s on Offer
  • 50,000 - 55,000 base salary
  • 25 days annual leave + public holidays (increasing with service)
  • Matched pension scheme
  • Private medical insurance & life assurance
  • Fitness allowance
  • Paid study leave & volunteering days
  • Flexible hybrid working
  • Excellent career development and training opportunities
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.